Sitelet https://funapi.dev/glossary/basic-authentication

Basic authentication

Basic authentication is the oldest HTTP authentication scheme. The client joins username and password with a colon, Base64-encodes the result and sends it as Authorization: Basic followed by that string. The server decodes it and checks the credentials on every request; there is no token and no session.

How it works

A server that wants credentials answers 401 with a WWW-Authenticate: Basic header, which is what makes a browser show its native login prompt. Because the credentials are on every request, the scheme is only acceptable over HTTPS, and it is still common for internal tools, CI webhooks, package registries and service-to-service calls with dedicated accounts.

The misconception

That Base64 is encryption. It is an encoding anyone can reverse in one line; over plain HTTP, Basic authentication sends the password in the clear. Its security comes entirely from TLS.

Try it here

This playground uses bearer tokens rather than Basic, which makes the contrast easy to see: compare GET /auth/v1/me with qa-admin-token, and decode a Basic header yourself in your browser console with atob().

Other terms

All glossary terms · Testing techniques · All 39 mock REST APIs

Last updated