Flash Sale:75% Off Hosting + Free DomainEnds in13h47m14sView Plans
Hostvento logoHostvento

Turn On or Off Password Protection with HTTP Authentication

This guide shows you how to ask visitors for a user name and password before they can open a folder on your website. It uses Apache and .htaccess files.

VPS and Cloud Servers2 min read11 steps

What is HTTP authentication?

HTTP authentication is a simple lock for a web page or folder. When a visitor opens it, the browser shows a small box that asks for a user name and password. It is like a door with a keypad.

Apache is a very common web server program. An .htaccess file is a small settings file you place in a folder. Apache reads it to learn the rules for that folder.

Turn it on

  1. Log in to your server over SSH, or use your file manager. If you use a control panel, look for a tool called Directory Privacy or Password Protect Directories. It does the same job with buttons.
  2. Create the password file with this command. Replace john with the user name you want:
    htpasswd -c /home/youruser/.htpasswd john
    It asks for a password twice and saves it in scrambled form. Keep this file outside your public website folder.
  3. To add another user later, run the same command without -c. The -c part creates a new file and would erase the old one.
  4. Open or create the .htaccess file in the folder you want to protect.
  5. Add these lines:
    AuthType Basic
    AuthName "Private area"
    AuthUserFile /home/youruser/.htpasswd
    Require valid-user
    AuthName is the text shown in the login box. AuthUserFile is the full path of your password file.
  6. Save the file.
  7. Open the folder in your browser. The login box should appear.

Turn it off

  1. Open the .htaccess file again.
  2. Delete the four lines you added, or put a # in front of each line.
  3. Save the file.
  4. Reload the page. The box should be gone.

Warning: take a copy of your .htaccess file before you edit it. A typing mistake can make the whole site show an error.

If it does not work

  • Check that the path in AuthUserFile is right.
  • Check that the password file can be read by the web server.
  • If you get a 500 error, look at the error log or remove the lines you added.
  • Some servers do not allow .htaccess. Ask Hostvento support.
Tip: Use HTTPS on the site. Basic authentication sends the password in a form that is easy to read on a plain HTTP connection.

Quick recap

  • HTTP authentication asks for a user name and password.
  • Create users with htpasswd.
  • Add four lines to .htaccess to turn it on.
  • Remove the lines to turn it off.
  • Back up the file before editing.