FIRST CH TOOLS / Development / 67 HTPASSWD GENERATOR

htpasswd Generator (Basic Auth)

Creates .htpasswd lines for HTTP Basic authentication from a user name and password, hashed with bcrypt ($2y$) or apr1-md5. Generate many users at once and get a matching .htaccess or nginx snippet alongside. Passwords are hashed on this page and never leave your device.

1 — Users and passwords

Input
"Generate" makes a 16-character password with your device's random number generator (crypto.getRandomValues). To choose the length and character sets yourself, use the Password Generator and paste the result.
Hash

2 — .htpasswd

Paste into the .htpasswd file on your server, or upload the saved file. The salt is random, so the same password gives a different line every time.
0
Users
—
Hash / cost
—
Time taken
Checks
  • Enter a user name and password, then press "Generate htpasswd".

3 — Basic auth configuration

Keep it outside the public web root (public_html, htdocs…). On shared hosting the control panel shows the absolute path of your home directory.
Visitors from these addresses (an office's fixed IP, say) see the site without a password; everyone else gets the Basic auth prompt. Separate with spaces or commas.
.htaccess

    
  

4 — Verify an existing .htpasswd

When a login fails, check here whether the line in the file and the password actually match. Supports bcrypt ($2y$ / $2b$ / $2a$), apr1, $1$ and {SHA}.

Hashing, salt generation and verification all run on this page; neither passwords nor user names are sent to any server. The page does not accept them as URL parameters either — a password in a URL reaches the server as part of the page request and stays in your history.

How to Use

  1. Enter users and passwordsFor one user, use the fields above; for several, switch to "Many" and type user:password one per line. Leave a password empty to have a 16-character one generated.
  2. Press "Generate htpasswd"You get bcrypt (recommended) or apr1-md5 lines. Copy them or save the file, and put it on the server as .htpasswd outside the public web root.
  3. Paste the configurationEnter the file's absolute path and paste the snippet into the .htaccess of the directory to protect (or the server block for nginx). If a login fails, check the line and password under "Verify".

About This Tool

HTTP Basic authentication is the usual way to keep a staging site or a client preview away from the public. On Apache it takes two files: .htaccess and .htpasswd, which holds one user:hash line per user. This tool builds those lines in your browser for setups where you cannot run the htpasswd command on the server (shared hosting, for example) — and where you would rather not type a client's password into someone else's website. All hashing happens on this page.

bcrypt ($2y$) is recommended. It is the same format as Apache 2.4's htpasswd -B and resists brute force. The cost sets how heavy the hash is; each step doubles it. The default of 5 matches htpasswd -B. With Basic auth the server re-hashes the password on every request (each image and CSS file), so a high cost slows down every page; 5–10 is usual for staging. bcrypt only uses the first 72 bytes of a password.

apr1-md5 ($apr1$) is Apache's own MD5-based scheme. It works on Apache 2.2, which cannot read bcrypt, and on nginx whatever the system. nginx's auth_basic_user_file reads apr1 itself but hands bcrypt to the OS crypt(), so bcrypt support depends on the server. If a bcrypt login fails on nginx, switch to apr1.

Generated lines are checked against Apache's htpasswd -v (verify) and OpenSSL's openssl passwd -apr1. The salt comes from the browser's cryptographic random number generator (crypto.getRandomValues), so the same password produces a different line each time — all of them log in.

Basic auth sends the password in readable form unless the connection is encrypted, so serve the protected site over HTTPS. Keep .htpasswd outside the web root; if it must sit inside, Apache's default configuration refuses to serve files starting with .ht. For the password itself, see the Password Generator; for redirects, the Redirect Generator; for hash values, the Hash Generator.

Other Tools