Resta saysBasic Auth sends a base64-encoded username:password in the Authorization header.
Authorization: Basic base64(user:pass) is the oldest HTTP auth scheme. Base64 is encoding, not encryption — trivially reversible — so Basic Auth is only safe over HTTPS, where TLS protects it. It sends credentials on every request and has no logout/expiry. Fine for quick internal tools; tokens are better for real apps.
Power-ups you unlock
Authorization: Basic base64(user:pass)
Base64 is encoding, NOT encryption
Only safe over HTTPS
Credentials sent on every request
The 401 Bandit attacks — common mistakes
Thinking base64 protects the password
Using Basic Auth over plain HTTP
Relying on it where token expiry is needed
Boss battleExplain why Basic Auth must never be used without HTTPS.
Example code
<!doctype html><html><head><meta charset="utf-8"></head>
<body style="background:#06040d;color:#e6e0ff;font-family:monospace;padding:20px"><pre>Authorization: Basic ZHJldzpwYXNz
= base64("drew:pass") — reversible!
→ TLS (https) is the only thing protecting it</pre></body></html>