Authentication
Authentication directives enable password protection for directories using HTTP Basic authentication. Users are prompted for credentials via the browser’s built-in login dialog.
Directive Reference
Section titled “Directive Reference”| Directive | Syntax | Description |
|---|---|---|
AuthType | AuthType Basic | Set the authentication type (only Basic is supported) |
AuthName | AuthName "realm" | Set the authentication realm shown in the login prompt |
AuthUserFile | AuthUserFile /path/to/.htpasswd | Absolute path to the password file created with htpasswd. Must be inside the site’s document root (see security note below). |
All three directives must be used together, along with a Require directive to specify who is allowed access.
Require directives
Section titled “Require directives”| Directive | Meaning |
|---|---|
Require valid-user | Any user with valid credentials in the AuthUserFile |
Require user alice bob | Only the listed usernames (with valid credentials) |
Require group ... | Not supported — group files are not implemented; this fails closed (access denied) rather than being ignored |
Any unrecognised Require form also fails closed (denies access) instead of being silently dropped, so a typo can never leave a directory unprotected.
Examples
Section titled “Examples”Protect a Directory
Section titled “Protect a Directory”AuthType BasicAuthName "Restricted Area"AuthUserFile /home/user/example.com/.htpasswdRequire valid-userProtect WordPress Admin
Section titled “Protect WordPress Admin”<Files "wp-login.php"> AuthType Basic AuthName "WordPress Admin" AuthUserFile /home/user/example.com/.htpasswd Require valid-user</Files>Restrict to specific users
Section titled “Restrict to specific users”AuthType BasicAuthName "Staff Only"AuthUserFile /home/user/example.com/.htpasswdRequire user alice bobOnly alice and bob (with valid passwords) are allowed; any other valid user is denied.
Creating the Password File
Section titled “Creating the Password File”Use the htpasswd utility to create and manage password files:
# Create a new file with a userhtpasswd -c /home/user/example.com/.htpasswd admin
# Add another user to an existing filehtpasswd /home/user/example.com/.htpasswd editor