What the generator creates
A password file for HTTP Basic Authentication stores one user per line as username:hash. This page creates a bcrypt hash with the Apache-compatible $2y$ prefix, then joins it to the validated username. The plaintext password is not included in the file.
Apache configuration example
Place the password file outside the public document directory, then point Apache at its absolute filesystem path. Apache recommends configuring authentication in the main server configuration when you control it; use .htaccess only where overrides are permitted.
AuthType Basic
AuthName "Restricted Area"
AuthUserFile "/etc/apache2/.htpasswd"
Require valid-usernginx configuration example
nginx supports password files created by Apache's htpasswd utility. Add the directives to the exact server or location block that handles the protected requests.
location /protected/ {
auth_basic "Restricted Area";
auth_basic_user_file /etc/nginx/.htpasswd;
}Use HTTPS with Basic Authentication
Basic Authentication does not encrypt credentials by itself. The browser sends the username and password with protected requests, so HTTPS is required to protect them in transit. The bcrypt hash protects the stored password file if it is exposed; it does not replace transport encryption.
Why bcrypt is the only browser option here
Apache documents bcrypt as a secure choice and exposes it through htpasswd -B. Legacy Apache MD5, unsalted SHA-1, traditional crypt, and plaintext modes exist for compatibility, but they are not offered here because they are weaker choices for a new password file.
Choose a cost that your server can verify
Apache accepts bcrypt costs from 4 through 17. This browser tool limits the choices to 8, 10, and 12 so a tab does not become unresponsive. Cost 10 is the balanced default; test authentication latency on the actual server before using a higher value broadly.
File placement and permissions matter
Do not put .htpasswd inside a directory that the web server can serve publicly. Limit filesystem read access to the web-server process and administrators. If the file is ever disclosed, replace the affected passwords even though the values are hashed.
References
See Apache's official htpasswd manual, authentication tutorial, and password-format reference. nginx documents the compatible file format in its Basic Authentication module.
Related tools
Minecraft RCON password generator creates a server-console credential and configuration block. Username and password generator creates plaintext fictional pairs for QA data rather than bcrypt hashes. Database password generator supplies database-specific credential formats. Random key generator creates raw random bytes for applications that require keys rather than password hashes.