Most clients build this header for you from a proxy URL such as http://USERNAME:PASSWORD@HOST:PORT. The value is Basic followed by USERNAME:PASSWORD in base64:

Proxy-Authorization: Basic VVNFUk5BTUU6UEFTU1dPUkQ=

Base64 is an encoding, not encryption. Anyone who can read the connection between you and the proxy can decode it, which is one reason to keep proxy credentials out of shared logs, screenshots and committed code.

Who sees it

The header is addressed to the proxy, and a proxy removes it before forwarding a plain HTTP request. For HTTPS sites it only appears on the CONNECT request that opens the tunnel, so the website never receives it.

When it goes wrong

A missing or wrong header gets 407 Proxy Authentication Required back from the proxy, often with a Proxy-Authenticate header naming the scheme it expects. Special characters in a password (@, :, /) must be percent-encoded inside a proxy URL, or the client will split the URL in the wrong place. If your tool cannot send proxy credentials at all, as with Chromium and SOCKS5, authorise by IP instead: the proxy authentication guide compares both.