Htpasswd Generator

Create a secure bcrypt .htpasswd line and .htaccess rules to password-protect a folder.

What is an .htpasswd file?

An .htpasswd file stores usernames and hashed passwords that Apache (and nginx) use for HTTP Basic Authentication, the simple login prompt that protects a folder or a whole website.

How to protect a folder

  1. Generate the line with this tool and save it in a file named .htpasswd, ideally outside your public web folder.
  2. Add the generated rules to an .htaccess file in the folder you want to protect, and set AuthUserFile to the full server path of .htpasswd.
  3. Visit the folder — the browser asks for the username and password.

Why bcrypt?

The tool uses bcrypt ($2y$), the strongest format Apache 2.4 supports. Older formats such as crypt() and MD5 (apr1) are much faster to crack.

nginx

nginx reads the same file with auth_basic "Restricted"; and auth_basic_user_file /path/.htpasswd;.

Frequently asked questions

Can I add several users?

Yes, put one username:hash line per user in the same .htpasswd file.

Is Basic Authentication secure?

Only over HTTPS. Without HTTPS the password is sent in plain text.

Is my password sent to your server?

No, the hash is created in your browser.