htpasswd Generator - Create Apache Password Files Online

Developer & Encoding Tools 4.7 Active

Create htpasswd entries for Apache Basic Authentication. Generate username and password credentials for .htaccess-protected directories and web server access.

24,721
23,721
4,422
Updated Jan 15 Use Tool

Tool Interface

🔒 Everything happens in your browser — your password is never sent anywhere.
No entries yet — add one above.
  • Upload the downloaded .htpasswd file to your server, ideally outside the public web root.
  • In Apache, add to your config or .htaccess: AuthType Basic, AuthUserFile /path/to/.htpasswd, Require valid-user.
  • In Nginx: auth_basic "Restricted"; and auth_basic_user_file /path/to/.htpasswd;
  • Nginx's basic auth only supports certain hash formats depending on version/build — bcrypt is supported since Nginx 1.0.3+ with a recent build; check your version if entries don't work.
  • You can add multiple username/password entries before downloading — each becomes its own line in the file.

Rate this tool

SPONSORED

About This Tool

Related guide: How to Password-Protect a Folder With .htaccess

htpasswd Generator – Create Apache Password Files Online

Apache HTTP Server can use Basic Authentication to restrict access to a website, directory, or file. The credentials are stored in an .htpasswd file as username:hash pairs — never as plain-text passwords. Trencada's htpasswd Generator creates properly formatted htpasswd entries in seconds: type a username, enter or generate a password, choose bcrypt or SHA-1 hashing, and copy or download the result. No signup needed — your passwords are hashed locally in your browser and never sent anywhere (the page only loads the bcrypt hashing library from cdnjs.cloudflare.com).

How to Use the htpasswd Generator

  1. Enter a username. Type the username that will be used for authentication. Usernames may contain letters, numbers, and _, ., or -.
  2. Enter or generate a password. Type a password, or click "Generate a random password" for a strong 16-character one. Use the Show/Hide toggle to check what you typed.
  3. Choose the hash format. Select bcrypt (recommended) or SHA-1 (legacy, insecure). For bcrypt, pick a cost: 8 (fast), 10 (default), or 12 (slower, stronger).
  4. Generate and add the entry. Click "Generate & Add Entry" — the username:hash line appears in your entries list. Repeat for more users, or remove an entry if needed. Each entry becomes its own line in the final file.
  5. Copy or download. Click "Copy All Lines" or "Download .htpasswd" to save the finished file (downloaded as .htpasswd).
  6. Install it on your server. Upload the file to your server — ideally outside the public web root — and reference it in your configuration. For Apache: AuthType Basic, AuthName "Restricted Area", AuthUserFile /path/to/.htpasswd, Require valid-user. For Nginx: auth_basic "Restricted"; and auth_basic_user_file /path/to/.htpasswd;. The tool's built-in "How to Use Your .htpasswd File" panel shows the exact lines.

Key Features

  • bcrypt hashing (recommended) with adjustable cost (8, 10, or 12), plus legacy SHA-1 support for older setups.
  • Random password generator with a show/hide password toggle.
  • Multiple user entries — build a complete .htpasswd file with one line per user before downloading.
  • Copy All Lines or download the finished file as .htpasswd.
  • Username validation with clear error notices before anything is generated.
  • Built-in server setup guide — exact Apache and Nginx configuration lines right inside the tool.
  • Private by design — hashing runs in your browser; your passwords are never uploaded or stored by Trencada. (The page loads the bcrypt library from cdnjs.cloudflare.com; no password data is ever sent out.)

Example htpasswd Entry

A generated htpasswd entry follows this structure:

username:hash

For example, a bcrypt entry looks like:

admin:$2y$10$...

The hash portion depends on the selected hashing method. Never replace the generated hash with the plain-text password.

Hash Formats

  • bcrypt — the recommended choice: strong, adaptive, and supported by modern Apache and Nginx builds.
  • SHA-1 — legacy format included for older setups; considered insecure for new deployments.

Why Choose Trencada?

  • Free and unlimited — generate as many htpasswd entries as you need.
  • No signup, nothing uploaded — every hash is computed locally in your browser.
  • Server-ready output — username:hash lines you can paste straight into your .htpasswd file.
  • Guidance included — from choosing a hash format to Apache/Nginx config lines and security best practices like keeping the file outside the web root and always using HTTPS with Basic Authentication.
  • Part of a complete developer toolkit — pair it with our Chmod Calculator for safe file permissions, our Cron Expression tool for scheduling server tasks, or our Hash Generator for other digest formats.

Related Developer and Security Tools

Frequently Asked Questions

What is an htpasswd generator?

An htpasswd generator creates a username and password hash in a format that Apache can use for Basic Authentication, producing a username:hash entry ready to paste into an .htpasswd file.

What is an .htpasswd file?

An .htpasswd file is commonly used by Apache HTTP Server to store username and password-hash pairs for HTTP Basic Authentication.

How do I create an htpasswd file?

You can create and manage an .htpasswd file using Apache's htpasswd utility on the server, or with an online generator like this one — then upload the finished file to your server and reference it in your configuration.

What is htpasswd used for?

htpasswd is used to create and manage username and password credentials for Apache Basic Authentication — for example, protecting staging websites, admin areas, development directories, or internal web tools.

How does htpasswd work with .htaccess?

An .htaccess configuration can tell Apache to require authentication for a directory, pointing at the password file with AuthUserFile. Apache then checks the submitted credentials against the stored hashes.

Is htpasswd secure?

The security of an htpasswd setup depends on the hashing method, server configuration, and use of HTTPS. Use a modern hash like bcrypt, keep the file outside the web root, restrict file permissions, and always use HTTPS — Basic Authentication only encodes credentials, it does not encrypt them.

Where should I put the .htpasswd file?

It is commonly preferable to store the file outside the public web root when possible, so it can never be fetched through a public URL.

Can an htpasswd file contain multiple users?

Yes. An .htpasswd file can contain multiple username:hash entries, one per line. This tool lets you add several users and download them all as one file.

What does the hash in an htpasswd file mean?

The hash is the stored representation of the password generated using a supported hashing method. Apache hashes the password a visitor submits and compares it against the stored hash.

Which hash format should I choose — bcrypt or SHA-1?

Choose bcrypt for new deployments: it is the recommended, modern option with adjustable cost (8, 10, or 12). Use SHA-1 only for legacy setups that cannot handle bcrypt. Note that Nginx's basic auth supports certain hash formats depending on version and build.

Can I add multiple users before downloading?

Yes. Click "Generate & Add Entry" for each username/password pair — each becomes its own line in the entries list. Then use "Copy All Lines" or "Download .htpasswd" to get the complete file.

Can I use htpasswd with Apache?

Yes. htpasswd is an Apache utility commonly used to manage credentials for Apache Basic Authentication.

Can I use an htpasswd generator for .htaccess?

Yes. A generated htpasswd entry can be used as part of an Apache Basic Authentication setup configured through .htaccess.

Should I put .htpasswd inside public_html?

It is generally preferable to keep authentication files outside the publicly accessible web root.

Is the htpasswd Generator free?

Yes. The htpasswd Generator on Trencada is free for creating supported htpasswd-formatted authentication entries — no signup needed.

Category: Developer & Encoding Tools

Tool Information

Category Developer & Encoding Tools
Updated Jan 15
Status Active
Rating 4.7
Type Free Tool
23,721 people used this tool
Your Ad Here

You May Also Like

View All
Trustpilot