Apache .htaccess Generator
Pick what your site needs and get a commented .htaccess file, with the modules it needs.
.htaccess
The download is named htaccess.txt; rename it to .htaccess on the server.
What each part does
About the Apache .htaccess Generator
An .htaccess file lets you change how the Apache web server handles your site without touching the main server configuration — the usual way on shared hosting. This generator writes one for Apache HTTP Server 2.4 from the options you pick: HTTPS and www/non-www redirects in a single hop, a bulk list of 301 redirects pasted from a spreadsheet, a single-page-app fallback, custom error pages, browser caching (mod_expires), gzip and Brotli compression, CORS headers, hotlink protection, IP blocking or allow-listing, a maintenance mode and common security headers.
Every section of the file is commented, and the page lists the Apache modules each one needs and the AllowOverride permission the server must grant — the two things behind most “500 Internal Server Error” messages after uploading an .htaccess. The generated rules are tested against Apache HTTP Server 2.4. Nothing you type leaves your browser.
How to use it
- Enter your domain (for example
example.com) and choose whether to force HTTPS and to remove or add “www.”. - Turn on the sections you need. For redirects, paste one “old new” pair per line — copied from a spreadsheet, as CSV, or separated by spaces — and add 410 for pages that are gone.
- Fix anything listed under Check before you upload, and read what each section does and which modules it needs.
- Copy the result or download it, rename the download to
.htaccessand upload it to your site’s root folder (or merge it into the existing one) on a staging copy first. - Test a few URLs: the redirect checker shows each hop and status, and the security headers checker shows the headers.
Examples
Domain example.com · Force HTTPS · Remove www
RewriteCond %{HTTP_HOST} ^www\.example\.com$ [NC]
RewriteRule ^ https://example.com%{REQUEST_URI} [R=301,L]
RewriteCond %{HTTPS} !=on
RewriteRule ^ https://%{HTTP_HOST}%{REQUEST_URI} [R=301,L]http://www.example.com/page goes straight to https://example.com/page — one 301, with the path and query string kept.
/old-page.html,/new-page/ /product.php?id=12,/shop/blue-shirt/ /retired-offer,410
RewriteRule ^/?old-page\.html$ https://example.com/new-page/ [R=301,L]
RewriteCond %{QUERY_STRING} ^id=12$
RewriteRule ^/?product\.php$ https://example.com/shop/blue-shirt/ [R=301,L,QSD]
RewriteRule ^/?retired-offer$ - [G]QSD drops the old query string; [G] answers 410 Gone.
Single-page app fallback: /index.html
FallbackResource /index.html
Deep links such as /dashboard/settings load the app instead of a 404, while real files are served as usual.
Common uses
- Moving a site to HTTPS and settling on one address (with or without www) for search engines.
- Redirecting the old URLs of a redesigned or migrated site with 301s, straight to the final address.
- Hosting a React, Vue, Angular or Svelte app on shared Apache hosting without 404s on reload.
- Speeding up a static site with browser caching and compression.
- Allowing a web font or API file to be used from another domain (CORS), or stopping other sites from embedding your images.
- Taking a site offline for maintenance with a proper 503 while you can still reach it from your own IP address.
Why an .htaccess file causes “500 Internal Server Error”
Apache reads .htaccess on every request, and refuses the whole request when a line is wrong. The two usual causes:
- A module is not loaded. The error log says Invalid command 'Header', perhaps misspelled or defined by a module not included in the server configuration — ask the host to enable mod_headers, or remove that section. Caching and compression are wrapped in
<IfModule>and are simply skipped without their module; redirects, access rules and headers deliberately are not, so you notice instead of silently losing them. - The directive is not allowed in .htaccess. The log says … not allowed here. Each directive belongs to an
AllowOverridecategory: rewrite rules, headers, error pages and compression need FileInfo, caching and the SPA fallback need Indexes, IP rules need AuthConfig, andOptions -Indexesneeds Options. The page lists exactly which ones your file needs; on shared hosting most are usually allowed.
mod_rewrite in .htaccess also needs at least one of the options FollowSymLinks or SymLinksIfOwnerMatch enabled for the folder (Apache 2.4 enables FollowSymLinks by default). Directive syntax, contexts and override categories here follow the Apache HTTP Server 2.4 documentation.
How the redirects are written
All redirects use mod_rewrite, so Apache tries them in the order they appear in the file. The list comes first and points each old URL straight at the final https:// address on your domain; the canonical-host and HTTPS rules follow. Each old URL is matched exactly (^/?old-page\.html$ works both in .htaccess and in the server configuration), and Apache compares it after decoding, so /caf%C3%A9 matches a request for /café. An old URL with a query string is matched on that exact query string, which is then dropped (QSD) unless the new URL brings its own. New URLs are written literally: mod_rewrite would read %2 in /new%20page or $1 as back-references, so %, $ and \ get a backslash (/new\%20page) and the NE flag keeps percent-encoding as it is. For trailing-slash variants, folder moves with wildcards, Nginx or IIS rules, and chain and loop checks, use the 301 redirect generator.
Caching and compression
mod_expires sends both Expires and Cache-Control: max-age for each media type. HTML is set to revalidate every time, so visitors always see new pages; CSS, JavaScript and images can be cached for longer. Use a year only for files whose names change when their content changes (fingerprinted builds); otherwise a visitor may keep an old stylesheet for a year. Compression covers text formats only — JPEG, PNG, WebP, WOFF2, MP4 and ZIP are already compressed. The Apache documentation warns that compressed responses over TLS can be open to the BREACH attack when a page mixes secrets with text an attacker can influence; static sites are not affected.
Behind Cloudflare, a load balancer or another proxy
When HTTPS ends at a proxy, Apache receives plain HTTP and %{HTTPS} is never “on”, so a normal HTTPS rule would redirect forever. Tick TLS ends at a proxy or CDN to also check the X-Forwarded-Proto header the proxy sends — but only if visitors cannot reach Apache directly, because anyone can send that header. For the same reason, IP rules see the proxy’s address unless the server uses mod_remoteip to restore the visitor’s address.
Limitations
- Written for Apache HTTP Server 2.4. Apache 2.2 used different access-control directives (Order/Allow/Deny), and Nginx, IIS and Caddy do not read .htaccess files at all.
- Rules in .htaccess are slower than the same rules in the server configuration, because Apache re-reads the file on every request. If you control the server, put them in the <VirtualHost> instead.
- The generator does not merge with an existing .htaccess: if your CMS (WordPress, for example) has its own block, paste these sections above it and keep its block intact.
- Password protection is not included; create the password file line with the bcrypt generator and add AuthType Basic yourself.
Privacy
Everything happens in your browser. What you enter or open here is not uploaded or stored by MySmartCoPilot.
Frequently asked questions
Where do I put the .htaccess file?
In the root folder of your site (the one with your home page, often public_html or htdocs). The name must be exactly .htaccess, with the leading dot and no extension. The download is named htaccess.txt because browsers do not reliably save files whose names start with a dot — rename it after uploading.
Why do I get a redirect loop after forcing HTTPS?
Almost always because HTTPS ends at a proxy or CDN (Cloudflare, a load balancer, some hosts), so Apache sees every request as plain HTTP. Turn on TLS ends at a proxy or CDN, and on Cloudflare use the Full (strict) SSL mode rather than Flexible.
Should I remove or add www?
Either works for search engines, as long as you pick one and redirect the other with a 301. The bare domain is shorter; www can make cookies and some CDN setups easier. Use the same choice in your sitemap, canonical tags and links.
Is 301 or 302 right for my redirects?
Use 301 (or 308) when a page has moved for good — search engines then treat the new URL as the one to index. Use 302 or 307 for a temporary move, and 410 when a page is gone with no replacement.
Will hotlink protection block search engines or social media previews?
Only requests whose Referer header names another site are blocked; requests without a Referer are always allowed. After turning it on, check your image search results and link previews, and add any site that legitimately shows your images to the allowed list.
Is my configuration uploaded anywhere?
No. The file is built in your browser, and your choices are only remembered in this browser’s local storage.