All Tools View Categories About Contact Privacy

Nginx Basic Authentication Config Generator (.htpasswd)

Password-protect a location with HTTP basic auth.

Runs entirely in your browser - nothing is uploaded and no cloud connection is made.
Your basic auth config will appear here.
-
lines
-
blocks
-
locations

About Nginx Basic Authentication Config Generator (.htpasswd)

HTTP basic authentication is the quickest way to put a simple password in front of a staging site, an admin area or an internal tool, and nginx supports it natively with just two directives. The usual mistakes are referencing an .htpasswd file that does not exist, placing the auth inside the wrong location, or serving it over plain HTTP where credentials travel in the clear. The Nginx Basic Authentication Config Generator builds a correct server and location block, insists on an absolute file path, and checks its own output.

At the heart of the configuration are a handful of directives. auth_basic turns on basic auth for the location and sets the realm name shown in the login prompt. auth_basic_user_file points nginx at the .htpasswd file holding username and hashed password pairs. server the virtual host that serves the protected content. location the path scope where authentication is enforced. listen the port the server binds, typically 80 (pair with TLS in production). server_name the domain this block answers for. Together they shape how the server behaves, and the tool assembles them in the right context so the result is valid on the first try.

Common mistakes are easy to make. A relative .htpasswd path is resolved against the nginx prefix and usually breaks, so the generator requires an absolute path. Basic auth without HTTPS exposes credentials, so the tool is meant to sit behind TLS in production. Protecting the wrong location (or none) defeats the purpose, so the auth directives are scoped to the exact path you enter. The generator anticipates each of these and either sets a safe default or rejects the input with a clear message before anything is written to your clipboard.

Validation is strict because small configuration errors fail in subtle ways. Every input is checked for plausibility, and after the block is assembled it is re-parsed by a built-in tokenizer so unbalanced braces, missing semicolons or stray characters cannot reach your clipboard. Stat cards report line and block counts, and copy, download and print exports are one click away. Everything runs in your browser; nothing you type is transmitted to any server.

In practice this block drops into any standard nginx install. Save the output as a file under /etc/nginx/conf.d/ (or sites-available with a symlink), run nginx -t to confirm the syntax, then reload with nginx -s reload. Because the generator emits a single, self-contained server block with no hidden dependencies, it composes cleanly with your existing caching, logging and security configuration without directive collisions.

Beyond producing correct config, the tool is a reference you can read back and learn from. Each control maps to a real nginx directive, the sample button shows a complete working block in seconds, and clearing the form resets every field to its safe default. Standardising on a generator like this removes per-developer variation, keeps your configuration readable, and gives you a repeatable, auditable setup that passes nginx -t on the first try.

When something looks wrong in production, the first move is always to re-run nginx -t and inspect /var/log/nginx/error.log; most failures surface there with a line number. The access log records every request, so a sudden spike or a wall of 499 responses points straight at backend or timeout problems the generator helps you avoid in the first place.

This server block is designed to sit alongside - not fight - your other configuration. Because it declares its own server_name and a single, self-contained set of directives, you can drop it into conf.d without worrying about collisions with global caching, logging or security snippets that live elsewhere in the nginx tree.

For a production site, pair this block with TLS termination: serve on 80 for the redirect or health checks, and place the encrypted listener (or a front-end load balancer / CDN) in front so clients always speak HTTPS. The generator keeps that boundary clean so the two layers compose instead of overlapping.

If a change ever needs to be undone, the output is plain text you control: delete the file from conf.d, re-run nginx -t, and reload. There is no database and no hidden state, so rolling back is as simple as restoring the previous version from version control or your own backup.

Performance and correctness both benefit from explicit configuration. Defaults baked into the generator reflect current best practice rather than decades-old forum snippets, so the block you ship today will not surprise you with deprecated directives or insecure fallbacks six months from now.

For teams, a generated block is also documentation. New engineers can read the exact directives in place, compare them against the sample, and learn the relevant nginx behaviour without reverse-engineering a hand-maintained file that drifted from its original intent.

Features

  • auth_basic - turns on basic auth for the location and sets the realm name shown in the login prompt.
  • auth_basic_user_file - points nginx at the .htpasswd file holding username and hashed password pairs.
  • server - the virtual host that serves the protected content.
  • location - the path scope where authentication is enforced.
  • listen - the port the server binds, typically 80 (pair with TLS in production).
  • server_name - the domain this block answers for.
  • Self-verifying output re-parsed before display.
  • Copy, Download and Print exports.
  • Load-sample button fills realistic values.
  • Statistics cards for quick checks.
  • Runs entirely in your browser - nothing uploaded.

How to Use

  1. Enter the domain to protect.
  2. Set the location path, usually / for the whole site or /admin for a subsection.
  3. Enter the absolute path to your .htpasswd file.
  4. Name the auth realm shown to users.
  5. Click Generate (or Load sample) and review the block.
  6. Create the .htpasswd file with htpasswd, then reload nginx.

Examples

Example 1 - Whole site auth on / for a staging site with a single realm.

Example 2 - Admin only auth scoped to /admin while the rest stays open.

Example 3 - Custom realm a friendly realm name in the browser prompt.

Example 4 - Relative path rejected an .htpasswd path without a leading slash is reported as an error.

Example 5 - Subdomain auth applied to a specific subdomain server block.

Benefits

  • Correct server and location scoping.
  • Absolute .htpasswd path enforced.
  • Realm name included in the prompt.
  • Self-checked output re-parsed before display.
  • Copy, download and print exports.
  • Private: everything runs in your browser.

Frequently Asked Questions

How do I create the .htpasswd file?
Use htpasswd from apache2-utils: htpasswd -c /etc/nginx/.htpasswd username. The generator only references the file, it does not create users.
Is basic auth secure?
It is encryption-free, so always pair it with HTTPS; the password is then sent over a protected channel.
Where should the file live?
Any absolute path nginx can read; keep it outside the web root and limit file permissions.
Can I protect just one path?
Yes - the auth directives are placed inside the specific location you choose.
What is the realm?
The realm string is shown in the browser login prompt and groups credentials; it is not a secret.
Why must the path be absolute?
Relative paths would be resolved against the nginx prefix and often fail, so the tool requires a leading slash.
Is the output validated?
Yes - the block is re-parsed by a built-in tokenizer before display.
Is anything uploaded?
No. Everything runs in your browser.