Your country

Tools that support it use your country for local currency, number formats, units and paper size. Your choice is saved only in this browser.

Type a name or a two-letter code. Use the up and down arrow keys to move through the countries, Enter to choose one and Escape to close.

.htpasswd Generator

Password lines and config for Apache and nginx Basic authentication, made on your device.

Security No upload Works offline Free, no sign-up

Users

    Each +1 doubles the time. OWASP’s minimum is 10; htpasswd’s default is 5.

    Server configuration

    The name of the protected area; some browsers show it in the login box.

      Apache — .htaccess
       
      Apache — server configuration
       
      nginx
       

      Keep the password file outside the website’s document root so it cannot be downloaded, and serve the protected pages over HTTPS: Basic authentication sends the password with every request, only Base64-encoded.

      Next steps

      About the .htpasswd Generator

      Password-protect a staging site, an admin folder or a status page with HTTP Basic authentication. This tool makes the user:hash lines that Apache httpd and nginx read from a .htpasswd file — one user or a whole list, with generated passwords for anyone who has none — in bcrypt ($2y$), SHA-512 or SHA-256 crypt, Apache MD5 (APR1) or legacy {SHA}, and shows which servers accept each format and how weak the old ones are.

      It also checks a password against an existing line in any of those formats (plus $1$ MD5-crypt, {SSHA}, {PLAIN} and old DES crypt()), updates an existing file without disturbing the other users, and writes the matching .htaccess, Apache and nginx configuration. Everything is computed in your browser; passwords are never sent anywhere.

      How to use it

      1. Type a user name and a password (or press Generate). For several users choose Several and write one name:password per line, or only the name to get a random password.
      2. Choose the format: bcrypt for Apache; on nginx, bcrypt works only where the server’s crypt() supports it, so SHA-512 crypt is the safe choice on Linux.
      3. Press Create, then copy the lines or download the file and upload it to your server, outside the web root (for example /etc/apache2/.htpasswd).
      4. Fill in the realm, path and file location under Server configuration and copy the .htaccess, Apache or nginx snippet.
      5. To test an existing login, choose Verify a line, paste the line (or the whole file) and type the password.

      Examples

      Apache documentation example (APR1)
      Input
      User myName · password myPassword · salt r31.....
      Result
      myName:$apr1$r31.....$HqJZimcKQFAMYayBlzkrA/

      Paste this line under Verify a line with the password myPassword to see a match.

      bcrypt as made by htpasswd -B
      Input
      myName:$2y$05$c4WoMPo3SXsafkva.HHa6uXQZWr7oboPiC2bT/r7q1BB8I2s0BRqC
      Result
      ✓ Match for myPassword — with a warning that cost 5 is below OWASP’s minimum of 10
      A batch with generated passwords
      Input
      alice:Correct-Horse-27
      bob
      carol
      Result
      Three bcrypt lines, plus a table with the 16-character passwords made for bob and carol

      Common uses

      • Locking a staging or preview site so search engines and strangers cannot see it.
      • Protecting /admin, phpMyAdmin, a status page or a monitoring dashboard behind a second password.
      • Moving an old .htpasswd from MD5 or {SHA} to bcrypt: check each password still works, then regenerate.
      • Creating accounts for a whole team at once and sending each person their generated password.

      Which format to choose

      • bcrypt ($2y$) — slow and salted; Apache’s htpasswd documentation calls it "very secure". Apache 2.4 supports it on every platform. Cost 10 or more follows OWASP’s minimum (htpasswd’s own default is 5).
      • SHA-512 / SHA-256 crypt ($6$ / $5$) — salted and iterated (5,000 rounds by default); htpasswd makes them with -5 and -2 on Unix systems whose crypt() supports them, which glibc does since version 2.7.
      • Apache MD5 ($apr1$) — htpasswd’s default and supported by every Apache and nginx, but 1,000 MD5 iterations are cheap to attack today.
      • {SHA} — unsalted SHA-1, which Apache’s and nginx’s documentation both describe as insecure; keep it only to migrate old systems.

      Apache or nginx?

      Apache reads all formats above (on Windows, not the crypt()-based $5$ and $6$). nginx’s auth_basic documentation lists three kinds of password: hashes checked with the system’s crypt(), Apache’s apr1, and the {scheme} forms {PLAIN}, {SHA} and {SSHA}. Because crypt() comes from the operating system, bcrypt works in nginx only where the C library supports it: glibc’s own crypt() does not, while libxcrypt, which some Linux distributions use instead, does. If you are unsure, use SHA-512 crypt on Linux, and test one login before you rely on it.

      Basic authentication in practice

      The browser sends the user name and password with every request, only Base64-encoded, so always serve protected pages over HTTPS. Keep the password file outside the document root so it cannot be downloaded — Apache’s documentation warns that password files should not be fetchable with a browser. A .htaccess file only works when the server allows it (AllowOverride AuthConfig); otherwise put the same lines in the server configuration. User names may not contain ":" and are limited to 255 bytes.

      Limitations

      • Old DES crypt() and $1$ MD5-crypt lines can be checked but not created: both are weak, and DES compares only the first 8 characters.
      • Whether bcrypt or SHA-2 crypt lines work on nginx depends on the operating system’s crypt() function, which this tool cannot check for you.
      • Only HTTP Basic authentication is covered; Digest authentication files (htdigest) are a different format.
      • Generated passwords are shown once and never saved: copy them before you leave the page.

      Privacy

      Everything happens in your browser. What you enter or open here is not uploaded or stored by MySmartCoPilot.

      Frequently asked questions

      Is .htpasswd password protection secure?

      It is fine for keeping strangers and search engines out of staging sites and admin areas, if you use HTTPS, a strong password and bcrypt or SHA-512 crypt. It has no lock-out after failed attempts by default and no two-factor sign-in, so do not use it as the only protection for sensitive data.

      Why do I get a new hash every time for the same password?

      bcrypt, SHA-crypt and APR1 add a random salt to every hash, so the same password gives a different line each time — and every one of them works. Only the unsalted {SHA} format always gives the same result, which is one reason it is insecure.

      Which format should I use for nginx?

      SHA-512 crypt ($6$) works with glibc on most Linux servers. bcrypt is stronger but depends on the server’s crypt() supporting it, so test one login first. APR1 works everywhere but is weak.

      Where do I put the .htpasswd file?

      Anywhere the web server can read but visitors cannot download — outside the document root, for example /etc/apache2/.htpasswd or /etc/nginx/.htpasswd — and point AuthUserFile (Apache) or auth_basic_user_file (nginx) at it with an absolute path.

      Are my passwords sent anywhere?

      No. Hashing and checking run in your browser, in a background worker, and nothing is stored. Only your choice of format and cost is remembered in this browser.

      Quick answers and tool search

      Type to search tools or to get a quick answer, for example 18% of 2500. Use the up and down arrow keys to move through the results, Enter to choose, and Escape to close.