🎫Bearer and Basic Auth Header Generator

Build an Authorization header and curl sample

The header this page builds is itself a secret. Keep it out of screenshots, chats, commits and issues, and press the clear button when you are done. Everything is processed in your browser and nothing is sent anywhere.

Paste a base64 value to turn it back into a user id and password.

Basic sends base64(user:password) as is, which anyone can reverse. Use it only over HTTPS, and paste a token your server issued rather than inventing one. The curl sample is meant for a shell, so values are wrapped in single quotes with any inner quote escaped safely.

You Might Also Need

How to use the auth header generator

Pick a scheme, fill in the values, and the page builds one Authorization header line plus a curl sample you can run as is. Bearer passes through the token your server issued, while Basic encodes a user id and password as base64. You can also enter your own scheme name, which is validated against the allowed character set. The decode field below lets you confirm how plainly a Basic value gives the credentials back.

How the header is built

The header shape follows RFC 9110 for HTTP authentication, RFC 7617 for Basic and RFC 6750 for Bearer. Scheme names are restricted to the RFC 9110 token characters and anything else is rejected. Basic credentials are turned into bytes as UTF-8; the specification does not fix a character set, so a server expecting a different one will read a different value. Checked October 2026.

Limits worth knowing

base64 is not encryption, only a reversible encoding. Send these headers over HTTPS and treat the result exactly like the password it contains. The page does not issue tokens, send requests or tell you whether a server accepts a given scheme. Everything runs in your browser, but use the clear button to wipe whatever is left on screen when you finish.

Frequently Asked Questions

Is the base64 in Basic auth encryption?

No. base64 only rewrites bytes as characters, so anyone can reverse it without a key. Use the decode field on this page to see that for yourself. The protection comes from HTTPS on the wire.

Can I save the header somewhere?

The header value is the password or token itself. Pasting it into code, an issue or a chat is a leak, and committing it leaves it in history. Press the clear button once you are done with it.

What does this tool not do?

It does not issue tokens, verify signatures or send any request. It builds one header line and a curl sample from the values you type, and stops there.