Htpasswd Generator — Free Online Apache .htpasswd Hash Generator
Generate .htpasswd entries for Apache and nginx HTTP Basic Authentication.
Jump to tool ↓Frequently Asked Questions
Creating .htpasswd Files for HTTP Basic Authentication
HTTP Basic Authentication protects web resources with a username and password, stored in an .htpasswd file. Apache httpd and nginx both support this file format for simple password protection of directories, admin panels, and staging environments.
The .htpasswd format is simple: one entry per line as username:hash. Multiple hash formats are supported: bcrypt ($2y$...) is the most secure and recommended for new setups. SHA-1 base64 ({SHA}...) is widely supported but cryptographically weak. Plain text is never appropriate. APR MD5 ($apr1$...) is legacy.
For production use, generate bcrypt entries using the Bcrypt Generator tool (which uses the bcryptjs library) and prepend the username manually. For quick SHA-1 entries compatible with legacy nginx and Apache configurations, this tool generates them directly.
Standards & References
Built and maintained by DevDecode. This tool processes your input in your browser; it is not uploaded for processing. Found an issue? Let us know.
Related Tools
Related Guides
What Is Password Hashing (and Why Salting Matters)?
Password hashing stores passwords as irreversible hashes instead of plain text. Learn how salting works, why bcrypt and Argon2 beat SHA-256, and how passwords get cracked.
Securitybcrypt vs Argon2: Which Password Hash Should You Use in 2026?
bcrypt has been the safe default for 25 years. Argon2 won the Password Hashing Competition. Here's how to choose between them — and why both are fine.