FIRST CH TOOLS / Development / 67 HTPASSWD GENERATOR
htpasswd Generator (Basic Auth)
Creates .htpasswd lines for HTTP Basic authentication from a user name and password, hashed with bcrypt ($2y$) or apr1-md5. Generate many users at once and get a matching .htaccess or nginx snippet alongside. Passwords are hashed on this page and never leave your device.
1 — Users and passwords
2 — .htpasswd
- Enter a user name and password, then press "Generate htpasswd".
3 — Basic auth configuration
4 — Verify an existing .htpasswd
Hashing, salt generation and verification all run on this page; neither passwords nor user names are sent to any server. The page does not accept them as URL parameters either — a password in a URL reaches the server as part of the page request and stays in your history.
How to Use
- Enter users and passwordsFor one user, use the fields above; for several, switch to "Many" and type user:password one per line. Leave a password empty to have a 16-character one generated.
- Press "Generate htpasswd"You get bcrypt (recommended) or apr1-md5 lines. Copy them or save the file, and put it on the server as .htpasswd outside the public web root.
- Paste the configurationEnter the file's absolute path and paste the snippet into the .htaccess of the directory to protect (or the server block for nginx). If a login fails, check the line and password under "Verify".
About This Tool
HTTP Basic authentication is the usual way to keep a staging site or a client preview away from the public. On Apache it takes two files: .htaccess and .htpasswd, which holds one user:hash line per user. This tool builds those lines in your browser for setups where you cannot run the htpasswd command on the server (shared hosting, for example) — and where you would rather not type a client's password into someone else's website. All hashing happens on this page.
bcrypt ($2y$) is recommended. It is the same format as Apache 2.4's htpasswd -B and resists brute force. The cost sets how heavy the hash is; each step doubles it. The default of 5 matches htpasswd -B. With Basic auth the server re-hashes the password on every request (each image and CSS file), so a high cost slows down every page; 5–10 is usual for staging. bcrypt only uses the first 72 bytes of a password.
apr1-md5 ($apr1$) is Apache's own MD5-based scheme. It works on Apache 2.2, which cannot read bcrypt, and on nginx whatever the system. nginx's auth_basic_user_file reads apr1 itself but hands bcrypt to the OS crypt(), so bcrypt support depends on the server. If a bcrypt login fails on nginx, switch to apr1.
Generated lines are checked against Apache's htpasswd -v (verify) and OpenSSL's openssl passwd -apr1. The salt comes from the browser's cryptographic random number generator (crypto.getRandomValues), so the same password produces a different line each time — all of them log in.
Basic auth sends the password in readable form unless the connection is encrypted, so serve the protected site over HTTPS. Keep .htpasswd outside the web root; if it must sit inside, Apache's default configuration refuses to serve files starting with .ht. For the password itself, see the Password Generator; for redirects, the Redirect Generator; for hash values, the Hash Generator.
Other Tools
- 01Batch Image → WebPWebP Converter
- 02White Background RemoverWhite BG Remover
- 03WCAG Contrast CheckerContrast Checker
- 04Character CounterCharacter Counter
- 05llms.txt Generatorllms.txt Generator
- 06JSON-LD GeneratorJSON-LD Generator
- 07Markdown → PDFMD → PDF
- 08OGP Meta Tag WizardOGP Wizard
- 09Favicon GeneratorFavicon Generator
- 10TikTok PublisherTikTok Publisher
- 11Encoding & Line Ending ConverterEncoding Converter
- 12Batch Image → AVIF + pictureAVIF Converter
- 13Test Data GeneratorTest Data Generator
- 14Marp Markdown → SlidesMarp Slides
- 15Text & Code Diff CheckerDiff Checker
- 16Cron Explainer & Next RunsCron Explainer
- 17Base64 & Data URI EncoderBase64 & Data URI
- 18URL Parameter Editor & UTM BuilderURL Parameters
- 19HTML Entity Escape & UnescapeHTML Escape
- 20JSON ⇄ YAML ConverterJSON ⇄ YAML
- 21PX ⇄ REM / EM ConverterPX ⇄ REM / EM 単位変換
- 22Color Converter & AlphaColorコード変換&アルファ透過
- 23MD5 / SHA-256 Hash Generatorハッシュ生成
- 24JWT Decoder & Expiry CheckerJWTデコーダー&有効期限チェッカー
- 25User-Agent ParserUser-Agent解析&デバイス判定
- 26UUID & ULID GeneratorUUID (v4) & ULID 一括生成
- 27Aspect Ratio Calculatorアスペクト比計算&サイズ算出
- 28Markdown Table GeneratorMarkdownテーブル整形&CSV/TSV変換
- 29SQL Query FormatterSQL Formatter
- 30QR Code GeneratorQR Code Generator
- 31Regex Tester正規表現テスター
- 32Unix Timestamp ConverterUNIXタイムスタンプ⇄日時変換
- 33New Tab Memo新規タブメモ帳
- 34Image Resizer & Cropper画像リサイズ&クロップ
- 35EXIF Viewer & RemoverEXIF情報の確認&除去
- 36robots.txt Generatorrobots.txt ジェネレーター
- 37Password Generator安全なパスワード生成
- 38Case Converter文字列ケース変換
- 39CSV/TSV ⇄ JSON ConverterCSV/TSV ⇄ JSON 相互変換
- 40PDF Merge, Split & ExtractPDF結合・分割・ページ抽出
- 41Full-width ⇄ Half-width Converter全角⇄半角変換&テキストクリーナー
- 42X (Twitter) Post CounterX(Twitter)投稿の文字ウェイト計算
- 43CSS clamp() Fluid Typography CalculatorCSS clamp() 計算機
- 44CSS Gradient GeneratorCSSグラデーションジェネレーター
- 45Image Colour Palette Extractor画像からカラーパレット抽出
- 46QR Code ReaderQRコード読み取り
- 47SVG Optimizer & Data URISVG最適化&data URI化
- 48Redirect Generatorリダイレクトルール ジェネレーター
- 49IP / CIDR CalculatorIPアドレス・CIDR計算機
- 50ICS Calendar Event GeneratorICS Generator
- 51cubic-bezier Easing Preview & ComparisonEasing Preview
- 52CSS box-shadow Generatorbox-shadow ジェネレーター
- 53Japanese Dummy Text Generator和文ダミーテキスト生成
- 54Social Media Image ResizerSNS画像サイズ一括書き出し
- 55Time Zone Converter & World Clockタイムゾーン変換・世界時計
- 56Date & Business Day Calculator日数・営業日計算
- 57HTML → MarkdownHTML→Markdown変換
- 58HEIC to JPEG/PNG ConverterHEIC Converter
- 59Print Size & DPI Calculator印刷サイズ・DPI計算機
- 60Color Blindness SimulatorColor Blindness Simulator
- 61SERP Preview & Meta Tag Length CheckerSERPプレビュー&メタタグ文字数チェック
- 62Flexbox & CSS Grid GeneratorFlexbox / CSS Grid ジェネレーター
- 63Text Line Toolsテキスト行操作ツール
- 64Screenshot Frame & Background Makerスクリーンショット枠装飾
- 65Japanese Era ⇄ Western Calendar Converter和暦 ⇄ 西暦変換
- 66URL Slug Generator (Japanese → Romaji)URLスラッグ生成(日本語→ローマ字)
- 68OGP Image GeneratorOGP画像ジェネレーター