Htpasswd Generator Update: bcrypt, Adjustable Cost and Apache MD5
Our htpasswd generator now gives you a choice of bcrypt with an adjustable cost or Apache MD5 / APR1. Bcrypt is selected by default, with cost 10; costs 11 and 12 are available in Options. APR1 remains available when an existing server requires the older format.
This makes the tool useful both for setting up a new password-protected Apache directory and for maintaining an installation with specific compatibility requirements. You can generate an entry in your browser, copy it into an existing password file, or download it for installation on your server.
What does an htpasswd generator actually produce?
An .htpasswd file contains entries in the form username:hash. Apache reads this file when checking access to a protected area, such as a staging website or a client preview. The hash represents the password; it is not the password you type into the browser’s sign-in prompt.
Hashing is a one-way operation, rather than encryption with a decryption key. Someone who obtains a password hash can still try candidate passwords against it, which is why the hashing method and the strength of your password matter. A deliberately slow password hash makes each guess more expensive. OWASP’s password storage guide explains this distinction.
bcrypt or Apache MD5: which should you choose?
| Format in the generator | Output prefix | Best fit |
|---|---|---|
| bcrypt | $2y$ | The recommended choice of these two formats when your Apache installation supports it. |
| Apache MD5 / APR1 | $apr1$ | Compatibility with an older installation that specifically needs APR1. |
APR1 is Apache’s salted, iterated MD5 password format. It is not a plain MD5 checksum, so pasting an ordinary MD5 digest into a password file is not equivalent. Apache documents both formats and their prefixes in its password formats reference.
Bcrypt lets you increase the work involved in computing and checking a hash. For this Apache-focused tool, it is the preferred option over APR1. That does not make it a universal recommendation for every new authentication system: OWASP recommends Argon2id for new application password storage where available, and gives separate guidance for systems using bcrypt. Choose within the formats your server actually supports.
Both options in our generator use a fresh random salt. Generating an entry twice for the same password therefore produces different hashes that can both verify that password. You do not need to copy or configure the salt separately.
What does bcrypt cost mean?
Cost is a work factor, not a price or a password length. Open Options while bcrypt is selected to choose 10, 11, or 12.
| Cost | Approximate hashing work relative to cost 10 | Practical effect |
|---|---|---|
| 10 | 1 times | The generator’s default. |
| 11 | 2 times | More work for each generation and verification. |
| 12 | 4 times | More work again, with a greater performance cost. |
The factor grows exponentially: increasing the cost by one roughly doubles the main hashing work. It does not mean ten or twelve simple hashing passes. The OpenBSD bcrypt documentation describes how this logarithmic value is stored in the hash.
For example, a bcrypt entry generated at cost 10 starts with username:$2y$10$. The remaining characters contain the salt and hash. Apache reads the cost from the entry, so there is no separate cost directive to add to your authentication configuration.
A higher cost also takes more time on your server when it verifies credentials. Try the default, then test higher settings against your server’s capacity and expected traffic. Browser generation time alone does not tell you how the server will perform. Apache’s htpasswd manual documents the corresponding command-line -B and -C options; our default of 10 is the web tool’s own setting.
Create and install an entry
- Open the htpasswd generator and enter a username and password. You can also choose Random password; save that password before leaving the page.
- Keep bcrypt selected for a compatible server. Open Options to adjust its cost, or select Apache MD5 / APR1 if your installation requires it.
- Select Generate entry, then Copy entry or Download file. Downloads are named
htpasswd.txt; rename the file to.htpasswdon your server if that is the name your configuration uses. - Add the entry to the server’s password file, preserving other users. Replace an existing entry for the same username instead of adding a duplicate.
Changing the cost does not update entries already installed on your server. Generate a replacement using the password and new settings, then replace the old entry. The tool cannot convert an existing APR1 hash into bcrypt without the password.
Keep the password file outside the public website directory. Configure Apache to use it, and serve the protected area over HTTPS: Basic authentication needs transport encryption even when the stored password uses bcrypt. Generating a file alone does not enable access protection. The tool includes a configuration example, and the Apache authentication guide explains the server setup.
Local processing and clearer limits
The tool generates hashes in your browser without uploading your username or password. It also checks input before calculating: bcrypt accepts up to 72 UTF-8 bytes, and our APR1 option accepts up to 255 bytes. Accented characters and emoji can occupy more than one byte. Overlong passwords are rejected rather than silently shortened.
Editing credentials or hash settings clears the old result, so it is harder to copy an entry for settings you have already changed. Work is not saved across reloads. Ordinary page loading still involves network requests; our guide to checking website network requests shows how to inspect that activity.
More help for your next web project
Preparing a client preview? Use the Lorem Ipsum generator to fill the layout, and read about its new HTML and list options. For HTTP troubleshooting, the cURL command builder prepares basic requests, while our cURL command guide covers additional terminal options and examples.
Create your Apache password entry with the format and cost that fit your server.