Htpasswd Generator

Create .htpasswd entries for HTTP Basic Authentication on Apache or Nginx. Passwords are hashed with bcrypt, APR1-MD5, or SHA-1 right in your browser.

Updated
Hashed in your browser. Passwords are never sent.

Apache (.htaccess)

        
Nginx (server or location block)

        

How to use the Htpasswd Generator

  1. Enter a Username and Password, or press Random for a strong password.
  2. Pick the Algorithm. Bcrypt is the safest; raise the Cost to make each guess slower for attackers.
  3. Press Add user. Repeat for more users, then copy or download the .htpasswd file and the server snippet.

How it works

Each line of an .htpasswd file is username:hash. The server hashes the password a visitor types and compares it with the stored hash, so the file never holds the password itself.

  • bcrypt ($2y$10$...) adds a random 16-byte salt and repeats the work 2^cost times. Cost 10 means 1,024 rounds. Apache 2.4+ and Nginx both support it.
  • APR1 ($apr1$salt$...) is Apache's MD5-based scheme with an 8-character salt and 1,000 rounds. It is older and much faster to crack, but works everywhere.
  • SHA-1 ({SHA}...) is one unsalted SHA-1 hash in Base64. It exists for compatibility only.
  • Salts come from crypto.getRandomValues, so hashing the same password twice gives different lines. Both are valid.

Examples

  • User admin, password secret, SHA-1: admin:{SHA}5en6G6MezRroT3XKqkdPOmY/BfQ=. This line is always the same, because SHA-1 has no salt.
  • The same user with bcrypt, cost 10, gives a line like admin:$2y$10$ followed by 53 more characters: 22 of salt and 31 of hash. The salt changes each time.
  • With APR1 the line looks like admin:$apr1$Xc3bQ9mz$ followed by a 22-character hash.

Limitations

  • Basic Authentication sends the password with every request, only Base64 encoded. Use it over HTTPS only.
  • Plain crypt() DES hashes are not offered, because they only use the first 8 characters of the password.
  • High bcrypt costs are slow on purpose: cost 14 can take a few seconds in the browser, and it also slows every login on your server.
  • Store the .htpasswd file outside your public web folder if you can.

Frequently asked questions

Which algorithm should I use?

Bcrypt with cost 10 to 12. It is salted and slow to brute-force, and Apache 2.4+ and Nginx support it. Use APR1 only for very old servers.

How do I protect a folder with the file?

For Apache, add AuthType Basic, AuthName, AuthUserFile /full/path/.htpasswd, and Require valid-user to the folder's .htaccess. The tool shows the exact snippet, plus the Nginx version.

Are my passwords sent to your server?

No. Hashing runs in your browser with JavaScript, and nothing you type is uploaded.

Why does bcrypt start with $2y$?

$2y$ is the bcrypt version tag that Apache's htpasswd -B writes. $2a$ and $2b$ hashes are also accepted by most servers.

Often used together with the Htpasswd Generator.