Create the HTTP Basic Authorization header from a username and password, plus cURL and fetch snippets.
Base64 is encoding, not encryption — anyone who sees the header can read the password. Only use Basic authentication over HTTPS.
Only over HTTPS. The password is just Base64-encoded, not encrypted.
No, the colon separates the username from the password.
No. Everything is worked out in your browser and nothing you type is sent to a server.