---
title: "HTTP Authorization Manager"
description: "Configure the JMeter HTTP Authorization Manager configuration elements: properties, defaults, and practical usage notes for building reliable load tests."
url: https://docs.jmeter.ai/components/http-authorization-manager/
lastUpdated: 2026-10-01
source: docs.jmeter.ai
---

# HTTP Authorization Manager

*Part of the **Configuration Elements** category. Also documented in context in the [full Component Reference](/user-manual/component-reference/#http-authorization-manager).*

![HTTP Authorization Manager](/images/screenshots/http-config/http-auth-manager.png)

> **Note**
> If there is more than one Authorization Manager in the scope of a Sampler,
> there is currently no way to specify which one is to be used.

The Authorization Manager lets you specify one or more user logins for web pages that are
restricted using server authentication.  You see this type of authentication when you use
your browser to access a restricted page, and your browser displays a login dialog box.  JMeter
transmits the login information when it encounters this type of page.

The Authorization headers may not be shown in the Tree View Listener “`Request`” tab.
The Java implementation does pre-emptive authentication, but it does not
return the Authorization header when JMeter fetches the headers.
The HttpComponents (HC 4.5.X) implementation defaults to pre-emptive since 3.2 and the header will be shown.
To disable this, set the values as below, in which case authentication will only be performed in response to a challenge.

In the file `jmeter.properties` set `httpclient4.auth.preemptive=false`

> **Note**
> Note: the above settings only apply to the HttpClient sampler.

> **Note**
> When looking for a match against a URL, JMeter checks each entry in turn, and stops when it finds the first match.
> Thus the most specific URLs should appear first in the list, followed by less specific ones.
> Duplicate URLs will be ignored.
> If you want to use different usernames/passwords for different threads, you can use variables.
> These can be set up using a [CSV Data Set Config](/components/csv-data-set-config/) Element (for example).

| Name | Required | Description |
| --- | --- | --- |
| Name | No | Descriptive name for this element that is shown in the tree. |
| Clear auth on each iteration | Yes | Used by Kerberos authentication. If checked, authentication will be done on each iteration of Main Thread Group loop even if it has already been done in a previous one.         This is usually useful if each main thread group iteration represents behaviour of one Virtual User. |
| Base URL | Yes | A partial or complete URL that matches one or more HTTP Request URLs.  As an example, say you specify a Base URL of “`http://localhost/restricted/`” with a `Username` of “`jmeter`” and a `Password` of “`jmeter`”.  If you send an HTTP request to the URL “`http://localhost/restricted/ant/myPage.html`”, the Authorization Manager sends the login information for the user named, “`jmeter`”. |
| Username | Yes | The username to authorize. |
| Password | Yes | The password for the user. (N.B. this is stored unencrypted in the test plan) |
| Domain | No | The domain to use for NTLM. |
| Realm | No | The realm to use for NTLM. |
| Mechanism | No | Type of authentication to perform. JMeter can perform different types of authentications based on used Http Samplers: **Java** : `BASIC` **HttpClient 4** : `BASIC`, `DIGEST` and `Kerberos` |

> **Note**
> The Realm only applies to the HttpClient sampler.

**Kerberos Configuration:**
To configure Kerberos you need to setup at least two JVM system properties:

- `-Djava.security.krb5.conf=krb5.conf`
- `-Djava.security.auth.login.config=jaas.conf`

You can also configure those two properties in the file `bin/system.properties`.
Look at the two sample configuration files (`krb5.conf` and `jaas.conf`) located in the JMeter `bin` folder
for references to more documentation, and tweak them to match your Kerberos configuration.

Delegation of credentials is disabled by default for SPNEGO. If you want to enable it, you can do so by setting the property `kerberos.spnego.delegate_cred` to `true`.

When generating a SPN for Kerberos SPNEGO authentication IE and Firefox will omit the port number
from the URL. Chrome has an option (`--enable-auth-negotiate-port`) to include the port
number if it differs from the standard ones (`80` and `443`). That behavior
can be emulated by setting the following JMeter property as below.

In `jmeter.properties` or `user.properties`, set:

- `kerberos.spnego.strip_port=false`

**Controls:**

- `Add` Button - Add an entry to the authorization table.
- `Delete` Button - Delete the currently selected table entry.
- `Load` Button - Load a previously saved authorization table and add the entries to the existing authorization table entries.
- `Save As` Button - Save the current authorization table to a file.

> **Note**
> When you save the Test Plan, JMeter automatically saves all of the authorization
> table entries - including any passwords, which are not encrypted.

#### Authorization Example

[Download](../demos/AuthManagerTestPlan.jmx) this example.  In this example, we created a Test Plan on a local server that sends three HTTP requests, two requiring a login and the
other is open to everyone.  See figure 10 to see the makeup of our Test Plan.  On our server, we have a restricted
directory named, “`secret`”, which contains two files, “`index.html`” and “`index2.html`”.  We created a login id named, “`kevin`”,
which has a password of “`spot`”.  So, in our Authorization Manager, we created an entry for the restricted directory and
a username and password (see figure 11).  The two HTTP requests named “`SecretPage1`” and “`SecretPage2`” make requests
to “`/secret/index.html`” and “`/secret/index2.html`”.  The other HTTP request, named “`NoSecretPage`” makes a request to
“`/index.html`”.

![Figure 10 - Test Plan](/images/screenshots/http-config/auth-manager-example1a.png)

*Figure 10 - Test Plan*

![Figure 11 - Authorization Manager Control Panel](/images/screenshots/http-config/auth-manager-example1b.png)

*Figure 11 - Authorization Manager Control Panel*

When we run the Test Plan, JMeter looks in the Authorization table for the URL it is requesting.  If the Base URL matches
the URL, then JMeter passes this information along with the request.

> **Note**
> You can download the Test Plan, but since it is built as a test for our local server, you will not
> be able to run it.  However, you can use it as a reference in constructing your own Test Plan.

## Related

- [CSV Data Set & Parameterization](/topics/csv-data-set-config-guide/)
- [Thread Calculator](/tools/thread-calculator/)
- [Full Component Reference](/user-manual/component-reference/)
- [Functions and Variables](/user-manual/functions/)
