.htaccess Validator

Check an Apache .htaccess file for mistakes before you upload it. Typos in directives, unclosed blocks, bad RewriteRule flags, and invalid patterns are listed by line.

Updated
Runs in your browser. Your data is not uploaded.
Checks as you type.

How to use the .htaccess Validator

  1. Paste the contents of your file into .htaccess content, or upload it.
  2. Press Validate. The file is also checked as you type.
  3. Work through the list of errors and warnings. Each one shows its line number and a suggested fix.

How it works

The file is read line by line, the way Apache reads it: comments start with #, and a line ending in \ continues on the next line.

  • Each directive name is compared with a list of directives allowed in .htaccess. Close misspellings, such as RewriteCondtion, get a suggestion.
  • Opening tags such as <IfModule>, <FilesMatch>, and <If> must be closed in the right order. <Directory> and <VirtualHost> are errors, because Apache refuses them in .htaccess.
  • RewriteRule needs a pattern and a target, and its flags are checked against the known list (L, R=301, NC, QSA, and so on). RewriteCond flags are checked too.
  • Patterns are compiled to catch unbalanced brackets and parentheses. Redirect status codes and ErrorDocument codes are range-checked.

Examples

RewriteEngine On
RewriteCondtion %{HTTPS} off
RewriteRule ^(.*$ https://%{HTTP_HOST}/$1 [R=301,L,X]
<IfModule mod_expires.c>
ExpiresActive On
  • Line 2, error: unknown directive RewriteCondtion. Did you mean RewriteCond?
  • Line 3, error: the pattern ^(.*$ has an unclosed parenthesis.
  • Line 3, error: unknown RewriteRule flag X.
  • Line 4, error: <IfModule> is never closed. Add </IfModule>.

Limitations

  • The validator checks syntax. It can't know which modules your server has loaded, or test what a rule does to real URLs.
  • Patterns are checked with JavaScript regular expressions. Apache uses PCRE, so rare PCRE-only syntax may be flagged even though Apache accepts it.
  • Directives from third-party modules (for example LiteSpeed's cache rules) are reported as unknown warnings, not errors.
  • A file that passes can still fail on a server where AllowOverride forbids the directive.

Frequently asked questions

Why does my .htaccess cause a 500 Internal Server Error?

Apache stops at any directive it doesn't understand or that isn't allowed there. A typo, a missing module, or an unclosed block are the usual causes. The server's error log names the exact line.

Is <Directory> allowed in .htaccess?

No. An .htaccess file already applies to its own directory. Use <Files> or <FilesMatch> for per-file rules instead.

Can this test my rewrite rules against a URL?

No, it checks syntax only. Try the rules on a staging site, or use the Regex Tester to test a pattern against sample paths.

Is my file uploaded?

No. It is checked in your browser.

Often used together with the .htaccess Validator.

  • Htpasswd Generator

    Creates .htpasswd lines with bcrypt, APR1-MD5, or SHA-1 hashes for Basic Auth.

  • Regex Tester

    Highlights regex matches live, lists capture groups and offsets, and previews replacements.