Htpasswd Generator

Create .htpasswd password lines for Apache and Nginx Basic Auth, with bcrypt, APR1-MD5 or SHA-1 hashes.

Passwords are hashed in your browser and never sent anywhere.

Most Nginx servers cannot check bcrypt hashes (it depends on the system's crypt library). For Nginx, choose APR1-MD5.

Htpasswd Generator

HTTP Basic Authentication is the quickest way to put a password on a staging site, an admin folder or a private page: the browser asks for a user name and password before anything loads. The passwords live in a .htpasswd file as hashes, not as plain text. This generator creates those lines for one or more users with bcrypt (the strongest option Apache supports), APR1-MD5 (works on both Apache and Nginx) or legacy SHA-1, and gives you the matching Apache .htaccess and Nginx configuration. The hashing runs in your browser, so the passwords are never sent to us.

How to use Htpasswd Generator

  1. Enter a user name and a password, or click Generate for a strong random password. Add more users if you need them.
  2. Choose the hash: bcrypt for Apache, APR1-MD5 if the site runs on Nginx.
  3. Click Create .htpasswd, then download the file or copy its lines.
  4. Upload the file to the server (ideally outside the public folder) and add the Apache or Nginx snippet, with the file's full path.

When it comes in handy

  • Hiding a staging or development site from visitors and search engines.
  • Adding a second password in front of /wp-admin or a control panel.
  • Protecting a folder of private downloads.

Frequently asked questions

Which hash should I choose?
Use bcrypt on Apache 2.4: it is slow to crack on purpose. Many Nginx builds cannot check bcrypt hashes, so use APR1-MD5 for Nginx. Avoid SHA-1 unless an old system needs it; it is unsalted and fast to crack.
Is Basic Auth secure?
The password is only encoded, not encrypted, on the way to the server, so always use it over HTTPS. For a staging site or an extra layer in front of a login page it works well; it is not a replacement for a proper user system.
Can I add more users later?
Yes. Each line of .htpasswd is one user. Generate a new line and add it to the existing file.
Are my passwords sent anywhere?
No. The hashes are created in your browser with JavaScript.

Choose which cookies SEOpeck may use. You can change this at any time from "Cookie settings" at the bottom of every page.