.htaccess Redirect Generator
Generates .htaccess redirect rules for pages, HTTPS, www, and domain moves.
Create .htpasswd entries for HTTP Basic Authentication on Apache or Nginx. Passwords are hashed with bcrypt, APR1-MD5, or SHA-1 right in your browser.
.htpasswd file and the server snippet.Each line of an .htpasswd file is username:hash. The server hashes the password a visitor types and compares it with the stored hash, so the file never holds the password itself.
$2y$10$...) adds a random 16-byte salt and repeats the work 2^cost times. Cost 10 means 1,024 rounds. Apache 2.4+ and Nginx both support it.$apr1$salt$...) is Apache's MD5-based scheme with an 8-character salt and 1,000 rounds. It is older and much faster to crack, but works everywhere.{SHA}...) is one unsalted SHA-1 hash in Base64. It exists for compatibility only.crypto.getRandomValues, so hashing the same password twice gives different lines. Both are valid.admin, password secret, SHA-1: admin:{SHA}5en6G6MezRroT3XKqkdPOmY/BfQ=. This line is always the same, because SHA-1 has no salt.admin:$2y$10$ followed by 53 more characters: 22 of salt and 31 of hash. The salt changes each time.admin:$apr1$Xc3bQ9mz$ followed by a 22-character hash.crypt() DES hashes are not offered, because they only use the first 8 characters of the password..htpasswd file outside your public web folder if you can.Bcrypt with cost 10 to 12. It is salted and slow to brute-force, and Apache 2.4+ and Nginx support it. Use APR1 only for very old servers.
For Apache, add AuthType Basic, AuthName, AuthUserFile /full/path/.htpasswd, and Require valid-user to the folder's .htaccess. The tool shows the exact snippet, plus the Nginx version.
No. Hashing runs in your browser with JavaScript, and nothing you type is uploaded.
$2y$ is the bcrypt version tag that Apache's htpasswd -B writes. $2a$ and $2b$ hashes are also accepted by most servers.
Often used together with the Htpasswd Generator.
Generates .htaccess redirect rules for pages, HTTPS, www, and domain moves.
Creates strong random passwords with a chosen length and character set.
Computes checksums of text or files and compares them with an expected hash.