go-supertools
SEO & Web Tools

HTTP-auth Generator

Generate a .htpasswd line (user and SHA-1 password hash) for HTTP Basic Authentication.

Runs in your browser Your input never leaves your device.

About this tool

Enter a username and password and the tool outputs one .htpasswd line in the form user:{SHA}hash, where the hash is the base64-encoded SHA-1 of the password. Apache accepts this format, and so does Nginx's auth_basic_user_file. The hashing runs in your browser and the password is not sent anywhere. Be aware that unsalted SHA-1 is a weak storage format: it is better than plain text but easy to attack, so use a long password, or generate a bcrypt entry with the htpasswd command on your server if you can. The tool does not create the Apache or Nginx configuration.

How to use it

  1. Enter a username and a password.
  2. Copy the generated line.
  3. Save it in a .htpasswd file outside your web root.
  4. Point AuthUserFile (Apache) or auth_basic_user_file (Nginx) at that file.

Example

Input
Username: admin, Password: secret
Result
admin:{SHA}5en6G6MezRroT3XKqkdPOmY/BfQ=

Common problems

Nothing is shown
Both fields are required; the output stays empty until you enter a username and a password.
Login is rejected by the server
Make sure the line is on its own row with no extra spaces and that the server supports the {SHA} scheme.
Security concerns about the hash
The hash is unsalted SHA-1. Prefer bcrypt from the htpasswd tool for anything sensitive.