htpasswd generator
Generate Apache .htpasswd entries with bcrypt ($2y$), SHA1 ({SHA}), APR1-MD5 or plain text; supports batch user:pass input and output ready to append to a .htpasswd file.
Runs in your browserEvery computation happens in your browser — your data never leaves this device.
.htpasswd content
One user:hash per line — append it straight to your .htpasswd file.
Enter a username and password to generate
Server configuration example
AuthType Basic
AuthName "Restricted"
AuthUserFile /etc/apache2/.htpasswd
Require valid-userWhat this tool does
- Protect a directory in Nginx or Apache with Basic Auth: turn a username and password into the hash line that belongs in .htpasswd.
- Generate a whole password file at once by pasting one user:pass pair per line in batch mode.
- Reproduce an existing hash: fill in the 8-character salt in APR1 mode and you get exactly the entry your server already stores, which makes auth debugging much easier.
- Compare the algorithms: hash the same password with bcrypt, {SHA}, APR1 and plain text to see the length, prefix and compatibility differences.
Example
Input
alice:MyPassword
Output
alice:$apr1$S8xLZ9qP$.SjyY7Gr2zWgduV8K27ZA1
This uses APR1-MD5 with the salt S8xLZ9qP typed in by hand, so the result is reproducible. The default bcrypt mode draws a fresh random salt every time, so the same input yields a different hash on each run — that is correct and necessary behaviour.
Frequently asked questions
Which algorithm should I pick?
Use bcrypt ($2y$) on Apache 2.4: it carries its own salt, has a tunable cost and resists brute force best, which is why it is the default here. APR1 is for legacy Apache servers only; {SHA} is the htpasswd -s format that mod_auth_basic on 2.4 rejects; plain text only works with the Windows build of Apache and still needs HTTPS.
Why do two runs produce different strings for the same password?
Because bcrypt and APR1 draw a new random salt each time and store it inside the hash — the 22 characters after $2y$10$ for bcrypt, the 8 characters between $apr1$ and the next $ for APR1. Both outputs verify correctly. Specify a salt in APR1 mode when you need a fixed result.
What bcrypt cost should I use?
The tool accepts 4–12, Apache htpasswd -B defaults to 5, and this page defaults to 10. Each extra round doubles the work: cost 10 takes tens of milliseconds on a normal machine, which is invisible during login yet raises the cost of brute forcing substantially. Cost 12 is stronger but slows down busy login endpoints.
Why is a password longer than 72 bytes rejected?
bcrypt itself only consumes the first 72 bytes and silently ignores the rest. Rather than let you believe a longer password is safer, the tool refuses it. Since UTF-8 uses 3 bytes per Chinese character, about 24 characters already hit the limit.
Are the passwords uploaded?
No. bcrypt is computed with the locally bundled bcryptjs library and SHA1/APR1 are plain JavaScript digest implementations, so everything happens in your browser, no request is sent, and nothing you type is logged.
How do I use the generated file on my server?
Append the output to a password file outside the web root (for example /etc/apache2/.htpasswd), then reference it from a vhost or .htaccess with AuthType Basic, AuthName, AuthUserFile and Require valid-user. Basic Auth sends credentials as Base64, so it only makes sense over HTTPS.
Keywords:htpasswdapachebasic authbcryptapr1sha1基本认证密码文件$2y$md5crypt