freecoding.school100% FREE · NO SIGNUP
Endpoint BayISSUE #33 of 45

basic auth · the legacy header

RestaVSThe 401 Bandit
Resta saysBasic Auth sends a base64-encoded username:password in the Authorization header.

Authorization: Basic base64(user:pass) is the oldest HTTP auth scheme. Base64 is encoding, not encryption — trivially reversible — so Basic Auth is only safe over HTTPS, where TLS protects it. It sends credentials on every request and has no logout/expiry. Fine for quick internal tools; tokens are better for real apps.

Power-ups you unlock

The 401 Bandit attacks — common mistakes

Boss battleExplain why Basic Auth must never be used without HTTPS.

Example code

<!doctype html><html><head><meta charset="utf-8"></head>
<body style="background:#06040d;color:#e6e0ff;font-family:monospace;padding:20px"><pre>Authorization: Basic ZHJldzpwYXNz
              = base64("drew:pass") — reversible!
→ TLS (https) is the only thing protecting it</pre></body></html>
▶ Open the interactive comic issue
‹ Api Keys · The Simplest SecretBearer Tokens · The Standard ›