HTTP-auth Generator
Generate a .htpasswd line (user and SHA-1 password hash) for HTTP Basic Authentication.
Runs in your browser Your input never leaves your device.
About this tool
Enter a username and password and the tool outputs one .htpasswd line in the form user:{SHA}hash, where the hash is the base64-encoded SHA-1 of the password. Apache accepts this format, and so does Nginx's auth_basic_user_file. The hashing runs in your browser and the password is not sent anywhere. Be aware that unsalted SHA-1 is a weak storage format: it is better than plain text but easy to attack, so use a long password, or generate a bcrypt entry with the htpasswd command on your server if you can. The tool does not create the Apache or Nginx configuration.
How to use it
- Enter a username and a password.
- Copy the generated line.
- Save it in a .htpasswd file outside your web root.
- Point AuthUserFile (Apache) or auth_basic_user_file (Nginx) at that file.
Example
Username: admin, Password: secret
admin:{SHA}5en6G6MezRroT3XKqkdPOmY/BfQ=Common problems
- Nothing is shown
- Both fields are required; the output stays empty until you enter a username and a password.
- Login is rejected by the server
- Make sure the line is on its own row with no extra spaces and that the server supports the {SHA} scheme.
- Security concerns about the hash
- The hash is unsalted SHA-1. Prefer bcrypt from the htpasswd tool for anything sensitive.