Skip to content
Browse tools
HTTP authentication toolkit

Authorization Header Generator

Build, inspect and copy HTTP authentication headers without mixing schemes together. Pick one method, fill only its fields, and take the finished header, the working behind it, or ready-to-run code. Basic, Bearer, API key, RFC 7616 Digest, AWS Signature V4 and your own HMAC — every hash computed in this tab.

6 auth schemesBasic to AWS SigV4
Built-in decoderBasic, JWT, Digest & AWS
Runs locallySecrets stay in your browser

Build a header from scratch, or paste one you already have and take it apart.

Choose an authentication type

Click one option to continue

Basic

RFC 7617

Joins the username and password with a colon and Base64-encodes the result. Base64 is encoding, not encryption — anyone who sees the header reads the password, so this needs HTTPS. The colon is the separator, which is why a username can never contain one.

Your generated header

live
Request header Authorization
—
Header value
—
How this value was computed

    💻 Use it in your code

    copy & paste
    Method Request URL

    
                

    Which scheme should you use?

    All six compared on what actually matters
    SchemeSecret sent?Replay-safe?Needs TLSTypical use
    Basic Yes — reversible Base64NoMandatory Internal tools, quick scripts
    Bearer Yes — the token itselfNoMandatory OAuth 2.0, most modern APIs
    API Key Yes — the key itselfNoMandatory Server-to-server, rate limiting
    Digest No — only a hashYes, via nonceRecommended Legacy devices, routers
    AWS SigV4 No — derived keyYes, signed timestampRecommended AWS APIs, S3-compatible storage
    Custom HMAC No — only a signatureYes, if timestampedRecommended Webhooks, payment APIs

    Nothing here reaches our server. This page has no backend: the Base64, the MD5 and SHA-256 hashes and the HMAC chains all run in your tab through the Web Crypto API. You can verify that in one step — open your browser's Network tab and generate a header; there is no request to see. The usual caveat still applies to any browser tab: an extension with page-read access can read what you type, so for a live production root key, sign on your own machine.

    REFERENCE

    Sending A Secret Versus Proving You Hold One

    The Authorization header has one grammar — a scheme token, a space, then credentials in whatever shape the scheme defines — and wildly different security properties behind it. The distinction that matters in practice is the one the table above is built around: what does an attacker get by reading a single request?

    For the top three, everything. Basic carries the password in a form that decodes in one step, Bearer carries a token that is replayable until it expires, and an API key is usually valid until somebody rotates it by hand. For the bottom three, nothing reusable. Digest, SigV4 and a well-designed HMAC scheme all send proof that you hold a secret rather than the secret itself, which is why SigV4 goes to the trouble of a canonical request: signing the method, host, path, query, headers and a hash of the body means a captured signature cannot be moved to a different request. An in-house HMAC scheme is only as good as its canonical string — sign a timestamp and you get replay protection, sign the body hash and you get integrity, sign only the path and you have built Basic auth with extra steps.

    What else can you check?

    These tools all work on the same connection and address data — pick whichever question you actually have.

    Want to see the full path to a site? DNS, redirects, every hop, the CDN, TLS and the origin server. Want to know your public IP? See your IPv4 and IPv6 addresses, location, ISP and ASN. Want to check your tower & route? Live ping, speed, DNS, traceroute and a map of nearby points. Want to ping from around the world? Real latency from real probes across 12 countries, live on a map. Want to locate any IP address? City, region, country and coordinates for any public IP. Want to know if an IP is risky? Proxy, VPN, Tor, hosting and abuse-report indicators. Want to know if you're blacklisted? Check an address against major spam and abuse DNSBLs. Want to know who owns an IP? Network owner, ASN, CIDR range and abuse contact. Want to explore an AS number? Announced prefixes, BGP neighbours and registry details. Want to test your connection speed? Measure real download, upload, ping and jitter. Want to see what changed? Word-level diff between two blocks of text or code. Want to know if a DNS change is live yet? Compare answers from five independent public resolvers. Want to verify a domain's nameservers? Direct authoritative checks, glue records and SOA serials. Want to check a domain's DNSSEC setup? DNSKEY, DS records, signature expiry and real validation. Want to see the hop-by-hop path to a server? A real traceroute from a genuine probe anywhere in the world. Want to know if a server port is open? A real TCP connection attempt - open, closed or filtered. Want to measure latency to a server? Real connect timing - min/avg/max, jitter and connection loss. Want a clean URL slug from a title? Real transliteration, stop words and batch mode. Want to find and replace across a document? Regex, capture groups and a live preview before you commit. Want to find the invisible character? Code points, escapes, bytes and hidden-character detection. Want to escape text for HTML? Minimal, named or numeric entities, attribute-safe. Want to strip emoji cleanly? Whole clusters - no half-flags or stray modifiers left. Want to spot repeated words? Frequency, density and accidental doubles like "the the". Want to know if a URL is cached? Two requests prove whether your CDN is really caching it. Want to see what a site knows about you? Storage, cookies, tokens and what your browser actually cached. Want to run that check on any site? One-click bookmarklet reads storage and tokens where they live. Want to know who your site talks to? Renders the page and names every outside company it contacts. Is your site one address or four? www, non-www, http and https - which serve, which redirect. Want to tidy up a messy SQL query? Beautify, minify, lint and convert keyword casing for six dialects. Need to work out a percentage? Nine calculators covering every way a percentage gets asked. Want to work out a rise or a raise? Increases, growth, compounding and CAGR, with the working shown. Want to work out a discount or a drop? Discounts, stacked sales and depreciation, with the working shown. What is actually on that page? Words, reading time, readability, every image, embed and link. Need a favicon that works everywhere? Every size, a real multi-resolution .ico, and the tags to paste. What headers does a site send back? Every response header on every redirect hop, explained. Need to test a regular expression? Live matches, capture groups, replace preview and code snippets. Need a JPG as a PNG? Batch convert in your browser, with optional transparent background. Need somewhere to jot things down? Private notes, links, to-dos and reminders saved in your browser. Need just some pages of a PDF? Split by page, range or chunk, or extract the pages you pick. What is hiding inside that image? EXIF camera settings, GPS tags, colour palette and web checks.
    COMMON QUESTIONS

    Authorization Header FAQ

    Is it safe to put my password or AWS secret key into this page?

    Nothing you type is transmitted. There is no API endpoint behind this route and no fetch in its JavaScript — the Base64, the MD5 and SHA-256 hashes and the HMAC chains all run in your tab through the Web Crypto API. Open your browser's Network tab while you generate a header and you will see no request at all, which is a stronger assurance than anything this sentence can claim. The honest caveat is the one that applies to every web page: a browser extension with permission to read the page can read what you type into it. For a live production root key, sign on your own machine.

    Why is Base64 not encryption?

    Because it is reversible with no key. Basic YWxhZGRpbjpvcGVuIHNlc2FtZQ== decodes to aladdin:open sesame in one step, which the decode tab here will do for you. Base64 exists to make arbitrary bytes safe to put in a header, not to hide them. Basic authentication is therefore only ever acceptable over HTTPS, where TLS — not the encoding — is what keeps the password private.

    What is the difference between Bearer and a JWT?

    They answer different questions. Bearer is the transport — RFC 6750 says put the token after the word Bearer and whoever holds it is authorised. JWT is one possible format for that token: a signed, base64url-encoded JSON structure. So every JWT sent this way is a bearer token, but plenty of bearer tokens are opaque random strings with no readable contents. If your token has two dots in it, this page decodes its claims automatically — but it never verifies the signature, which needs the issuer's key.

    My AWS request keeps returning SignatureDoesNotMatch. What now?

    AWS returns that same error for every possible mistake, but it also echoes the canonical request it expected. Compare it line by line with the one under "How this value was computed" — the difference is almost always one of four things: a header you signed but did not send (or sent but did not sign), a query string sorted differently, a payload hash computed over a body that changed, or a clock more than a few minutes out. The x-amz-date you sign and the one you send must be identical.

    Why does Digest still use MD5?

    Because the devices that speak Digest were built before the alternative existed. RFC 7616 added SHA-256 in 2015, and almost nothing implements it — routers, NAS boxes, IP cameras and SIP gateways still send algorithm=MD5 in their challenge, and a client has to answer in the algorithm it was challenged with. This tool computes MD5 for that reason, not as an endorsement. Digest also authenticates only the method and the URI, never the response, so it is only meaningful inside TLS.

    Should an API key go in a header or the query string?

    A header, whenever the API allows it. A key in the query string is written into every access log, proxy log and browser history entry along the path, is carried in the Referer header of any link the page then follows, and shows up in analytics. None of those are places you can retrospectively scrub. The query-string option is here because some older APIs accept nothing else, and the tool says so when you pick it.

    What should I actually sign in a custom HMAC scheme?

    At minimum the method, the path with its query string, and a timestamp — the timestamp is what stops a captured signature being replayed tomorrow, provided the server also rejects stale ones. Add a SHA-256 hash of the body for any request that has one, or an attacker can swap the body while keeping your signature valid. Add a nonce if you need protection against replay inside the timestamp window. Join the parts with a separator that cannot appear in the values, and make sure both sides agree on it exactly: a client joining with a literal backslash-n while the server joins with a real newline is the classic all-day bug.

    Can I use this for S3-compatible storage that is not AWS?

    Yes. Cloudflare R2, MinIO, Backblaze B2, Wasabi and DigitalOcean Spaces all implement Signature Version 4 unchanged — put their endpoint in the URL field, keep the service as s3, and use whichever region string that provider expects (R2 uses auto). Keep x-amz-content-sha256 signed: it is required by the S3 API regardless of who is implementing it.

    Which schemes are actually registered with IANA?

    Basic, Bearer, Digest, HOBA, Mutual, Negotiate, SCRAM-SHA-1, SCRAM-SHA-256 and vapid are in the IANA HTTP Authentication Scheme Registry. Everything else — AWS SigV4, every vendor HMAC scheme, and the whole X-API-Key convention — is a private arrangement between one API and its clients. That is not a fault, but it does mean there is no spec to appeal to when two implementations disagree, which is why this page shows the exact bytes it signed.