Skip to content
UniKit

htpasswd generator

Generate Apache .htpasswd entries with bcrypt ($2y$), SHA1 ({SHA}), APR1-MD5 or plain text; supports batch user:pass input and output ready to append to a .htpasswd file.

Runs in your browserEvery computation happens in your browser — your data never leaves this device.

.htpasswd content

One user:hash per line — append it straight to your .htpasswd file.

Enter a username and password to generate

0 entries
Server configuration example

AuthType Basic
AuthName "Restricted"
AuthUserFile /etc/apache2/.htpasswd
Require valid-user

What this tool does

  • Protect a directory in Nginx or Apache with Basic Auth: turn a username and password into the hash line that belongs in .htpasswd.
  • Generate a whole password file at once by pasting one user:pass pair per line in batch mode.
  • Reproduce an existing hash: fill in the 8-character salt in APR1 mode and you get exactly the entry your server already stores, which makes auth debugging much easier.
  • Compare the algorithms: hash the same password with bcrypt, {SHA}, APR1 and plain text to see the length, prefix and compatibility differences.

Example

Input

alice:MyPassword

Output

alice:$apr1$S8xLZ9qP$.SjyY7Gr2zWgduV8K27ZA1

This uses APR1-MD5 with the salt S8xLZ9qP typed in by hand, so the result is reproducible. The default bcrypt mode draws a fresh random salt every time, so the same input yields a different hash on each run — that is correct and necessary behaviour.

Frequently asked questions

Which algorithm should I pick?

Use bcrypt ($2y$) on Apache 2.4: it carries its own salt, has a tunable cost and resists brute force best, which is why it is the default here. APR1 is for legacy Apache servers only; {SHA} is the htpasswd -s format that mod_auth_basic on 2.4 rejects; plain text only works with the Windows build of Apache and still needs HTTPS.

Why do two runs produce different strings for the same password?

Because bcrypt and APR1 draw a new random salt each time and store it inside the hash — the 22 characters after $2y$10$ for bcrypt, the 8 characters between $apr1$ and the next $ for APR1. Both outputs verify correctly. Specify a salt in APR1 mode when you need a fixed result.

What bcrypt cost should I use?

The tool accepts 4–12, Apache htpasswd -B defaults to 5, and this page defaults to 10. Each extra round doubles the work: cost 10 takes tens of milliseconds on a normal machine, which is invisible during login yet raises the cost of brute forcing substantially. Cost 12 is stronger but slows down busy login endpoints.

Why is a password longer than 72 bytes rejected?

bcrypt itself only consumes the first 72 bytes and silently ignores the rest. Rather than let you believe a longer password is safer, the tool refuses it. Since UTF-8 uses 3 bytes per Chinese character, about 24 characters already hit the limit.

Are the passwords uploaded?

No. bcrypt is computed with the locally bundled bcryptjs library and SHA1/APR1 are plain JavaScript digest implementations, so everything happens in your browser, no request is sent, and nothing you type is logged.

How do I use the generated file on my server?

Append the output to a password file outside the web root (for example /etc/apache2/.htpasswd), then reference it from a vhost or .htaccess with AuthType Basic, AuthName, AuthUserFile and Require valid-user. Basic Auth sends credentials as Base64, so it only makes sense over HTTPS.

Keywords:htpasswdapachebasic authbcryptapr1sha1基本认证密码文件$2y$md5crypt

Related tools