Apache and nginx Basic Auth

.htpasswd Generator

Create a bcrypt username:hash entry locally for HTTP Basic Authentication. Generate a fresh password here or hash a new password you have chosen for this protected area.

Create a bcrypt .htpasswd entry

Do not paste a password used for email, hosting, SSH, or any other account. Basic Authentication must be served over HTTPS.

Printable ASCII only; colons are not allowed.
Higher costs take longer to create and verify.
Bcrypt processes at most 72 password bytes. A 24-character random password is generated when this page loads.

bcrypt ($2y$)Cost 1024 password bytes
Hashed in this tabThe page code does not submit the username, password, or hash to a hashing service. Copy both the generated password and entry before leaving.

What the generator creates

A password file for HTTP Basic Authentication stores one user per line as username:hash. This page creates a bcrypt hash with the Apache-compatible $2y$ prefix, then joins it to the validated username. The plaintext password is not included in the file.

Apache configuration example

Place the password file outside the public document directory, then point Apache at its absolute filesystem path. Apache recommends configuring authentication in the main server configuration when you control it; use .htaccess only where overrides are permitted.

Apache configuration
AuthType Basic
AuthName "Restricted Area"
AuthUserFile "/etc/apache2/.htpasswd"
Require valid-user

nginx configuration example

nginx supports password files created by Apache's htpasswd utility. Add the directives to the exact server or location block that handles the protected requests.

nginx location block
location /protected/ {
    auth_basic "Restricted Area";
    auth_basic_user_file /etc/nginx/.htpasswd;
}

Use HTTPS with Basic Authentication

Basic Authentication does not encrypt credentials by itself. The browser sends the username and password with protected requests, so HTTPS is required to protect them in transit. The bcrypt hash protects the stored password file if it is exposed; it does not replace transport encryption.

Why bcrypt is the only browser option here

Apache documents bcrypt as a secure choice and exposes it through htpasswd -B. Legacy Apache MD5, unsalted SHA-1, traditional crypt, and plaintext modes exist for compatibility, but they are not offered here because they are weaker choices for a new password file.

Choose a cost that your server can verify

Apache accepts bcrypt costs from 4 through 17. This browser tool limits the choices to 8, 10, and 12 so a tab does not become unresponsive. Cost 10 is the balanced default; test authentication latency on the actual server before using a higher value broadly.

File placement and permissions matter

Do not put .htpasswd inside a directory that the web server can serve publicly. Limit filesystem read access to the web-server process and administrators. If the file is ever disclosed, replace the affected passwords even though the values are hashed.

References

See Apache's official htpasswd manual, authentication tutorial, and password-format reference. nginx documents the compatible file format in its Basic Authentication module.

Related tools

Minecraft RCON password generator creates a server-console credential and configuration block. Username and password generator creates plaintext fictional pairs for QA data rather than bcrypt hashes. Database password generator supplies database-specific credential formats. Random key generator creates raw random bytes for applications that require keys rather than password hashes.