Skip to content

Authentication

Authentication directives enable password protection for directories using HTTP Basic authentication. Users are prompted for credentials via the browser’s built-in login dialog.

DirectiveSyntaxDescription
AuthTypeAuthType BasicSet the authentication type (only Basic is supported)
AuthNameAuthName "realm"Set the authentication realm shown in the login prompt
AuthUserFileAuthUserFile /path/to/.htpasswdAbsolute path to the password file created with htpasswd. Must be inside the site’s document root (see security note below).

All three directives must be used together, along with a Require directive to specify who is allowed access.

DirectiveMeaning
Require valid-userAny user with valid credentials in the AuthUserFile
Require user alice bobOnly the listed usernames (with valid credentials)
Require group ...Not supported — group files are not implemented; this fails closed (access denied) rather than being ignored

Any unrecognised Require form also fails closed (denies access) instead of being silently dropped, so a typo can never leave a directory unprotected.

AuthType Basic
AuthName "Restricted Area"
AuthUserFile /home/user/example.com/.htpasswd
Require valid-user
<Files "wp-login.php">
AuthType Basic
AuthName "WordPress Admin"
AuthUserFile /home/user/example.com/.htpasswd
Require valid-user
</Files>
AuthType Basic
AuthName "Staff Only"
AuthUserFile /home/user/example.com/.htpasswd
Require user alice bob

Only alice and bob (with valid passwords) are allowed; any other valid user is denied.

Use the htpasswd utility to create and manage password files:

Terminal window
# Create a new file with a user
htpasswd -c /home/user/example.com/.htpasswd admin
# Add another user to an existing file
htpasswd /home/user/example.com/.htpasswd editor