Htpasswd generator for Apache password files
Create a username and password-hash entry for an Apache .htpasswd file. Choose the format your server supports, then copy the entry or download a file ready to rename and install.
Loading the tool…
What is an htpasswd entry?
An .htpasswd file stores one username and password hash per line. Apache can use it to check credentials for a restricted area, such as a staging site. This tool creates the entry; your server still needs an authentication configuration that points to the file.
The result has the form username:hash. It contains a password hash, not the original password. Keep the original password for signing in and use the generated entry in the server’s password file.
Configure Apache access
Place your password file outside the public website directory and grant the web server permission to read it. On an Apache server that permits authentication settings in .htaccess, an example configuration is:
AuthType Basic
AuthName "Restricted area"
AuthUserFile /absolute/path/outside/public/.htpasswd
Require valid-user
Replace the example path with the file’s actual absolute path. Use HTTPS: HTTP Basic authentication sends credentials on requests and needs transport encryption. The generated file does not configure or protect a site by itself. These instructions apply to Apache; Cloudflare Workers does not process .htaccess files.
Input limits
The username must be 1–255 UTF-8 bytes without colons, whitespace, or control characters, and must not start with #. Passwords must be nonempty and contain no control characters. Bcrypt passwords are limited to 72 UTF-8 bytes, while this tool accepts up to 255 bytes for APR1. Emoji and accented characters can take several bytes; passwords exceeding the limit are rejected rather than truncated. Password spaces are preserved.
Editing credentials or hash settings clears the previous result. Clear removes the credentials and output and cancels any pending calculation. The tool does not save your work across reloads.
Hash formats
| Format | Entry prefix | When to choose it |
|---|---|---|
| bcrypt | $2y$ | Recommended when supported by your Apache server; cost is adjustable. |
| Apache MD5 / APR1 | $apr1$ | Compatibility with an installation that requires this older format. |
Bcrypt cost defaults to 10. Expand Options to choose 11 or 12, which take more work to compute. Each generation uses a fresh random salt, so the same password produces different valid hashes.
Bcrypt entries begin with $2y$; Apache MD5 entries begin with $apr1$. APR1 is the older Apache-specific format, not a plain MD5 digest. This tool does not generate unsalted SHA-1, traditional DES crypt, or plaintext password entries.
How to use this tool
- Enter a username and password. Alternatively, select Random password beside Password. Use Show password to check it and save the password before leaving the page; the generated hash cannot be used to recover it.
- Choose the hash format. Keep bcrypt for a server that supports it. The default cost is 10; expand Options if you need a higher cost, which takes longer to calculate. Use Apache MD5 / APR1 only when an older installation requires it.
- Select Generate entry. Wait for the
username:hashline to appear. If a field shows an error, correct it and generate again. Editing the credentials or hash settings clears the previous result. - Save the entry. Select Copy entry to add it to your password file, preserving other users’ entries and replacing any entry for the same username. Or choose Download file, then rename
htpasswd.txtto.htpasswdon your server.
Keep the password file outside the public website directory. The Apache configuration example on this page explains how to reference it; generating the file alone does not enable authentication. Clear removes the credentials and output and cancels a pending calculation.
Your tool data stays in your browser
This tool processes your data on your device. The text, files, or passwords you enter and the results it creates are not sent to our servers or any other server.
Page and asset requests still occur. Production pages also load Google Tag Manager and AdSense advertising; tool code does not send inputs or results to analytics or ads. See our privacy policy.
To inspect requests while using the tool, open your browser's developer tools and select Network. Try it with sample data.
Read How to check website network requests in Chrome, Firefox, Edge, and Safari.
Learn more
- Apache htpasswd manual - command-line options for creating and managing password files.
- Apache password formats - supported hash formats and their identifying prefixes.
- Apache authentication guide - how to connect a password file to server access rules.