Developer tool / 24
Apache / Nginx .htpasswd Generator
Generate Apache and Nginx .htpasswd authentication lines and password hashes in client memory.
Apache / Nginx .htpasswd Generator: TOEA writes the line Apache and nginx expect for HTTP basic authentication. The default is Apache's $apr1$ format: the password is salted with eight random characters and folded through a thousand rounds, which is what htpasswd -m produces and what both servers read. Runs 100% locally in your browser with zero server file uploads.
- Category
- Developer tools
- Runs
- In your browser
- Cost
- Free · no sign-up
- Availability
- Ready to use
Wiring the line into a server
Save the line in a file outside the web root, one user:hash per line. For nginx, add auth_basic "Restricted"; and auth_basic_user_file /etc/nginx/.htpasswd; to the location or server block. For Apache, use AuthType Basic, AuthName, AuthUserFile with the file's full path, and Require valid-user. Reload the server afterwards; a syntax error there shows up as every request failing, not only logins.
Dollar signs and plain HTTP
The hash is full of $ characters, and Docker Compose files, .env files, and some proxy labels read $ as the start of a variable. In Compose, write each $ as $$; otherwise the hash is silently shortened and no password matches.
Basic authentication sends the username and password with every request, encoded but not encrypted. Put it behind HTTPS, and treat it as a gate for staging sites and admin paths rather than as a login system for customers.
How to use it
- Enter a username and password.
- Leave the algorithm on Apache MD5 unless you have a reason not to.
- Copy the generated line into your .htpasswd file.
Privacy & limitations
The password is hashed in your browser and never sent anywhere. Nothing is logged, and the salt comes from your browser's own cryptographic random source, so two people generating a line for the same password do not get the same hash.
Related tools
Frequently asked questions
Which algorithm should I pick?
Apache MD5 ($apr1$), the default here. It is salted and iterated, and both Apache and nginx accept it. The {SHA} option is an unsalted SHA-1 digest kept only for older setups that require it — Apache's own htpasswd tool labels that option insecure, because identical passwords produce identical hashes and a lookup table breaks them.
Is this as strong as bcrypt?
No. bcrypt is the stronger choice and Apache supports it, but it cannot be generated here — it needs a Blowfish implementation that would be a large amount of code to ship and to trust. If you want bcrypt, run htpasswd -B -n username locally and paste the result.
Can I check a line before I rely on it?
Yes, and it is worth doing. Save it to a file and run htpasswd -vb yourfile username password — Apache will tell you whether it authenticates. These lines are verified against both htpasswd and openssl passwd -apr1.
Free tool · runs in your browser · no account required