Click to generateCopy result

Online htpasswd generator

What is htpasswd?

htpasswd is a command-line tool of the open-source HTTP server Apache httpd, used to generate password files for HTTP basic authentication.

What is the difference between encryption methods?

MD5:Encrypt passwords with MD5. This is the default encryption on Windows, Netware and TPF.

crypt:Uses crypt() to encrypt passwords. On all platforms except Windows, Netware and TPF this is the default. Although it can be supported by htpasswd on all platforms,\n it cannot be supported by the httpd server on Windows, Netware and TPF.

SHA:Encrypts passwords with SHA. It is designed to make it easier to import or migrate to Netscape, which uses the LDAP Directory Interchange Format (ldif).

plain:No encryption; uses plaintext passwords. Although htpasswd can create such passwords on all platforms, the httpd daemon only supports plaintext passwords on Windows, Netware and TPF.

Why make it online?

If we do not use an apache server, for example when using nginx or similar, we may not have this command line tool at hand and cannot generate a password file; the online version makes it convenient for server administrators.

Recently used:

How to use

This tool belongs to the “Encryption & encoding” category.

  1. 1Pick an algorithm: reversible ones are AES, DES and RC4; one-way digests are MD5 and the SHA family.
  2. 2Enter the text plus your key or salt. Encrypting twice with the same key must give the same result.
  3. 3Copy the output into your code. When comparing digests, match case and the 16/32-bit variant first.

Your input is processed locally in the browser whenever possible. We do not store it.

Frequently asked questions

Can MD5 be decrypted?

No. MD5 is a one-way digest — you can compare it, never reverse it. So-called "decryption" is a rainbow-table hit.

Why do two runs give different results?

Salts, random IVs, or a different case or source encoding all change the output. Normalise to UTF-8 before comparing.

Is it safe to paste a real key here?

Use it for learning and format checks. Generate and store production keys server-side; never paste a live secret into a web page.