เครือข่าย/HTTP
Basic Auth Generator
สร้างหรือถอดรหัสส่วนหัว HTTP Basic Authentication — Base64(ชื่อผู้ใช้:รหัสผ่าน)
HTTP Basic Authentication sends a username and password in the Authorization header as Base64("username:password"). That's encoding, not encryption, so Basic Auth only makes sense on top of HTTPS.
How to use it
- Generate: enter a username and password and the tool builds the username:password string, Base64-encodes it, and produces a ready Authorization: Basic ... header.
- Decode: paste an existing Basic Auth header to decode it back into a username and password.
- Copy the finished header straight into curl, Postman, or a server config.
Common uses
- Building a header for manually testing an API with curl or Postman without running client code.
- Setting up basic authentication on nginx/Apache or in a reverse-proxy config.
- Decoding a header from logs or captured traffic while debugging an authentication issue.
Things to keep in mind
Base64 is not encryption — anyone intercepting the header instantly recovers the username and password in plain text.
Basic Auth is only safe over HTTPS — without TLS, credentials travel essentially in the clear.
บทความเกี่ยวกับเครื่องมือนี้: HTTP Basic Auth: เฮดเดอร์ Authorization ถูกสร้างขึ้นอย่างไร
คำถามที่พบบ่อย
Basic Auth header ถูกสร้างขึ้นจริง ๆ อย่างไร?
ชื่อผู้ใช้และรหัสผ่านถูกรวมกันด้วยเครื่องหมายโคลอน (user:password) จากนั้นทั้งสตริงจะถูกเข้ารหัส Base64 และเติมคำนำหน้า "Basic " ในเฮดเดอร์ Authorization — นี่คือการเข้ารหัสข้อมูล ไม่ใช่การเข้ารหัสลับ
การใช้ Basic Auth ผ่าน HTTP ธรรมดาปลอดภัยหรือไม่?
ไม่ปลอดภัย เนื่องจากข้อมูลรับรองถูกเข้ารหัสแค่ Base64 ใครก็ตามที่ดักจับทราฟฟิกสามารถถอดรหัสได้ง่าย ๆ — ควรใช้ Basic Auth ผ่าน HTTPS เท่านั้น
เครื่องมือนี้ส่งชื่อผู้ใช้หรือรหัสผ่านของฉันไปที่ไหนหรือไม่?
ไม่ เฮดเดอร์ถูกสร้างขึ้นทั้งหมดในเบราว์เซอร์ของคุณ ไม่มีการส่งข้อมูลไปยังเซิร์ฟเวอร์
จะ "ออกจากระบบ" จากเว็บไซต์ที่ป้องกันด้วย Basic Auth ได้อย่างไร?
ไม่มีวิธีมาตรฐาน — เบราว์เซอร์จะแคชข้อมูลรับรองไว้ตราบใดที่แท็บยังเปิดอยู่ วิธีที่น่าเชื่อถือที่สุดคือปิดแท็บทั้งหมดของเว็บไซต์นั้น หรือล้างข้อมูลเว็บไซต์ในการตั้งค่าเบราว์เซอร์
สามารถใช้อักขระพิเศษในชื่อผู้ใช้หรือรหัสผ่านของ Basic Auth ได้หรือไม่?
ได้ แต่เครื่องหมายโคลอนภายในชื่อผู้ใช้เองจะทำให้เกิดความกำกวมตอนถอดรหัส ข้อกำหนดจึงแนะนำให้หลีกเลี่ยงเครื่องหมายโคลอนในชื่อผู้ใช้