# htpasswd generator — basic auth entries, no upload

> Generate htpasswd entries (bcrypt/APR1) for Apache or Nginx basic auth in your browser. Nothing is uploaded — the credentials stay in the tab.

Generate htpasswd entries for Apache or Nginx HTTP basic auth, hashing the password with bcrypt or APR1 in the browser. The password is never uploaded — hashing happens on your device.

HTTP basic auth is a quick way to protect a page or endpoint, and it reads credentials from an htpasswd file of hashed passwords. Generating the entry locally means the password is hashed on your machine, not typed into a remote form.

Use bcrypt unless you must support a legacy setup. For related crypto, the security tools cover hashing and encryption.

## How to

1. **Enter credentials.** Type a username and password.
2. **Pick a hash.** Choose bcrypt or APR1 (MD5).
3. **Copy.** Copy the htpasswd line into your file.

## FAQ

### Which hash should I use?

bcrypt is the stronger, recommended choice; APR1 (MD5) exists for older setups. The generator supports both so you match your server's needs.

### Is the password sent anywhere?

No. The password is hashed locally in the browser, so the plaintext never leaves your device — important since it's a live credential.

### Where does the htpasswd line go?

Into the .htpasswd file your Apache or Nginx basic-auth config points to; each line is one username:hash entry.


## Related tools

- [Password hasher](https://www.safepaper.app/security/password-hash)
- [Password generator](https://www.safepaper.app/dev/password-gen)
- [Security headers](https://www.safepaper.app/dev/security-headers)
- [Hash & checksum](https://www.safepaper.app/security/hash-verify)

---

Canonical HTML: https://www.safepaper.app/dev/htpasswd
Markdown: https://www.safepaper.app/dev/htpasswd.md

There is no upload endpoint — your files are processed in this browser tab. Open your network tab and check.
