Skip to content
empinet.dev
Security & JWT

Htpasswd Generator — Bcrypt Password Entries

Generate a username and bcrypt password hash for an Apache .htpasswd file. Choose the cost, copy the entry, and protect your credentials without sending them to a server.

Generate a bcrypt .htpasswd entry

Credentials

Username

Password

Maximum 72 UTF-8 bytes. Spaces are preserved.

Bcrypt cost (4–14)

Higher values take longer. Default: 10.

.htpasswd output

Enter your credentials and generate an entry.

Credentials stay on this device and are not saved by this tool. The generated entry is a password hash, not an HTTP Authorization header.

How to use a .htpasswd entry

Each line contains a username, a colon, and a password hash. Add the generated line to your password file; replace an existing line for the same username instead of creating duplicates. Configure your web server separately to use that file. Keep the file outside the publicly served directory.

Bcrypt, random salts, and cost

This generator outputs bcrypt with the $2y$ prefix used by Apache htpasswd. A fresh salt means generating the same credentials twice produces different hashes. Cost defaults to 10 and is capped at 14 here to keep browser processing practical. Check that your server supports bcrypt; this tool does not generate legacy MD5, SHA-1, or plaintext entries.

Password length and username rules

Bcrypt processes at most 72 bytes, not 72 characters. Non-ASCII characters may take several UTF-8 bytes. Longer passwords are rejected rather than silently truncated. Usernames cannot contain colons or control characters, start with a comment marker, or exceed 255 UTF-8 bytes. Spaces are preserved, so enter exactly the credentials you intend to use.

A password file is not an Authorization header

The server stores the hash; clients send their credentials using HTTP Basic Authentication. Use the Basic Auth generator for the request header, and HTTPS for transport protection. Generating an entry does not configure authentication or change any server files.

Reference: Apache htpasswd documentation.