Skip to content
SEO SMO HUB
Get Free Audit

Address: Jaipur, Rajasthan, India

[email protected]

Free Htpasswd Generator

This free htpasswd generator turns usernames and passwords into username:hash lines for the .htpasswd file used by Apache and Nginx basic authentication. Choose bcrypt, the stronger option, or APR1 for older setups, add up to 20 users, and copy the lines with the config snippets that switch protection on. Passwords are hashed for this request only and are not stored.

Htpasswd Generator

Generators and Converters

Free

Up to 20 users. Usernames may use letters, digits and . _ @ -

Passwords are hashed in memory for this request and are not stored or logged.

About this tool

Basic authentication puts a simple username and password prompt in front of a folder or a whole site. It is a quick way to hide a staging site, an admin folder or a draft from search engines and visitors. The server needs a password file where each line is a username, a colon and a password hash, never the password itself.

Enter one user per line as username:password. For each line the tool creates a hash and prints the finished file. Bcrypt is the better choice, since it is slow to guess and is supported by current Apache and Nginx. APR1 is an MD5-based format that works almost everywhere, including older servers, but it is weaker. Salts are random, so hashing the same password twice gives different lines, and both are valid.

Basic authentication sends the password with every request, so always use it over HTTPS. Save the result as .htpasswd outside the public web folder, and never put real passwords you use elsewhere into any online form. This page does not store or log what you type, but for the highest assurance you can generate the file locally with the htpasswd command.

Frequently asked questions

Which hash should I choose, bcrypt or APR1?

Choose bcrypt whenever your server supports it. Apache 2.4 and Nginx both read it, and it is designed to be slow to brute force. APR1 is an older MD5-based format that you only need for very old servers or software that cannot read bcrypt.

Where do I put the .htpasswd file?

Outside the public web root if you can, for example one level above it, and point the server to the full path. A file kept inside the public folder can be downloaded unless the server is set to block it. On Apache, the AuthUserFile line holds the path.

Is basic authentication secure enough?

It is fine for keeping casual visitors and crawlers out of a staging site, but it is not a full login system. The password travels with each request, so use HTTPS only, choose long passwords and avoid reusing them. For real user accounts, use proper application authentication.

Why does the same password give a different hash each time?

Each hash includes a random salt. The salt is stored in the hash, so the server can still check the password. This also means two users with the same password do not share the same line, which is what you want.