WMW

htpasswd Generator

Free

Generate a real Apache .htpasswd file with bcrypt or SHA, verified byte-for-byte against the official htpasswd command-line tool, with support for multiple users at once.

Runs entirely in your browser. Your usernames and passwords are never uploaded anywhere.

Algorithm

Higher is slower to compute but more resistant to cracking. Apache's own default is 5; most current guidance recommends 10 or higher.

Users

Recent Activity

Visible to everyone. Last 20 uses across all visitors, newest first.

No activity yet. Be the first.

Comments (0)

Found this tool useful? Leave a comment, share a tip, or tell us how we can make it better.

Guest comments are reviewed before publishing. Sign in to post instantly.

No comments yet. Be the first to share your thoughts!

What this tool does

This tool generates a real Apache .htpasswd file for HTTP Basic Authentication. Add one or more username and password pairs, choose bcrypt (recommended, with an adjustable cost factor) or SHA, and get a ready-to-save file, verified to byte-for-byte match the output of Apache's own htpasswd command-line tool.

How It Works

Each line in a .htpasswd file follows the format username:hashedpassword. For bcrypt, a random 16-byte salt is generated for every password and combined with your chosen cost factor to produce a $2y$-style hash; for SHA, the password is run through a single SHA-1 pass and base64-encoded with a {SHA} prefix. Both formats were checked against real output from Apache's htpasswd tool to confirm an exact match before this tool shipped.

Problems it solves

Frequently asked questions

›Why isn't the old Apache MD5 (apr1) format included?

Apache's own documentation has recommended bcrypt over the MD5-based "apr1" format since httpd 2.4.4, calling the older crypt() and MD5 methods legacy. Rather than ship an algorithm we couldn't independently verify byte-for-byte against real Apache output, this tool focuses on bcrypt and SHA, both verified to match the real htpasswd command-line tool exactly.

›What cost factor should I use for bcrypt?

Apache's own htpasswd tool defaults to 5, chosen decades ago for compatibility with slower hardware. For a new deployment today, 10 to 12 is a common recommendation, higher values are slower to compute (which is the point, it makes brute-forcing more expensive) but also slightly slower for real logins to verify.

›What's the difference between bcrypt and SHA here?

Bcrypt is a slow, purpose-built password hashing algorithm with a built-in random salt and adjustable cost, the current Apache-recommended choice. SHA ({SHA}password) is just a single fast SHA-1 pass with no salt, included for compatibility with very old Apache setups or scripts that specifically expect that format, not recommended for new deployments.

›Where does the generated file actually go?

Save the output as a file (commonly named .htpasswd) outside your site's public web root, then point your Apache config's AuthUserFile directive at its path, alongside AuthType Basic and a Require valid-user directive in the relevant <Directory> or .htaccess block.

›Can I add more than one user at a time?

Yes, use "Add User" to add as many username and password rows as you need; the output box combines every row into one file, one user per line, exactly matching the format Apache expects.

Related Tools