Skip to content

htpasswd Generator

Enter a username and password, and get a ready-to-paste .htpasswd line — bcrypt, the format Apache recommends today, or the older {SHA} format still accepted for compatibility. APR1-MD5 is deliberately not offered: its algorithm is a genuine hand-rolled-crypto risk, and bcrypt is the better choice anyway.

  • bcrypt with a configurable cost factor
  • Legacy {SHA} format for older Apache setups
  • A fresh random salt every time for bcrypt
  • Runs fully client-side

Generator

Hashed locally, never sent anywhere

How to generate an htpasswd line

  1. 01

    Enter the username and password

    The username cannot contain a colon — it is the field separator in the file.

  2. 02

    Pick a format

    bcrypt is the current Apache-recommended default; {SHA} exists for compatibility with older setups.

  3. 03

    Copy the line

    Paste it into your .htpasswd file, one line per user.

Why APR1-MD5 is not one of the format options#

APR1-MD5 is Apache's own variant of the MD5-crypt algorithm — a specific, iterative construction that has to be reproduced exactly, byte for byte, to interoperate with real Apache installations. Getting a detail of that iteration wrong produces a hash that looks plausible but silently fails to authenticate anyone, and the failure mode is nearly impossible to debug from the outside. Rather than ship a hand-rolled implementation of an algorithm this easy to get subtly wrong, this tool offers bcrypt — the format Apache's own documentation recommends as the current default — and the much simpler {SHA} format for legacy compatibility.

bcrypt versus {SHA}: pick bcrypt unless you have a specific reason not to#

{SHA} is just a single, unsalted SHA-1 hash of the password — a legacy format kept around for compatibility, not because it's a good choice today. Unsalted means the same password always produces the exact same hash, which is exactly the property a good password hash should not have (it makes precomputed rainbow-table attacks trivial). bcrypt, by contrast, includes a random salt and deliberately expensive repeated hashing (the "cost factor"), specifically designed to resist both of those attacks. Use {SHA} only if the receiving server genuinely does not support anything newer; bcrypt is the right default otherwise.

Why the same input produces a different bcrypt hash every time#

A fresh random salt is generated on every single click, mixed into the hash before the expensive part of the algorithm runs — this is intentional and correct. Two different bcrypt hashes for the identical password are not a bug; they will both verify correctly against that password, and the randomness is exactly what keeps two users who happen to choose the same password from having identical, comparable hashes in the file.

Frequently asked questions

Why is APR1 (Apache MD5) not offered as a format?

It's a specific, iterative algorithm that has to be reproduced exactly to work with real Apache servers, and getting a detail wrong produces a hash that looks fine but silently fails to authenticate. bcrypt — the format Apache's own docs recommend as the current default — is offered instead, along with the simpler legacy {SHA} format.

Should I use bcrypt or {SHA}?

bcrypt, unless the server you're deploying to genuinely only supports the older format. {SHA} is an unsalted single SHA-1 hash — the same password always hashes identically, which makes it far weaker against precomputed attacks than bcrypt's salted, deliberately slow design.

Why do I get a different hash every time I generate the same password?

bcrypt uses a fresh random salt on every hash — this is intentional, not a bug. Every one of those different-looking hashes still verifies correctly against the same original password.

Is my password sent anywhere?

No. Hashing runs entirely in your browser — nothing you type is transmitted or stored.

Developers

UUID Generator

Generate cryptographically random UUID v4 or time-ordered UUID v7, in bulk.

Developers

Base64 Encoder & Decoder

Encode and decode Base64 with correct UTF-8 handling, including the URL-safe alphabet.

Developers

ULID Generator

Generate ULIDs — sortable by creation time like UUID v7, but Crockford Base32 instead of hex.