How to protect a folder
- Generate the line with this tool and save it in a file named
.htpasswd, ideally outside your public web folder. - Add the generated rules to an
.htaccessfile in the folder you want to protect, and setAuthUserFileto the full server path of .htpasswd. - Visit the folder — the browser asks for the username and password.
Why bcrypt?
The tool uses bcrypt ($2y$), the strongest format Apache 2.4 supports. Older formats such as crypt() and MD5 (apr1) are much faster to crack.
nginx
nginx reads the same file with auth_basic "Restricted"; and auth_basic_user_file /path/.htpasswd;.
Frequently asked questions
Can I add several users?
Yes, put one username:hash line per user in the same .htpasswd file.
Is Basic Authentication secure?
Only over HTTPS. Without HTTPS the password is sent in plain text.
Is my password sent to your server?
No, the hash is created in your browser.

