Free Server Admin Tool

htpasswd Generator

Generate Apache .htpasswd password entries using bcrypt, MD5-APR, SHA1, or plaintext — single users, bulk lists, and ready-to-paste .htaccess snippets, all computed in your browser.

  • ✔ bcrypt (recommended)
  • ✔ MD5-APR ($apr1$)
  • ✔ SHA1
  • ✔ Bulk user generation
  • ✔ .htaccess snippet
  • ✔ Nothing uploaded
.htpasswd admin:$2y$10$abcdefghijk... user1:$apr1$xyz$hash123... dev:{SHA}W6ph5Mm5Pz8GgiUL... .htaccess AuthType Basic AuthName "Restricted" require valid-user

Generate .htpasswd Entries Without Installing Apache Tools


Apache's htpasswd command-line utility is often unavailable on shared hosting or Windows environments. This tool computes the same entries entirely in your browser — including bcrypt (the only algorithm still recommended for new deployments), MD5-APR (Apache's own $apr1$ format, widely supported), and SHA1 for legacy systems.
Generate single entries, build a complete multi-user .htpasswd file in bulk, or get the exact .htaccess directives needed to password-protect any directory.

How It Works

1. Enter Username & Password

Type the credentials — the password field has a show/hide toggle.

2. Choose an Algorithm

bcrypt for new setups, MD5-APR for maximum compatibility, SHA1 for legacy.

3. Generate

The entry is computed in your browser — for bcrypt this takes a moment by design.

4. Copy & Deploy

Copy the entry directly into your .htpasswd file on the server.

bcrypt
Recommended
MD5-APR
$apr1$ — wide compat
SHA1
Legacy only
Plaintext
Never use
Add multiple username/password pairs below. All entries are generated using the selected algorithm and output as a ready-to-use .htpasswd file.
These directives go in an .htaccess file inside the directory you want to protect, or inside a <Directory> block in your Apache VirtualHost config. The .htpasswd file should live outside your document root for security.
Algorithm Reference

Which Algorithm Should You Use?

AlgorithmFormatSecurityApache SupportRecommendation
bcrypt $2y$10$... Excellent Apache 2.4+ with mod_authn_core Use for all new deployments. Adjustable cost factor makes it future-proof.
MD5-APR $apr1$salt$hash Acceptable All Apache versions Best choice when you need maximum compatibility with older Apache versions.
SHA1 {SHA}base64hash Weak All Apache versions Only for legacy systems that can't use bcrypt or MD5-APR. No salt — vulnerable to rainbow tables.
Plaintext password None All Apache versions Never use on a production server. Visible to anyone who can read the file.

Where should the .htpasswd file live?

The .htpasswd file should be stored outside your web root (outside public_html, www, or htdocs) so it cannot be downloaded by web visitors. A common path on cPanel hosts is /home/username/.htpasswd. On Plesk/Debian: /etc/apache2/.htpasswd.

Does bcrypt work on shared hosting?

Most cPanel and Plesk hosts running Apache 2.4+ support bcrypt via mod_authn_core. If you get a 500 Internal Server Error after switching to bcrypt entries, your host's Apache version may be older — fall back to MD5-APR ($apr1$), which works on all Apache versions.

FAQshtpasswd Generator

Which algorithm should I use?

bcrypt for all new deployments. MD5-APR ($apr1$) for maximum compatibility with older Apache versions. Never use SHA1 or plaintext on a production server.

Where should the .htpasswd file live?

Outside your web root — outside public_html, www, or htdocs. On cPanel: /home/username/.htpasswd. On Debian/Ubuntu: /etc/apache2/.htpasswd.

Is my password sent anywhere?

No. All hashing is computed in your browser using JavaScript and the Web Crypto API. Nothing is transmitted to any server.

24/7 Support Available:

Our support team is here to assist you around the clock. Get Expert Help, Anytime.