Recommended Free Tools
Some links on this page are affiliate links: if you buy through them we may earn a commission, at no extra cost to you.
To send an HTTP Basic Auth request with cURL, use --user (or its shorthand, -u) with a username and password: curl --user 'username:password' https://example.com/. Use an HTTPS URL: Basic Auth does not encrypt credentials, and they can be read by someone who observes an unprotected connection. For interactive use, you can omit the password and let cURL prompt; for automation, avoid placing a live password directly in a command that could be recorded or exposed.
Send a Basic Auth request with cURL
When you know the server expects HTTP Basic authentication, pass the credentials with --user or -u. The general syntax is:
curl --user 'USERNAME:PASSWORD' 'https://example.com/protected-resource'
For example, using illustrative credentials and a placeholder endpoint:
curl --user 'alice:example-password' 'https://api.example.com/private'
Replace the username, password and URL with the values supplied by the service. The URL should use https:// so TLS protects the request in transit. The username and password shown here are examples, not real credentials.
#1 Best Overall
- POWERFUL SECURITY KEY: The Security Key C NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
- WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key C NFC secures 100 of your favorite accounts, including email, password managers, and more.
- FAST & CONVENIENT LOGIN: Plug in your Security Key C NFC via USB-C and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
- TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
- BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
Use the shorthand option
-u is the short form of --user and works the same way:
curl -u 'USERNAME:PASSWORD' 'https://example.com/protected-resource'
For HTTP requests, cURL uses Basic by default when no other authentication method is selected. You can explicitly request it with --basic if clarity or an override is needed:
curl --basic --user 'USERNAME:PASSWORD' 'https://example.com/protected-resource'
For a known Basic Auth endpoint, --basic is usually unnecessary; --user supplies the credentials, and Basic is the default method. The cURL manual documents the options and their current behavior.
Pass the password more safely
A command such as curl --user 'alice:secret' https://example.com/ is convenient, but the password is part of the command-line arguments. Depending on the environment, command arguments can be visible in process listings or retained in shell history, logs or automation records. HTTPS protects credentials in transit; it does not prevent local exposure before the request is sent.
For an interactive request, let cURL prompt
Supply the username but leave off the colon and password:
curl --user 'alice' 'https://example.com/protected-resource'
cURL prompts for the password interactively. This avoids typing the password as part of the command itself. The prompt behavior is documented in the cURL project’s HTTP scripting guide.
Rank #2
- POWERFUL SECURITY KEY: The YubiKey 5C NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
- WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5C NFC secures 100+ of your favorite accounts, including email, password managers, and more
- FAST & CONVENIENT LOGIN: Plug in your YubiKey 5C NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
- MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
- PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts
For automation, protect the secret source
Do not embed a live password in a script or command that may be checked into source control, copied into a ticket, printed by a build log or exposed to other users on the machine. Use your environment’s protected secret mechanism, or supply cURL options through a protected configuration file or standard input where appropriate. Restrict access to any file containing credentials and keep it out of shared logs and repositories. The cURL FAQ discusses command-line visibility and safer ways to provide options.
There is no universally safe secret-delivery method for every shell, CI system or host. Choose the mechanism supported by your environment, and check what it writes to logs or exposes to other processes. Avoid treating a password stored in a plain-text script or a publicly readable file as protected merely because it is not visible in the command you ran.
Understand what Basic Auth protects—and what it does not
HTTP Basic authentication encodes credentials in a format that is only lightly obfuscated; the encoding is not encryption. As the cURL project explains, the username and password remain readable to someone who sniffs an unprotected connection. Use HTTPS for requests that carry credentials. The cURL guide to scripting HTTP requests explains the distinction.
HTTPS protects the connection in transit, but it does not make it safe to share the password, print it in logs or put it in a publicly accessible script. Keep transport security and local secret handling separate in your threat model: both matter.
Choose the right authentication option
Known method: use Basic explicitly or rely on the default
If the service documentation says it accepts HTTP Basic, use --user. Add --basic to make the selected method explicit, especially if the same command or configuration might otherwise select another authentication mode:
What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
curl --basic --user 'USERNAME:PASSWORD' 'https://example.com/resource'
Unknown method: let cURL discover a supported method
If you do not know which HTTP authentication method the server supports, --anyauth allows cURL to inspect the server’s response and choose a supported method:
Rank #3
- POWERFUL SECURITY KEY: The YubiKey 5 NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
- WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5 NFC secures 100+ of your favorite accounts, including email, password managers, and more
- FAST & CONVENIENT LOGIN: Plug in your YubiKey 5 NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
- MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
- PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts
curl --anyauth --user 'USERNAME:PASSWORD' 'https://example.com/resource'
Discovery can require an additional request-and-response round trip. If you already know the endpoint uses Basic, selecting it directly avoids that discovery step. cURL documents --anyauth and other HTTP authentication options in its manual.
Do not switch schemes at random when a request fails. Confirm what the endpoint supports; other methods, such as Digest, NTLM and Negotiate, have their own options, and availability of some methods depends on the cURL build.
Authenticate to a proxy instead of the website
--user supplies credentials for the remote server. If an intermediary proxy requires its own login, use --proxy-user (short form -U) for the proxy credentials instead:
curl --proxy-user 'PROXY_USERNAME:PROXY_PASSWORD' --proxy 'http://proxy.example:8080' 'https://example.com/'
Use --proxy-basic when you need to explicitly select Basic for proxy authentication:
curl --proxy-basic --proxy-user 'PROXY_USERNAME:PROXY_PASSWORD' --proxy 'http://proxy.example:8080' 'https://example.com/'
Proxy and server authentication are different. If both endpoints require credentials, configure the option for each separately and protect both secrets. See the cURL manual and tutorial for the proxy options.
Handle redirects without leaking credentials
Add --location (or -L) when you want cURL to follow redirects:
Rank #4
- POWERFUL SECURITY KEY: The Security Key NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
- WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key NFC secures 100 of your favorite accounts, including email, password managers, and more.
- FAST & CONVENIENT LOGIN: Plug in your Security Key NFC via USB-A and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
- TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
- BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
curl --location --user 'USERNAME:PASSWORD' 'https://example.com/start'
By default, cURL sends credentials supplied with --user only to the initial host, rather than forwarding them to a different host reached through a redirect. This boundary helps prevent accidental credential disclosure.
Quick wins for a faster PC:
Fix the driver behind crashes, sound loss and screen glitchesFind Drivers →Clear out junk files and repair common Windows errorsFree Scan →--location-trusted changes that behavior and permits credential forwarding to other hosts. Do not use it as a routine way to make a redirected request succeed: cURL warns that forwarding credentials beyond the initial host can introduce a security breach. Use it only when you intend to trust the redirect destination and have verified that sending those credentials there is appropriate. See the cURL manual’s redirect options.
Distinguish HTTP Basic from a website login
A website having a username-and-password form does not mean its pages accept HTTP Basic authentication. Many user-facing sites log visitors in through a form and then use cookies; that flow is different from cURL’s --user HTTP authentication. Sending a site’s form password with --user will not automatically submit the form or establish a browser-style login session.
Check the endpoint’s documentation or authentication challenge. HTTP Basic is appropriate only when the server or API says it accepts that scheme. The cURL HTTP scripting guide describes the difference between HTTP authentication and form-based logins.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Troubleshoot a failed Basic Auth request
Authentication is rejected
First confirm that the endpoint actually expects HTTP Basic, then verify the username and password and check that you are using the intended host and resource. Inspect the server’s authentication challenge, commonly given in a WWW-Authenticate response header, to learn which method it offers. Do not assume that a login form or a generic “unauthorized” message means Basic is supported.
Outdated Drivers Are Slowing You Down
One free scan finds every outdated or missing driver and matches the right update for your exact hardware.Free scan · exact hardware matchWindows Errors? Fix Them Before They Spread
Repair common Windows errors and clear accumulated junk for a smoother, more stable PC - no reinstall needed.Free scan · no reinstallThe username or password contains a colon
With --user, cURL splits the supplied value at the first colon. A colon in the password can therefore appear after the separator, but a colon in the username cannot be represented in this form. If the username itself contains a colon, consult the service’s authentication documentation for a supported alternative rather than assuming that quoting changes the parsing rule.
Best Value
- Security Key : Protect your online accounts against unauthorized access by using FIDO2 and U2F authentication with T110. It's the world's most protective security key that works with windows, Mac OS, Linux as well as Chrome, Firefox, Edge and many other major browsers.
- Certified with the new FIDO2 standard, T110 provides the benefit of fast login and strong protection against phishing, account takeover as well as many other online attactks.
- Works with : Bank of America, Github, Google, Microsoft, DUO, Twitter, Facebook, Dropbox, Apple, ebay, BINANCE, mor and more.
- Fits USB-A port : Insert the T110 security key into the USB-A port of each service and log in conveniently with one touch
- For the driver download and user guide, please visit TrustKey Solutions Home support page.
A redirect leads to an authentication failure
Check whether the destination is the same host and whether the redirected endpoint expects the same authentication. Credentials are not forwarded to a different host by default. Avoid immediately switching to --location-trusted; first establish that the destination is trusted and is meant to receive those credentials.
The request succeeds in a browser but fails in cURL
The browser may be using a form login and cookies rather than HTTP Basic. Identify the actual API endpoint and its documented authentication scheme. A site’s interactive sign-in page is not, by itself, evidence that its server expects --user.
The proxy reports an authentication problem
Determine whether the rejection comes from the proxy or the destination server. Use --proxy-user for proxy credentials and --user for the remote server; one does not replace the other. Select --proxy-basic only when Basic is the proxy’s supported method.
The Tool Desk
Outbyte PC Repair FREERepair Windows errors before they cause bigger problemsFix Now →Outbyte Driver Updater FREEScan for outdated or missing drivers - takes under a minuteDriver Scan →The command works locally but leaks a password in automation
Remove the literal password from the command or script, rotate the credential if it has already been exposed, and use a protected secret mechanism or cURL configuration/input path appropriate to the environment. Review shell history, build output and process visibility as applicable; changing to HTTPS does not address local exposure.
Or skip the browser setup
If your task is to capture a webpage rather than authenticate a cURL request, ScreenshotNeo offers a website screenshot API and MCP server. It is not a replacement for Basic Auth, and the example below makes no claim about authenticated pages. For a public page, one GET request returns an image or PDF:
Quick Recap
curl -G "https://api.screenshotneo.com/v1/shot" -d access_key=YOUR_API_KEY --data-urlencode url=https://stripe.com -o shot.webp
See the ScreenshotNeo documentation for request options. Cookie banners, popups and chat widgets are removed before the shot; bot checks, blank pages and failed loads are never billed. Its MCP server lets AI agents take screenshots. The free plan includes 1,000 screenshots a month with no card, and paid plans start at $5 for 3,000.
Sign up for ScreenshotNeo’s free plan.
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

