.htpasswd File Generator

Generate .htpasswd files for Apache and Nginx Basic Authentication securely in your browser. Supports bcrypt, APR1-MD5, and SHA-1. Passwords are never sent to the server.

What is an htpasswd file?

An htpasswd file is a plain text file that stores one username-and-hashed-password pair per line, in the format username:hash. Apache and Nginx read this file to verify credentials submitted by a visitor before granting access to whatever area it protects. Traditionally, it's created and updated on the server itself using the htpasswd command-line utility. In practice, though, that isn't always convenient — many managed hosting plans, restrictive shared-hosting environments, or quick one-off situations don't give you easy SSH or terminal access at all.

That's the gap this tool fills: it produces the exact same file format entirely in your browser, with no server access or extra software required. You choose whether the password should be hashed with bcrypt, APR1-MD5, or SHA-1, and the matching username:hash line appears instantly, ready to copy or download. Every calculation happens locally via JavaScript — the plaintext password you type never leaves your machine or travels across the network in any form. Once generated, the resulting file should be placed outside your server's DocumentRoot and referenced through the AuthUserFile directive, so it can never be fetched directly by a browser request.

How to generate a .htpasswd file

  1. Add a user row Click "Add user" once for every account you need. Each row in the table becomes exactly one user entry in the final file.
  2. Enter username and password For each row, type the username and the password you want that user to have. Use the eye icon to toggle visibility and double-check what you typed.
  3. Choose an algorithm and cost Pick bcrypt, APR1-MD5, or SHA-1 per row. When bcrypt is selected, you can also adjust the cost value to balance security against computation time.
  4. Generate Clicking "Generate" runs the hashing immediately in your browser. A preview of the complete .htpasswd file content appears right below.
  5. Copy or download Copy the result to your clipboard, or download it as a ready-made file so you can upload it straight to your server.

Tips for getting more out of it

  • Use bcrypt: The most secure algorithm available. Works with Apache 2.4+ and Nginx. Higher cost values slow down hashing and increase resistance to brute-force attacks (10 is a common default).
  • APR1-MD5 ($apr1$) is for compatibility with Apache 2.2 or older. It works with virtually all Apache and Nginx versions.
  • SHA-1 ({SHA}) has low collision resistance and is not recommended. Use it only in legacy environments that require backward compatibility.
  • Place the .htpasswd file outside the DocumentRoot (or Nginx's web root) so that it cannot be accessed directly over the web.
  • Always use HTTPS. Basic Authentication credentials are only Base64-encoded, not encrypted — they travel in plain text over HTTP.

Use cases

Shield a pre-launch staging site

A site that isn't public yet can be hidden from search engine crawlers and curious third parties in minutes with a quick Basic Auth wall.

Lock down internal admin panels

Homegrown dashboards or internal tools that never got their own login system can gain a simple layer of access control almost instantly.

Add defense in depth alongside IP restriction

When restricting access by IP address alone isn't practical — say, a team accessing from many different locations — Basic Auth adds a useful second layer.

Protect only specific API endpoints

Using location or Directory directives, you can require authentication for a single path while leaving the rest of the service open.

Add a new user to a live service

For a service that's already running in production, you can generate just the one additional line needed and append it to the existing file.

Glossary

Basic Authentication
A standard HTTP authentication scheme. The username and password are Base64-encoded and sent with every request in the Authorization header, then verified on the server.
bcrypt
A password-hashing algorithm that builds in a random salt. Its adjustable cost factor keeps computation slow enough to resist brute-force attacks even as hardware gets faster, making it the currently recommended choice.
APR1-MD5
Apache's own MD5-based hash format, identifiable by its $apr1$ prefix. It's mainly kept around for compatibility with older Apache installations.
SHA-1 ({SHA})
A hash format marked with the {SHA} prefix. It uses no salt and has weak collision resistance, so it's no longer recommended for new setups.
Salt
A random string appended to a password before it's hashed. It ensures the same password produces a different hash every time it's generated, which defeats precomputed rainbow-table attacks.
DocumentRoot
The directory a web server treats as the root of publicly served files. The .htpasswd file must live outside it, or it could be read directly through a browser request.
AuthUserFile
An Apache configuration directive that specifies the path to the .htpasswd file used to verify credentials for Basic Authentication.

FAQ

Add the following to your .htaccess or httpd.conf, pointing AuthUserFile at your generated .htpasswd file:
AuthType Basic
AuthName "Restricted Area"
AuthUserFile /etc/apache2/.htpasswd
Require valid-user

Add the directives to your nginx.conf or the relevant server block:
location /admin {
    auth_basic "Restricted Area";
    auth_basic_user_file /etc/nginx/.htpasswd;
}
Nginx supports both bcrypt and APR1-MD5.

bcrypt is strongly recommended for any Apache 2.4+ or Nginx setup. Use APR1-MD5 only when you need compatibility with Apache 2.2 or older. Avoid SHA-1 unless specifically required by a legacy system.

Simply append the generated line (username:hash) to the end of your existing file. Each line represents one user. Blank lines and lines starting with # are ignored.

Yes. All hashing happens entirely in your browser using JavaScript. No password data is transmitted to the server. That said, always use this tool on a secure HTTPS page and handle the generated file carefully.
Tool-kun

Side Note — Why Basic Auth survives despite its age

HTTP Basic Authentication was defined in 1999 by RFC 2617 (later updated to RFC 7617). The mechanism is simple: concatenate username and password with :, Base64-encode the result, and send it in the Authorization header.

Its simplicity is exactly why it's still widely used. It's a go-to for staging environments, internal tools, or as a first line of defense combined with IP allowlisting. Two or three config lines are all you need — no extra middleware or database required.

The caveats are real, though: no logout mechanism (the session persists until the browser is closed), no built-in password expiry, and no multi-factor authentication. For production services with genuine security requirements, consider OAuth 2.0 or OIDC instead.