bcrypt for all new deployments. MD5-APR ($apr1$) for maximum compatibility with older Apache versions. Never use SHA1 or plaintext on a production server.
Generate Apache .htpasswd password entries using bcrypt,
MD5-APR, SHA1, or plaintext — single users, bulk lists, and ready-to-paste
.htaccess snippets, all computed in your browser.
htpasswd command-line utility is often unavailable on shared hosting
or Windows environments. This tool computes the same entries entirely in your browser —
including bcrypt (the only algorithm still recommended for new deployments), MD5-APR
(Apache's own $apr1$ format, widely supported), and SHA1 for legacy systems.
.htpasswd file in bulk,
or get the exact .htaccess directives needed to password-protect any directory.
Type the credentials — the password field has a show/hide toggle.
bcrypt for new setups, MD5-APR for maximum compatibility, SHA1 for legacy.
The entry is computed in your browser — for bcrypt this takes a moment by design.
Copy the entry directly into your .htpasswd file on the server.
.htpasswd file.
.htaccess file inside the directory you
want to protect, or inside a <Directory> block in your Apache
VirtualHost config. The .htpasswd file should live outside
your document root for security.
| Algorithm | Format | Security | Apache Support | Recommendation |
|---|---|---|---|---|
| bcrypt | $2y$10$... |
Excellent | Apache 2.4+ with mod_authn_core | Use for all new deployments. Adjustable cost factor makes it future-proof. |
| MD5-APR | $apr1$salt$hash |
Acceptable | All Apache versions | Best choice when you need maximum compatibility with older Apache versions. |
| SHA1 | {SHA}base64hash |
Weak | All Apache versions | Only for legacy systems that can't use bcrypt or MD5-APR. No salt — vulnerable to rainbow tables. |
| Plaintext | password |
None | All Apache versions | Never use on a production server. Visible to anyone who can read the file. |
The .htpasswd file should be stored outside your web root (outside public_html, www, or htdocs) so it cannot be downloaded by web visitors. A common path on cPanel hosts is /home/username/.htpasswd. On Plesk/Debian: /etc/apache2/.htpasswd.
Most cPanel and Plesk hosts running Apache 2.4+ support bcrypt via mod_authn_core. If you get a 500 Internal Server Error after switching to bcrypt entries, your host's Apache version may be older — fall back to MD5-APR ($apr1$), which works on all Apache versions.
bcrypt for all new deployments. MD5-APR ($apr1$) for maximum compatibility with older Apache versions. Never use SHA1 or plaintext on a production server.
Outside your web root — outside public_html, www, or htdocs. On cPanel: /home/username/.htpasswd. On Debian/Ubuntu: /etc/apache2/.htpasswd.
No. All hashing is computed in your browser using JavaScript and the Web Crypto API. Nothing is transmitted to any server.