What .htpasswd is for
The .htpasswd file stores usernames and password hashes for HTTP basic authentication. Together with a few lines in .htaccess it password-protects a directory: the browser shows a login prompt before the site opens. It’s a handy way to protect an admin panel, a staging copy of a site or internal files.
Which algorithm to choose
- bcrypt — the most secure, supported by Apache 2.4 and later.
- APR1-MD5 — the default format of the htpasswd utility; works with older Apache versions and with nginx.
- SHA-1 — outdated and unsalted; use it only for compatibility.
Important
- Keep .htpasswd outside the site directory (outside public_html) and specify the full path in AuthUserFile.
- Basic authentication sends the password with every request, so only use it together with HTTPS.
- The password is processed in memory and never stored; the generated line contains only the hash.