Sign up free

Htpasswd Generator for Apache and Nginx Basic Auth

Create .htpasswd lines for one user or a whole list, with the Apache or Nginx settings that switch on the password prompt.

About Htpasswd Generator

An .htpasswd file from this htpasswd generator puts a password prompt in front of a staging site, an admin folder or files you share with a client, using the basic authentication built into Apache and Nginx. Enter one user, or several as user:password on separate lines, and use the password generator when you need a new password. Every line comes out hashed and ready to paste into .htpasswd.

Choose APR1-MD5, the lines starting with $apr1$, which is Apache's default and works with Nginx too, or SHA-1 ({SHA}) for older setups. APR1 is salted, so it's the better choice. The output includes Apache and Nginx configuration snippets. Keep .htpasswd outside the public web folder, and serve the site over HTTPS, because basic authentication only encodes the password on its way to the server. Hashing happens in your browser, so passwords never leave your device. An HTTPS site needs a valid certificate, and the SSL Certificate Checker confirms yours is trusted.

How to use Htpasswd Generator

  1. 1
    Enter the users

    Type one user or paste several as user:password, one per line, or generate a password.

  2. 2
    Pick the format

    APR1-MD5 for Apache and Nginx, or SHA-1 if an older system needs it.

  3. 3
    Save the .htpasswd file

    Paste the lines into a .htpasswd file stored outside your web root.

  4. 4
    Add the server config

    Copy the Apache or Nginx snippet, set the path to your file and reload the server.

Why use Cubfile for this

  • Many users at once

    Paste a list of user:password pairs and every line is hashed.

  • Password generator

    Make a random password for a user without leaving the page.

  • Two hash formats

    Salted APR1-MD5, Apache's default, and SHA-1 for older systems.

  • Private hashing

    Passwords are hashed in your browser and never sent anywhere.

FAQ

Htpasswd Generator: questions and answers

Which htpasswd format should I choose?
APR1-MD5. It's salted, it's Apache's default and Nginx accepts it. SHA-1 ({SHA}) isn't salted, so use it only when an old system requires it.
Does the htpasswd file work with Nginx?
Yes. Point auth_basic_user_file at the file, as in the Nginx snippet, and reload Nginx. Both APR1-MD5 and {SHA} lines are accepted.
Where should the .htpasswd file go?
Outside the folder your website is served from, so nobody can download it. The configuration then refers to it by its full path.
Is basic authentication secure?
Only over HTTPS, since the browser sends the password merely encoded. It's fine for staging sites and private folders, but it doesn't replace a proper login on a public app. To keep passwords off plain HTTP, force HTTPS with a site-wide rule from the 301 Redirect Generator.
Are my passwords sent to your server?
No. Hashing runs in your browser, nothing is uploaded and there's no daily limit.
Share Htpasswd Generator with a friendIt runs in any browser, and they can try it without signing up.

Related tools

XML XML Sitemap GeneratorCrawl your site or paste a list of URLs to build an XML sitemap.
HTML Meta Tag GeneratorWrite title, description and robots tags with live length checks and a preview.
TXT Robots.txt GeneratorCreate a robots.txt with presets for search engines and AI crawlers.
JSON Schema Markup GeneratorGenerate JSON-LD for FAQ, articles, products, organizations and more.
HTML Open Graph GeneratorMake Open Graph and Twitter Card tags and preview the share card.
CONF 301 Redirect GeneratorGet redirect rules for Apache, Nginx, IIS, PHP and HTML.
URL UTM Link BuilderAdd UTM tags to links so you can track campaigns in analytics.
HTML Hreflang Tag GeneratorBuild hreflang tags for every language version of a page.