← All headersRequest header

What is an Authorization header?

Carries credentials to authenticate the client with the server, e.g. a Bearer token or Basic auth string.

Authorization is how the vast majority of authenticated API calls to a website identify the caller, whether that's a Bearer token, an API key, or classic Basic auth. Because an expired credential, a misconfigured auth middleware, or a clock-skew issue on token validation can quietly take an entire authenticated surface offline while public pages keep responding fine, it's worth monitoring authenticated endpoints separately rather than assuming a healthy homepage means a healthy API.

Common use case

A mobile app attaches a Bearer JWT to Authorization on every API call after login, and the server verifies its signature and expiry before processing the request.

Example

Authorization: Bearer eyJhbGciOiJIUzI1NiIs...

History

Part of the original HTTP/1.0 specification, RFC 1945 (1996), originally designed around Basic authentication and later extended to support Bearer, Digest, and other schemes.

Did you know?

Despite the name similarity, it's completely unrelated to the Authorization request in OAuth flows - this header just carries the already-issued credential, not the authorization grant itself.