Micron Document
<!DOCTYPE html>
<html class="client-nojs vector-feature-night-mode-disabled vector-feature-language-in-header-enabled vector-feature-language-in-main-page-header-disabled vector-feature-page-tools-pinned-disabled vector-feature-toc-pinned-clientpref-1 vector-feature-main-menu-pinned-disabled vector-feature-limited-width-clientpref-1 vector-feature-limited-width-content-enabled vector-feature-custom-font-size-clientpref-1 vector-feature-appearance-pinned-clientpref-1 vector-sticky-header-enabled" lang="en" dir="ltr"><head>
<meta charset="UTF-8">
<title>Basic access authentication</title>
<meta name="viewport" content="width=device-width, initial-scale=1.0">
<link rel="canonical" href="https://en.wikipedia.org/wiki/Basic_access_authentication"> <link href="./mw/ext.cite.styles.css" rel="stylesheet" type="text/css">
<link href="./mw/ext.pygments.css" rel="stylesheet" type="text/css">
<link href="./mw/skins.vector.icons.css" rel="stylesheet" type="text/css">
<link href="./mw/skins.vector.search.codex.styles.css" rel="stylesheet" type="text/css">
<link href="./mw/skins.vector.styles.css" rel="stylesheet" type="text/css">
<link href="./mw/user.styles.css" rel="stylesheet" type="text/css">
<meta name="ResourceLoaderDynamicStyles" content="">
<link rel="stylesheet" type="text/css" href="./mw/site.styles.css">
<link rel="stylesheet" type="text/css" href="./mw/noscript.css">
<link rel="stylesheet" type="text/css" href="./footer.css">
<link rel="stylesheet" type="text/css" href="./vector-2022.css">
</head>
<body class="skin--responsive skin-vector skin-vector-search-vue mediawiki ltr sitedir-ltr mw-hide-empty-elt ns-0 ns-subject page-Basic_access_authentication rootpage-Basic_access_authentication skin-vector-2022 action-view">
<div class="mw-page-container">
<div class="mw-page-container-inner">
<div class="mw-content-container">
<main id="content" class="mw-body">
<header class="mw-body-header vector-page-titlebar">
<h1 id="firstHeading" class="firstHeading mw-first-heading">
<span id="openzim-page-title" class="mw-page-title-main"><span class="mw-page-title-main">Basic access authentication</span></span>
</h1>
</header>
<a id="top"></a>
<div id="bodyContent" class="vector-body ve-init-mw-desktopArticleTarget-targetContainer" aria-labelledby="firstHeading" data-mw-ve-target-container="">
<div id="mw-content-text" class="mw-body-content mw-content-ltr" lang="en" dir="ltr"><div class="mw-content-ltr mw-parser-output" lang="en" dir="ltr">
<style data-mw-deduplicate="TemplateStyles:r1129693374">
/* start https://en.wikipedia.org/ */


.mw-parser-output .hlist dl,.mw-parser-output .hlist ol,.mw-parser-output .hlist ul{margin:0;padding:0}.mw-parser-output .hlist dd,.mw-parser-output .hlist dt,.mw-parser-output .hlist li{margin:0;display:inline}.mw-parser-output .hlist.inline,.mw-parser-output .hlist.inline dl,.mw-parser-output .hlist.inline ol,.mw-parser-output .hlist.inline ul,.mw-parser-output .hlist dl dl,.mw-parser-output .hlist dl ol,.mw-parser-output .hlist dl ul,.mw-parser-output .hlist ol dl,.mw-parser-output .hlist ol ol,.mw-parser-output .hlist ol ul,.mw-parser-output .hlist ul dl,.mw-parser-output .hlist ul ol,.mw-parser-output .hlist ul ul{display:inline}.mw-parser-output .hlist .mw-empty-li{display:none}.mw-parser-output .hlist dt::after{content:": "}.mw-parser-output .hlist dd::after,.mw-parser-output .hlist li::after{content:" ยท ";font-weight:bold}.mw-parser-output .hlist dd:last-child::after,.mw-parser-output .hlist dt:last-child::after,.mw-parser-output .hlist li:last-child::after{content:none}.mw-parser-output .hlist dd dd:first-child::before,.mw-parser-output .hlist dd dt:first-child::before,.mw-parser-output .hlist dd li:first-child::before,.mw-parser-output .hlist dt dd:first-child::before,.mw-parser-output .hlist dt dt:first-child::before,.mw-parser-output .hlist dt li:first-child::before,.mw-parser-output .hlist li dd:first-child::before,.mw-parser-output .hlist li dt:first-child::before,.mw-parser-output .hlist li li:first-child::before{content:" (";font-weight:normal}.mw-parser-output .hlist dd dd:last-child::after,.mw-parser-output .hlist dd dt:last-child::after,.mw-parser-output .hlist dd li:last-child::after,.mw-parser-output .hlist dt dd:last-child::after,.mw-parser-output .hlist dt dt:last-child::after,.mw-parser-output .hlist dt li:last-child::after,.mw-parser-output .hlist li dd:last-child::after,.mw-parser-output .hlist li dt:last-child::after,.mw-parser-output .hlist li li:last-child::after{content:")";font-weight:normal}.mw-parser-output .hlist ol{counter-reset:listitem}.mw-parser-output .hlist ol>li{counter-increment:listitem}.mw-parser-output .hlist ol>li::before{content:" "counter(listitem)"\a0 "}.mw-parser-output .hlist dd ol>li:first-child::before,.mw-parser-output .hlist dt ol>li:first-child::before,.mw-parser-output .hlist li ol>li:first-child::before{content:" ("counter(listitem)"\a0 "}


/* end https://en.wikipedia.org/ */
</style><style data-mw-deduplicate="TemplateStyles:r1246091330">
/* start https://en.wikipedia.org/ */


.mw-parser-output .sidebar{width:22em;float:right;clear:right;margin:0.5em 0 1em 1em;background:var(--background-color-neutral-subtle,#f8f9fa);border:1px solid var(--border-color-base,#a2a9b1);padding:0.2em;text-align:center;line-height:1.4em;font-size:88%;border-collapse:collapse;display:table}body.skin-minerva .mw-parser-output .sidebar{display:table!important;float:right!important;margin:0.5em 0 1em 1em!important}.mw-parser-output .sidebar-subgroup{width:100%;margin:0;border-spacing:0}.mw-parser-output .sidebar-left{float:left;clear:left;margin:0.5em 1em 1em 0}.mw-parser-output .sidebar-none{float:none;clear:both;margin:0.5em 1em 1em 0}.mw-parser-output .sidebar-outer-title{padding:0 0.4em 0.2em;font-size:125%;line-height:1.2em;font-weight:bold}.mw-parser-output .sidebar-top-image{padding:0.4em}.mw-parser-output .sidebar-top-caption,.mw-parser-output .sidebar-pretitle-with-top-image,.mw-parser-output .sidebar-caption{padding:0.2em 0.4em 0;line-height:1.2em}.mw-parser-output .sidebar-pretitle{padding:0.4em 0.4em 0;line-height:1.2em}.mw-parser-output .sidebar-title,.mw-parser-output .sidebar-title-with-pretitle{padding:0.2em 0.8em;font-size:145%;line-height:1.2em}.mw-parser-output .sidebar-title-with-pretitle{padding:0.1em 0.4em}.mw-parser-output .sidebar-image{padding:0.2em 0.4em 0.4em}.mw-parser-output .sidebar-heading{padding:0.1em 0.4em}.mw-parser-output .sidebar-content{padding:0 0.5em 0.4em}.mw-parser-output .sidebar-content-with-subgroup{padding:0.1em 0.4em 0.2em}.mw-parser-output .sidebar-above,.mw-parser-output .sidebar-below{padding:0.3em 0.8em;font-weight:bold}.mw-parser-output .sidebar-collapse .sidebar-above,.mw-parser-output .sidebar-collapse .sidebar-below{border-top:1px solid #aaa;border-bottom:1px solid #aaa}.mw-parser-output .sidebar-navbar{text-align:right;font-size:115%;padding:0 0.4em 0.4em}.mw-parser-output .sidebar-list-title{padding:0 0.4em;text-align:left;font-weight:bold;line-height:1.6em;font-size:105%}.mw-parser-output .sidebar-list-title-c{padding:0 0.4em;text-align:center;margin:0 3.3em}@media(max-width:640px){body.mediawiki .mw-parser-output .sidebar{width:100%!important;clear:both;float:none!important;margin-left:0!important;margin-right:0!important}}body.skin--responsive .mw-parser-output .sidebar a>img{max-width:none!important}@media screen{html.skin-theme-clientpref-night .mw-parser-output .sidebar:not(.notheme) .sidebar-list-title,html.skin-theme-clientpref-night .mw-parser-output .sidebar:not(.notheme) .sidebar-title-with-pretitle{background:transparent!important}html.skin-theme-clientpref-night .mw-parser-output .sidebar:not(.notheme) .sidebar-title-with-pretitle a{color:var(--color-progressive)!important}}@media screen and (prefers-color-scheme:dark){html.skin-theme-clientpref-os .mw-parser-output .sidebar:not(.notheme) .sidebar-list-title,html.skin-theme-clientpref-os .mw-parser-output .sidebar:not(.notheme) .sidebar-title-with-pretitle{background:transparent!important}html.skin-theme-clientpref-os .mw-parser-output .sidebar:not(.notheme) .sidebar-title-with-pretitle a{color:var(--color-progressive)!important}}@media print{body.ns-0 .mw-parser-output .sidebar{display:none!important}}


/* end https://en.wikipedia.org/ */
</style><table class="sidebar nomobile nowraplinks hlist"><tbody><tr><th class="sidebar-title"><a href="HTTP" title="HTTP">HTTP</a></th></tr><tr><td class="sidebar-image"><span typeof="mw:File"></span></td></tr><tr><td class="sidebar-content">
<ul><li><a href="HTTP_persistent_connection" title="HTTP persistent connection">Persistence</a></li>
<li><a href="HTTP_compression" title="HTTP compression">Compression</a></li>
<li><a href="HTTPS" title="HTTPS">HTTPS</a></li>
<li><a href="QUIC" title="QUIC">QUIC</a></li></ul></td>
</tr><tr><th class="sidebar-heading">
<a href="HTTP#Request_methods" title="HTTP">Request methods</a></th></tr><tr><td class="sidebar-content">
<ul><li><a href="HTTP#Request_methods" title="HTTP">OPTIONS</a></li>
<li><a href="HTTP#Request_methods" title="HTTP">GET</a></li>
<li><a href="HTTP#Request_methods" title="HTTP">HEAD</a></li>
<li><a href="POST_(HTTP)" title="POST (HTTP)">POST</a></li>
<li><a href="HTTP#Request_methods" title="HTTP">PUT</a></li>
<li><a href="HTTP#Request_methods" title="HTTP">DELETE</a></li>
<li><a href="HTTP#Request_methods" title="HTTP">TRACE</a></li>
<li><a href="HTTP#Request_methods" title="HTTP">CONNECT</a></li>
<li><a href="PATCH_(HTTP)" title="PATCH (HTTP)">PATCH</a></li></ul></td>
</tr><tr><th class="sidebar-heading">
<a href="List_of_HTTP_header_fields" title="List of HTTP header fields">Header fields</a></th></tr><tr><td class="sidebar-content">
<ul><li><a href="HTTP_cookie" title="HTTP cookie">Cookie</a></li>
<li><a href="HTTP_ETag" title="HTTP ETag">ETag</a></li>
<li><a href="HTTP_location" title="HTTP location">Location</a></li>
<li><a href="HTTP_referer" title="HTTP referer">HTTP referer</a></li>
<li><a href="Do_Not_Track" title="Do Not Track">DNT</a></li>
<li><a href="X-Forwarded-For" title="X-Forwarded-For">X-Forwarded-For</a></li></ul></td>
</tr><tr><th class="sidebar-heading">
<a href="List_of_HTTP_status_codes" title="List of HTTP status codes">Response status codes</a></th></tr><tr><td class="sidebar-content">
<ul><li><a href="HTTP_301" title="HTTP 301">301 Moved Permanently</a></li>
<li><a href="HTTP_302" title="HTTP 302">302 Found</a></li>
<li><a href="HTTP_303" title="HTTP 303">303 See Other</a></li>
<li><a href="HTTP_403" title="HTTP 403">403 Forbidden</a></li>
<li><a href="HTTP_404" title="HTTP 404">404 Not Found</a></li>
<li><a href="HTTP_451" title="HTTP 451">451 Unavailable for Legal Reasons</a></li></ul></td>
</tr><tr><th class="sidebar-heading">
Security access control methods</th></tr><tr><td class="sidebar-content">
<ul>
<li><a href="Digest_access_authentication" title="Digest access authentication">Digest access authentication</a></li></ul></td>
</tr><tr><th class="sidebar-heading">
Security vulnerabilities</th></tr><tr><td class="sidebar-content">
<ul><li><a href="HTTP_header_injection" title="HTTP header injection">HTTP header injection</a></li>
<li><a href="HTTP_request_smuggling" title="HTTP request smuggling">HTTP request smuggling</a></li>
<li><a href="HTTP_response_splitting" title="HTTP response splitting">HTTP response splitting</a></li>
<li><a href="HTTP_parameter_pollution" title="HTTP parameter pollution">HTTP parameter pollution</a></li></ul></td>
</tr><tr><td class="sidebar-navbar"><style data-mw-deduplicate="TemplateStyles:r1239400231">
/* start https://en.wikipedia.org/ */


.mw-parser-output .navbar{display:inline;font-size:88%;font-weight:normal}.mw-parser-output .navbar-collapse{float:left;text-align:left}.mw-parser-output .navbar-boxtext{word-spacing:0}.mw-parser-output .navbar ul{display:inline-block;white-space:nowrap;line-height:inherit}.mw-parser-output .navbar-brackets::before{margin-right:-0.125em;content:"[ "}.mw-parser-output .navbar-brackets::after{margin-left:-0.125em;content:" ]"}.mw-parser-output .navbar li{word-spacing:-0.125em}.mw-parser-output .navbar a>span,.mw-parser-output .navbar a>abbr{text-decoration:inherit}.mw-parser-output .navbar-mini abbr{font-variant:small-caps;border-bottom:none;text-decoration:none;cursor:inherit}.mw-parser-output .navbar-ct-full{font-size:114%;margin:0 7em}.mw-parser-output .navbar-ct-mini{font-size:114%;margin:0 4em}html.skin-theme-clientpref-night .mw-parser-output .navbar li a abbr{color:var(--color-base)!important}@media(prefers-color-scheme:dark){html.skin-theme-clientpref-os .mw-parser-output .navbar li a abbr{color:var(--color-base)!important}}@media print{.mw-parser-output .navbar{display:none!important}}


/* end https://en.wikipedia.org/ */
</style></td></tr></tbody></table>
<p>In the context of an <a href="HTTP" title="HTTP">HTTP</a> transaction, <b>basic access authentication</b> is a method for an <a href="User_Agent_Profiling" class="mw-redirect" title="User Agent Profiling">HTTP user agent</a> (e.g. a <a href="Web_browser" title="Web browser">web browser</a>) to provide a <a href="User_name" class="mw-redirect" title="User name">user name</a> and <a href="Password" title="Password">password</a> when making a request. In basic HTTP authentication, a request contains a header field in the form of <code>Authorization: Basic &lt;credentials&gt;</code>, where <code>&lt;credentials&gt;</code> is the <a href="Base64" title="Base64">Base64</a> encoding of ID and password joined by a single colon <code>:</code>.
</p><p>It was originally implemented by <a href="Ari_Luotonen" title="Ari Luotonen">Ari Luotonen</a> at <a href="CERN" title="CERN">CERN</a> in 1993<sup id="cite_ref-1" class="reference"><a href="#cite_note-1"><span class="cite-bracket">[</span>1<span class="cite-bracket">]</span></a></sup> and defined in the HTTP 1.0 specification in 1996.<sup id="cite_ref-2" class="reference"><a href="#cite_note-2"><span class="cite-bracket">[</span>2<span class="cite-bracket">]</span></a></sup>
It is specified in <style data-mw-deduplicate="TemplateStyles:r1238218222">
/* start https://en.wikipedia.org/ */


.mw-parser-output cite.citation{font-style:inherit;word-wrap:break-word}.mw-parser-output .citation q{quotes:"\"""\"""'""'"}.mw-parser-output .citation:target{background-color:rgba(0,127,255,0.133)}.mw-parser-output .id-lock-free.id-lock-free a{background:url("./mw/Lock-green.svg")right 0.1em center/9px no-repeat}.mw-parser-output .id-lock-limited.id-lock-limited a,.mw-parser-output .id-lock-registration.id-lock-registration a{background:url("./mw/Lock-gray-alt-2.svg")right 0.1em center/9px no-repeat}.mw-parser-output .id-lock-subscription.id-lock-subscription a{background:url("./mw/Lock-red-alt-2.svg")right 0.1em center/9px no-repeat}.mw-parser-output .cs1-ws-icon a{background:url("./mw/Wikisource-logo.svg")right 0.1em center/12px no-repeat}body:not(.skin-timeless):not(.skin-minerva) .mw-parser-output .id-lock-free a,body:not(.skin-timeless):not(.skin-minerva) .mw-parser-output .id-lock-limited a,body:not(.skin-timeless):not(.skin-minerva) .mw-parser-output .id-lock-registration a,body:not(.skin-timeless):not(.skin-minerva) .mw-parser-output .id-lock-subscription a,body:not(.skin-timeless):not(.skin-minerva) .mw-parser-output .cs1-ws-icon a{background-size:contain;padding:0 1em 0 0}.mw-parser-output .cs1-code{color:inherit;background:inherit;border:none;padding:inherit}.mw-parser-output .cs1-hidden-error{display:none;color:var(--color-error,#d33)}.mw-parser-output .cs1-visible-error{color:var(--color-error,#d33)}.mw-parser-output .cs1-maint{display:none;color:#085;margin-left:0.3em}.mw-parser-output .cs1-kern-left{padding-left:0.2em}.mw-parser-output .cs1-kern-right{padding-right:0.2em}.mw-parser-output .citation .mw-selflink{font-weight:inherit}@media screen{.mw-parser-output .cs1-format{font-size:95%}html.skin-theme-clientpref-night .mw-parser-output .cs1-maint{color:#18911f}}@media screen and (prefers-color-scheme:dark){html.skin-theme-clientpref-os .mw-parser-output .cs1-maint{color:#18911f}}


/* end https://en.wikipedia.org/ */
</style><a href="RFC_(identifier)" class="mw-redirect" title="RFC (identifier)">RFC</a>&nbsp;<a rel="nofollow" class="external text" href="https://www.rfc-editor.org/rfc/rfc7617">7617</a> from 2015, which obsoletes <a href="RFC_(identifier)" class="mw-redirect" title="RFC (identifier)">RFC</a>&nbsp;<a rel="nofollow" class="external text" href="https://www.rfc-editor.org/rfc/rfc2617">2617</a> from 1999.
</p>
<meta property="mw:PageProp/toc">
<div class="mw-heading mw-heading2"><h2 id="Features">Features</h2></div>
<p>HTTP Basic authentication (BA) implementation is the simplest technique for enforcing <a href="Access_controls" class="mw-redirect" title="Access controls">access controls</a> to web resources because it does not require <a href="HTTP_cookie" title="HTTP cookie">cookies</a>, session identifiers, or login pages; rather, HTTP Basic authentication uses standard fields in the <a href="HTTP_header" class="mw-redirect" title="HTTP header">HTTP header</a>.
</p>
<div class="mw-heading mw-heading2"><h2 id="Security">Security</h2></div>
<p>The BA mechanism does not provide <a href="Information_security#Confidentiality" title="Information security">confidentiality</a> protection for the transmitted credentials. They are merely encoded with <a href="Base64" title="Base64">Base64</a> in transit and not <a href="Encryption" title="Encryption">encrypted</a> or <a href="Cryptographic_hash" class="mw-redirect" title="Cryptographic hash">hashed</a> in any way. Therefore, basic authentication is typically used in conjunction with <a href="HTTPS" title="HTTPS">HTTPS</a> to provide confidentiality.
</p><p>Because the BA field has to be sent in the header of each HTTP request, the web browser needs to <a href="Cache_(computing)" title="Cache (computing)">cache</a> credentials for a reasonable period of time to avoid constantly prompting the user for their username and password. Caching policy differs between browsers.
</p><p>HTTP does not provide a method for a web server to instruct the client to "log out" the user. However, there are a number of methods to clear cached credentials in certain web browsers. One of them is redirecting the user to a URL on the same domain, using credentials that are intentionally incorrect. However, this behavior is inconsistent between various browsers and browser versions.<sup id="cite_ref-:0_3-0" class="reference"><a href="#cite_note-:0-3"><span class="cite-bracket">[</span>3<span class="cite-bracket">]</span></a></sup> <a href="Internet_Explorer" title="Internet Explorer">Microsoft Internet Explorer</a> offers a dedicated JavaScript method to clear cached credentials:<sup id="cite_ref-4" class="reference"><a href="#cite_note-4"><span class="cite-bracket">[</span>4<span class="cite-bracket">]</span></a></sup>
</p>
<div class="mw-highlight mw-highlight-lang-html mw-content-ltr" dir="ltr"><pre><span class="p">&lt;</span><span class="nt">script</span><span class="p">&gt;</span><span class="nb">document</span><span class="p">.</span><span class="nx">execCommand</span><span class="p">(</span><span class="s1">''</span><span class="p">);&lt;/</span><span class="nt">script</span><span class="p">&gt;</span>
</pre></div>
<p>In modern browsers, cached credentials for basic authentication are typically cleared when clearing browsing history. Most browsers allow users to specifically clear only credentials, though the option may be hard to find, and typically clears credentials for all visited sites.<sup id="cite_ref-5" class="reference"><a href="#cite_note-5"><span class="cite-bracket">[</span>5<span class="cite-bracket">]</span></a></sup><sup id="cite_ref-6" class="reference"><a href="#cite_note-6"><span class="cite-bracket">[</span>6<span class="cite-bracket">]</span></a></sup>
</p><p>Brute forcing credentials is not actively prevented or detected (unless a server-side mechanism is used).
</p>
<div class="mw-heading mw-heading2"><h2 id="Protocol">Protocol</h2></div>
<div class="mw-heading mw-heading3"><h3 id="Server_side">Server side</h3></div>
<p>When the server wants the user agent to authenticate itself towards the server after receiving an unauthenticated request, it must send a response with a <i>HTTP 401 Unauthorized</i> status line<sup id="cite_ref-7" class="reference"><a href="#cite_note-7"><span class="cite-bracket">[</span>7<span class="cite-bracket">]</span></a></sup> and a <i>WWW-Authenticate</i> header field.<sup id="cite_ref-8" class="reference"><a href="#cite_note-8"><span class="cite-bracket">[</span>8<span class="cite-bracket">]</span></a></sup>
</p><p>The <i>WWW-Authenticate</i> header field for basic authentication is constructed as following:
</p><p><code>
WWW-Authenticate: Basic realm="User Visible Realm"
</code>
</p><p>The server may choose to include the <i>charset</i> parameter from <a href="RFC_(identifier)" class="mw-redirect" title="RFC (identifier)">RFC</a>&nbsp;<a rel="nofollow" class="external text" href="https://www.rfc-editor.org/rfc/rfc7617">7617</a>:<sup id="cite_ref-:0_3-1" class="reference"><a href="#cite_note-:0-3"><span class="cite-bracket">[</span>3<span class="cite-bracket">]</span></a></sup>
</p><p><code>
WWW-Authenticate: Basic realm="User Visible Realm", charset="UTF-8"
</code>
</p><p>This parameter indicates that the server expects the client to use UTF-8 for encoding username and password (see below).
</p>
<div class="mw-heading mw-heading3"><h3 id="Client_side">Client side</h3></div>
<p>When the user agent wants to send authentication credentials to the server, it may use the <i>Authorization</i> header field.
</p><p>The <i>Authorization</i> header field is constructed as follows:<sup id="cite_ref-RFC7617_9-0" class="reference"><a href="#cite_note-RFC7617-9"><span class="cite-bracket">[</span>9<span class="cite-bracket">]</span></a></sup>
</p>
<ol><li>The username and password are combined with a single colon (<code class="mw-highlight mw-highlight-lang-text mw-content-ltr" style="" dir="ltr">:</code>). This means that the username itself cannot contain a colon.</li>
<li>The resulting string is encoded into an octet sequence. The character set to use for this encoding is by default unspecified, as long as it is compatible with US-ASCII, but the server may suggest the use of UTF-8 by sending the <i>charset</i> parameter.<sup id="cite_ref-RFC7617_9-1" class="reference"><a href="#cite_note-RFC7617-9"><span class="cite-bracket">[</span>9<span class="cite-bracket">]</span></a></sup></li>
<li>The resulting string is encoded using a variant of Base64 (+/ and with padding).</li>
<li>The authorization method and a space character (e.g. "Basic ") is then prepended to the encoded string.</li></ol>
<p>For example, if the browser uses <i>Aladdin</i> as the username and <i>open sesame</i> as the password, then the field's value is the Base64 encoding of <i>Aladdin:open sesame</i>, or <i>QWxhZGRpbjpvcGVuIHNlc2FtZQ==</i>. Then the <i>Authorization</i> header field will appear as:
</p><p><code>
Authorization: Basic QWxhZGRpbjpvcGVuIHNlc2FtZQ==
</code>
</p><p><code>
'Basic ' + base64.b64encode(f"{&lt;clientid&gt;}:{&lt;client secret key&gt;}".encode()).decode()
</code>
</p>
<div class="mw-heading mw-heading2"><h2 id="See_also">See also</h2></div>
<ul><li><a href="Digest_access_authentication" title="Digest access authentication">Digest access authentication</a></li>
<li><a href="HTTP_header" class="mw-redirect" title="HTTP header">HTTP header</a></li>
<li><a href="TLS-SRP" title="TLS-SRP">TLS-SRP</a>, an alternative if one wants to avoid transmitting a password-equivalent to the server (even encrypted, like with TLS).</li></ul>
<div class="mw-heading mw-heading2"><h2 id="References_and_notes">References and notes</h2></div>
<style data-mw-deduplicate="TemplateStyles:r1239543626">
/* start https://en.wikipedia.org/ */


.mw-parser-output .reflist{margin-bottom:0.5em;list-style-type:decimal}@media screen{.mw-parser-output .reflist{font-size:90%}}.mw-parser-output .reflist .references{font-size:100%;margin-bottom:0;list-style-type:inherit}.mw-parser-output .reflist-columns-2{column-width:30em}.mw-parser-output .reflist-columns-3{column-width:25em}.mw-parser-output .reflist-columns{margin-top:0.3em}.mw-parser-output .reflist-columns ol{margin-top:0}.mw-parser-output .reflist-columns li{page-break-inside:avoid;break-inside:avoid-column}.mw-parser-output .reflist-upper-alpha{list-style-type:upper-alpha}.mw-parser-output .reflist-upper-roman{list-style-type:upper-roman}.mw-parser-output .reflist-lower-alpha{list-style-type:lower-alpha}.mw-parser-output .reflist-lower-greek{list-style-type:lower-greek}.mw-parser-output .reflist-lower-roman{list-style-type:lower-roman}


/* end https://en.wikipedia.org/ */
</style><div class="reflist">
<div class="mw-references-wrap"><ol class="references">
<li id="cite_note-1"><span class="mw-cite-backlink"><b><a href="#cite_ref-1">^</a></b></span> <span class="reference-text"><cite id="CITEREFLuotonen2022" class="citation mailinglist cs1">Luotonen, Ari (10 September 2022). <a rel="nofollow" class="external text" href="http://1997.webhistory.org/www.lists/www-talk.1993q3/0882.html">"Announcing Access Authorization Documentation"</a>. <i>www-talk@w3.org</i> (Mailing list)<span class="reference-accessdate">. Retrieved <span class="nowrap">7 February</span> 2022</span>.</cite></span>
</li>
<li id="cite_note-2"><span class="mw-cite-backlink"><b><a href="#cite_ref-2">^</a></b></span> <span class="reference-text"><cite class="citation web cs1"><a rel="nofollow" class="external text" href="https://www.w3.org/Protocols/HTTP/1.0/spec.html#BasicAA">"Hypertext Transfer Protocol -- HTTP/1.0"</a>. <i>www.w3.org</i>. W3C. 19 February 1996<span class="reference-accessdate">. Retrieved <span class="nowrap">7 February</span> 2022</span>.</cite></span>
</li>
<li id="cite_note-:0-3"><span class="mw-cite-backlink">^ <a href="#cite_ref-:0_3-0"><sup><i><b>a</b></i></sup></a> <a href="#cite_ref-:0_3-1"><sup><i><b>b</b></i></sup></a></span> <span class="reference-text"><cite class="citation web cs1"><a rel="nofollow" class="external text" href="https://stackoverflow.com/questions/31326/is-there-a-browser-equivalent-to-ies-clearauthenticationcache">"Is there a browser equivalent to IE's ClearAuthenticationCache?"</a>. StackOverflow<span class="reference-accessdate">. Retrieved <span class="nowrap">March 15,</span> 2013</span>.</cite></span>
</li>
<li id="cite_note-4"><span class="mw-cite-backlink"><b><a href="#cite_ref-4">^</a></b></span> <span class="reference-text"><cite class="citation web cs1"><a rel="nofollow" class="external text" href="https://docs.microsoft.com/en-us/previous-versions/windows/internet-explorer/ie-developer/platform-apis/hh801226(v=vs.85)#idmclearauthenticationcache">"<code>IDM_CLEARAUTHENTICATIONCACHE</code> command identifier"</a>. Microsoft<span class="reference-accessdate">. Retrieved <span class="nowrap">March 15,</span> 2013</span>.</cite></span>
</li>
<li id="cite_note-5"><span class="mw-cite-backlink"><b><a href="#cite_ref-5">^</a></b></span> <span class="reference-text"><cite class="citation web cs1"><a rel="nofollow" class="external text" href="https://bugzilla.mozilla.org/show_bug.cgi?id=540516">"540516 - Usability: Allow users to clear HTTP Basic authentication details ('Logout')"</a>. <i>bugzilla.mozilla.org</i><span class="reference-accessdate">. Retrieved <span class="nowrap">2020-08-06</span></span>. <q>Clear Recent History-&gt;Active Logins (in the details) is used to clear the authentication.</q></cite></span>
</li>
<li id="cite_note-6"><span class="mw-cite-backlink"><b><a href="#cite_ref-6">^</a></b></span> <span class="reference-text"><cite class="citation web cs1"><a rel="nofollow" class="external text" href="https://support.google.com/chrome/answer/2392709?co=GENIE.Platform=Desktop&amp;hl=en">"Clear browsing data - Computer - Google Chrome Help"</a>. <i>support.google.com</i><span class="reference-accessdate">. Retrieved <span class="nowrap">2020-08-06</span></span>. <q>Data that can be deleted[...]Passwords: Records of passwords you saved are deleted.</q></cite></span>
</li>
<li id="cite_note-7"><span class="mw-cite-backlink"><b><a href="#cite_ref-7">^</a></b></span> <span class="reference-text"><cite class="citation cs1"><a rel="nofollow" class="external text" href="https://datatracker.ietf.org/doc/html/rfc1945#section-11"><i>Access Authentication</i></a>. <a href="Internet_Engineering_Task_Force" title="Internet Engineering Task Force">Internet Engineering Task Force</a>. May 1996. p.&nbsp;46.&nbsp;sec.&nbsp;11. <a href="Doi_(identifier)" class="mw-redirect" title="Doi (identifier)">doi</a>:<span class="id-lock-free" title="Freely accessible"><a rel="nofollow" class="external text" href="https://doi.org/10.17487%2FRFC1945">10.17487/RFC1945</a></span>. <a href="Request_for_Comments" title="Request for Comments">RFC</a> <a rel="nofollow" class="external text" href="https://datatracker.ietf.org/doc/html/rfc1945">1945</a><span class="reference-accessdate">. Retrieved <span class="nowrap">3 February</span> 2017</span>.</cite></span>
</li>
<li id="cite_note-8"><span class="mw-cite-backlink"><b><a href="#cite_ref-8">^</a></b></span> <span class="reference-text"><cite id="CITEREFFieldingBerners-LeeHenrik" class="citation cs1"><a href="Roy_Fielding" title="Roy Fielding">Fielding, Roy T.</a>; <a href="Tim_Berners-Lee" title="Tim Berners-Lee">Berners-Lee, Tim</a>; Henrik, Frystyk. <a rel="nofollow" class="external text" href="https://datatracker.ietf.org/doc/html/rfc1945#section-10.16"><i>Hypertext Transfer Protocol -- HTTP/1.0</i></a>. Internet Engineering Task Force. sec.&nbsp;10.16. <a href="Doi_(identifier)" class="mw-redirect" title="Doi (identifier)">doi</a>:<span class="id-lock-free" title="Freely accessible"><a rel="nofollow" class="external text" href="https://doi.org/10.17487%2FRFC1945">10.17487/RFC1945</a></span>. <a href="Request_for_Comments" title="Request for Comments">RFC</a> <a rel="nofollow" class="external text" href="https://datatracker.ietf.org/doc/html/rfc1945">1945</a>.</cite></span>
</li>
<li id="cite_note-RFC7617-9"><span class="mw-cite-backlink">^ <a href="#cite_ref-RFC7617_9-0"><sup><i><b>a</b></i></sup></a> <a href="#cite_ref-RFC7617_9-1"><sup><i><b>b</b></i></sup></a></span> <span class="reference-text"><cite id="CITEREFReschke" class="citation cs1">Reschke, Julian. <a rel="nofollow" class="external text" href="https://datatracker.ietf.org/doc/html/rfc7617#section-2.1"><i>The 'Basic' HTTP Authentication Scheme</i></a>. Internet Engineering Task Force. sec.&nbsp;2.1. <a href="Doi_(identifier)" class="mw-redirect" title="Doi (identifier)">doi</a>:<span class="id-lock-free" title="Freely accessible"><a rel="nofollow" class="external text" href="https://doi.org/10.17487%2FRFC7617">10.17487/RFC7617</a></span>. <a href="Request_for_Comments" title="Request for Comments">RFC</a> <a rel="nofollow" class="external text" href="https://datatracker.ietf.org/doc/html/rfc7617">7617</a>.</cite></span>
</li>
</ol></div></div>
<div class="mw-heading mw-heading2"><h2 id="External_links">External links</h2></div>
<ul><li><cite class="citation cs1"><a rel="nofollow" class="external text" href="https://datatracker.ietf.org/doc/html/rfc7617"><i>The 'Basic' HTTP Authentication Scheme</i></a>. <a href="Internet_Engineering_Task_Force" title="Internet Engineering Task Force">Internet Engineering Task Force</a>. September 2015. <a href="Doi_(identifier)" class="mw-redirect" title="Doi (identifier)">doi</a>:<span class="id-lock-free" title="Freely accessible"><a rel="nofollow" class="external text" href="https://doi.org/10.17487%2FRFC7617">10.17487/RFC7617</a></span>. <a href="Request_for_Comments" title="Request for Comments">RFC</a> <a rel="nofollow" class="external text" href="https://datatracker.ietf.org/doc/html/rfc7617">7617</a>.</cite></li></ul></div><!--htdig_noindex--><div><div class="zim-footer">
This article is issued from <a class="external text" title="Last edited on 2025-06-30" href="https://en.wikipedia.org/wiki/?title=Basic_access_authentication&amp;oldid=1298106655">Wikipedia</a>. The text is available under <a class="external text" href="https://creativecommons.org/licenses/by-sa/4.0/deed.en">Creative Commons Attribution-Share Alike 4.0</a> unless otherwise noted. Additional terms may apply for the media files.
</div>
</div><!--/htdig_noindex--></div>
</div>
</main>
</div>
</div>
</div>

</body></html>