Htpasswd Generator
Create an htpasswd file with bcrypt, SHA-1, or plain hashes. Multi-user, copy or download.
Generate .htpasswd files for Apache and nginx Basic Auth with bcrypt, SHA-1, or plain hashes. Free, offline, runs in your browser. Read more Show less
What is an htpasswd file?
An .htpasswd file stores usernames and hashed passwords for HTTP Basic Authentication. It is used by Apache and nginx to protect directories, staging sites, admin panels, and status pages. Each line contains a username and a password hash, separated by a colon:
alice:$2y$10$...
The file itself is not encrypted. Anyone who obtains it has the hashes and can attempt to crack weak passwords offline. Use strong passwords and correct file permissions (chmod 640, owned by the web server user).
Hash formats
| Format | Prefix | Support | Recommendation |
|---|---|---|---|
| bcrypt | $2y$ | Apache 2.4.4+, nginx with a modern ngx_http_auth_basic_module built against OpenSSL 1.0.1+ | ? Use this |
| SHA-1 | {SHA} | Apache, nginx | ? Legacy - weak |
| MD5 / apr1 | $apr1$ | Apache only | ? Deprecated |
| crypt (DES) | none | Apache only | ? Broken (8 chars, 56-bit) |
| plain | {PLAIN} | Apache only | ? Never use |
This tool supports bcrypt, SHA-1, and plain. bcrypt is the correct choice for anything new. SHA-1 exists here for compatibility with old deployments you cannot change. Plain is here only because some embedded systems still expect it.
Why bcrypt
bcrypt is a password-hashing function specifically designed to be slow. Where MD5 computes billions of hashes per second on a GPU, bcrypt with cost 10 computes around 10 hashes per second per CPU core - and the cost is tunable so it stays slow as hardware gets faster.
The cost factor controls the work: each increment doubles the time. Cost 10 is the default; cost 12 is common for new deployments; cost 14+ is used when the password file protects very sensitive resources and you can tolerate the login latency.
Recommended: cost 10 or 12 for typical web apps. Every login takes a small fraction of a second - that is by design.
How to use
Enter one user per line in the format username:password. Choose the hash type and cost, and the tool produces the .htpasswd content. Copy it or download it as htpasswd.txt.
Save the file on your server (usually alongside your site root, outside the document root) and point your web server configuration at it:
Apache - in .htaccess or your vhost:
AuthType Basic
AuthName "Restricted"
AuthUserFile /etc/apache2/.htpasswd
Require valid-user
nginx - in a location block:
auth_basic "Restricted";
auth_basic_user_file /etc/nginx/.htpasswd;
Reload the web server after editing the file. nginx caches credentials and will not pick up changes until reloaded.
Security notes
Basic Auth is cleartext over HTTP. It sends the password Base64-encoded (not encrypted) in every request. Always use it over HTTPS.
The file must be readable by the web server user only. chown www-data:www-data .htpasswd && chmod 640 .htpasswd on Debian/Ubuntu. chown nginx:nginx on RHEL/CentOS.
Store the file outside the document root. If .htpasswd is inside your site root, some server misconfiguration could serve it to the public. Apache denies access by default (via <FilesMatch>), but nginx does not - you must add an explicit location block that returns 404 for dotfiles.
This tool never sends anything to a server. All hashing happens in your browser. Your passwords stay on your device.
FAQ
What cost factor should I use?
Cost 10 is a safe default. Cost 12 if the site is high-value and logins can afford to be a bit slower. Cost 14 or above is for cases where you specifically want to slow down an attacker who has stolen the file. Each increment doubles the time for both you and the attacker - a good thing, because you only hash once per login and they hash billions of times trying to crack.
Why does bcrypt output look different each time I click Generate?
bcrypt includes a random 16-byte salt in every hash. The same password produces a different string every time - that is by design. All those strings verify correctly against the same password.
Can nginx use bcrypt htpasswd files?
Yes, on nginx 1.0.1 or later built against OpenSSL 1.0.1+. On very old or very custom builds, nginx may only support crypt and apr1. If bcrypt authentication fails on nginx, generate a SHA-1 hash instead.
How many users can I put in one file?
No practical limit. Every line is one user. Both Apache and nginx parse the file linearly - thousands of users is fine.
Is Basic Auth good enough for production?
It is fine for internal tools, staging sites, admin panels on trusted networks, and emergency lockdowns. For user-facing applications, use a proper authentication system (OAuth, SAML, or a session-based login with rate limiting and account recovery). Basic Auth has no rate limiting built in - an attacker can brute force it as fast as your server responds.
Can I use a password with a colon in it?
The tool splits on the first colon only. Everything after that is treated as part of the password, so alice:my:pass produces user alice with password my:pass. The username itself cannot contain a colon (RFC 7617 forbids it).
How do I update a password for an existing user?
Regenerate the file with the new password. htpasswd files are read fresh on every request, so no server restart is needed for Apache. nginx caches credentials - reload with nginx -s reload or systemctl reload nginx.
What about SHA-256 or Argon2?
Neither is supported by Apache or nginx's Basic Auth implementation. bcrypt is the strongest algorithm they both accept.
Command line equivalent
# Apache htpasswd utility
htpasswd -c /etc/apache2/.htpasswd alice # create with alice (prompts for password)
htpasswd /etc/apache2/.htpasswd bob # add bob
htpasswd -B -C 12 /etc/apache2/.htpasswd carol # bcrypt cost 12
htpasswd -nb alice secret # print to stdout
# nginx - no built-in tool; use htpasswd from apache2-utils, or openssl
openssl passwd -apr1 # interactive
# Docker / online alternative
docker run --rm httpd:alpine htpasswd -nbB alice secret
# This tool
# - Fills the same role entirely in your browser
# - Supports bcrypt, SHA-1, and plain
# - Works offline, no install Server configuration
AuthType Basic AuthName "Restricted Area" AuthUserFile /etc/apache2/.htpasswd Require valid-user
auth_basic "Restricted Area"; auth_basic_user_file /etc/nginx/.htpasswd;
chown www-data:www-data /etc/apache2/.htpasswd chmod 640 /etc/apache2/.htpasswd