Code tool

.htaccess Snippet Generator

Combine Apache 2.4 .htaccess drafts for HTTPS redirects, gzip, static-asset caching and Basic authentication, then copy or download the text.

In-browser processingNo account requiredPrivacy details ↗

Apache HTTP Server 2.4 drafts only. This page does not deploy configuration, create password files, inspect a server or conduct a security audit.

All input and output stay in current page memory, without upload or saved settings. Do not enter usernames, passwords or keys.

Enable the modules for your selections: HTTPS: mod_rewrite; gzip: mod_deflate and mod_filter; cache: mod_expires and mod_headers; Basic authentication: mod_auth_basic, mod_authn_file, mod_authz_user, mod_authn_core and mod_authz_core. AllowOverride must permit FileInfo / Indexes / AuthConfig as needed. Missing modules or overrides can prevent operation.

A QUICK WALKTHROUGH

How to use this tool

  1. Choose any combination of the four features.
  2. Enter the fixed HTTPS origin, cache seconds or authentication realm and absolute path required by your selections.
  3. Generate, review the draft and its server requirements, then copy or download it.

Configuration draft

Apache HTTP Server 2.4 drafts only. This page does not deploy configuration, create password files, inspect a server or conduct a security audit. All input and output stay in current page memory, without upload or saved settings. Do not enter usernames, passwords or keys.

HTTPS redirect (301)

HTTPS assumes Apache directly receives TLS and has a working HTTPS listener and certificate. TLS termination at a reverse proxy needs an administrator-specific configuration; X-Forwarded-Proto is not assumed. Origin hosts are ASCII DNS names or IPv4 values; IPv6 literals are not accepted.

Gzip text responses / Static-asset caching

Cache rules cover listed CSS/JavaScript, common images and WOFF fonts; HTML is excluded. Lifetime is 0–31,536,000 seconds. Review application caching and compression behavior before use. Enable the modules for your selections: HTTPS: mod_rewrite; gzip: mod_deflate and mod_filter; cache: mod_expires and mod_headers; Basic authentication: mod_auth_basic, mod_authn_file, mod_authz_user, mod_authn_core and mod_authz_core. AllowOverride must permit FileInfo / Indexes / AuthConfig as needed. Missing modules or overrides can prevent operation. Cache-Control is private, allowing browser caching without marking assets public.

Basic authentication

Basic authentication applies to this directory and descendants. Create the password file separately, keep it outside the web document tree, and serve authentication over HTTPS. The tool cannot verify the file, credentials or permissions. Example: /srv/private/.htpasswd or C:/Apache/private/.htpasswd. No spaces or traversal segments. 1–120 characters; quotes are escaped. Controls, backslashes and dollar signs are rejected. The realm must not begin with expr=.

GOOD TO KNOW

Common questions

Does it work with Nginx or a TLS proxy?

Nginx does not use .htaccess. HTTPS output assumes direct Apache TLS; proxy deployments need their own reviewed rules.

Does it create a password file?

No. It only emits AuthUserFile pointing to your separately prepared absolute server path. Do not enter credentials here.

Will it work if a module is missing?

The tool cannot confirm this. Required modules and AllowOverride permissions must be configured on the server; the output is a draft.