{"id":7461,"date":"2026-04-03T10:01:12","date_gmt":"2026-04-03T08:01:12","guid":{"rendered":"https:\/\/mybox.com\/help\/?post_type=manual_kb&#038;p=7461"},"modified":"2026-04-03T10:01:14","modified_gmt":"2026-04-03T08:01:14","slug":"how-to-password-protect-a-directory-htpasswd","status":"publish","type":"manual_kb","link":"https:\/\/mybox.com\/help\/en\/knowledgebase\/how-to-password-protect-a-directory-htpasswd\/","title":{"rendered":"How to password protect a directory (.htpasswd)"},"content":{"rendered":"\n<div class=\"translation-block translation-block-merged\">\n<p class=\"wp-block-paragraph\">You can restrict access to specific folders on your <strong>mybox<\/strong> hosting by using <code>.htaccess<\/code> and <code>.htpasswd<\/code> files. When a user tries to access a protected directory, their browser will prompt them for a username and password before any content is loaded.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">This is a reliable way to secure administrative areas, staging sites, or private files without modifying your website\u2019s code.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><\/p>\n\n\n\n<div id=\"ez-toc-container\" class=\"ez-toc-v2_0_86 ez-toc-wrap-left counter-hierarchy ez-toc-counter ez-toc-custom ez-toc-container-direction\">\n<div class=\"ez-toc-title-container\">\n<p class=\"ez-toc-title\" style=\"cursor:inherit\">Table of Contents<\/p>\n<span class=\"ez-toc-title-toggle\"><\/span><\/div>\n<nav><ul class='ez-toc-list ez-toc-list-level-1 ' ><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-1\" href=\"https:\/\/mybox.com\/help\/en\/knowledgebase\/how-to-password-protect-a-directory-htpasswd\/#How_it_works\" >How it works<\/a><ul class='ez-toc-list-level-3' ><li class='ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-2\" href=\"https:\/\/mybox.com\/help\/en\/knowledgebase\/how-to-password-protect-a-directory-htpasswd\/#1_Create_the_htaccess_file\" >1. Create the .htaccess file<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-3\" href=\"https:\/\/mybox.com\/help\/en\/knowledgebase\/how-to-password-protect-a-directory-htpasswd\/#2_Create_the_htpasswd_file\" >2. Create the .htpasswd file<\/a><\/li><\/ul><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-4\" href=\"https:\/\/mybox.com\/help\/en\/knowledgebase\/how-to-password-protect-a-directory-htpasswd\/#Protecting_a_Specific_File\" >Protecting a Specific File<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-5\" href=\"https:\/\/mybox.com\/help\/en\/knowledgebase\/how-to-password-protect-a-directory-htpasswd\/#Practical_Implications\" >Practical Implications<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-6\" href=\"https:\/\/mybox.com\/help\/en\/knowledgebase\/how-to-password-protect-a-directory-htpasswd\/#Summary\" >Summary<\/a><\/li><\/ul><\/nav><\/div>\n<h2 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"How_it_works\"><\/span>How it works<span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n\n<\/div>\n\n<div id=\"mybox-2236916121\" class=\"mybox-content mybox-entity-placement\"><div class=\"early-access-banner-inpost\">\r\n  <div class=\"banner-left-inpost\">\r\n    <div class=\"icon-box-inpost\">\r\n      <img decoding=\"async\" src=\"https:\/\/mybox.com\/help\/wp-content\/uploads\/2026\/02\/square-info-icon.svg\" alt=\"Info\">\r\n    <\/div>\r\n    <div class=\"text-box-inpost\">\r\n      <span class=\"label-inpost\"><span class=\"translation-block translation-block-banner-text\">Early access<\/span><\/span>\r\n      <h4><span class=\"translation-block translation-block-banner-text\">Still need help?<\/span><\/h4>\r\n      <p><span class=\"translation-block translation-block-banner-text\">Contact our customer service team.<\/span><\/p>\r\n    <\/div>\r\n  <\/div>\r\n\r\n  <div class=\"banner-right-inpost\">\r\n    <a href=\"https:\/\/panel.mybox.com\/helpdesk2\/v\/list\/\" class=\"banner-button-inpost\"><span class=\"translation-block translation-block-banner-text\">Message us<\/span><\/a>\r\n  <\/div>\r\n<\/div><\/div>\n\n<div class=\"translation-block translation-block-merged\"><p class=\"wp-block-paragraph\">To set up protection, you must create two hidden files inside the folder you want to secure (e.g., a folder named <code>\/secret\/<\/code>):<\/p>\n\n\n\n<ol start=\"1\" class=\"wp-block-list\">\n<li><strong>.htaccess:<\/strong> Contains the instructions telling the server to require a password.<\/li>\n\n\n\n<li><strong>.htpasswd:<\/strong> Contains the encrypted usernames and passwords.<\/li>\n<\/ol>\n\n\n\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\">\n<p class=\"wp-block-paragraph\"><strong>Note:<\/strong> These filenames must start with a dot (<code>.<\/code>). In many FTP clients, files starting with a dot are hidden by default; ensure your client is set to &#8220;Show hidden files&#8221; to manage them.<\/p>\n<\/blockquote>\n\n\n\n<p class=\"wp-block-paragraph\"><\/p>\n\n\n\n<h3 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"1_Create_the_htaccess_file\"><\/span>1. Create the .htaccess file<span class=\"ez-toc-section-end\"><\/span><\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Use a plain text editor (like Notepad or TextEdit) to create a file named <code>.htaccess<\/code>. Paste the following configuration:<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Apache<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>AuthType Basic\nAuthName \"Restricted Area\"\nAuthUserFile \/home\/mybox-login\/public_html\/secret\/.htpasswd\nRequire valid-user\n<\/code><\/pre>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>AuthName:<\/strong> The message displayed in the login prompt.<\/li>\n\n\n\n<li><strong>AuthUserFile:<\/strong> The full system path to your password file.<\/li>\n<\/ul>\n\n\n\n<h3 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"2_Create_the_htpasswd_file\"><\/span>2. Create the .htpasswd file<span class=\"ez-toc-section-end\"><\/span><\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">The <code>.htpasswd<\/code> file stores credentials in an encrypted format. You can generate these strings using several methods:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>Online Generators:<\/strong> Use a tool like <a href=\"https:\/\/www.web2generators.com\/apache\/htpasswd_generator\" target=\"_blank\" rel=\"noreferrer noopener\">htpasswd generator<\/a> to create the encrypted line (e.g., <code>user:y9L.kR5v2<\/code>).<\/li>\n\n\n\n<li><strong>Windows:<\/strong> Use a utility like <code>passwd.exe<\/code>.<\/li>\n\n\n\n<li><strong>Linux\/Terminal:<\/strong> Run the command <code>htpasswd -c .htpasswd username<\/code>.<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">An example <code>.htpasswd<\/code> file looks like this:<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Plaintext<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>admin:usAyCVmx1ycqI\nmanager:beae.2fYYfCwM\n<\/code><\/pre>\n\n\n\n<h2 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"Protecting_a_Specific_File\"><\/span>Protecting a Specific File<span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">If you want to protect only one specific file (e.g., <code>config.php<\/code>) instead of the whole folder, wrap the requirement in a <code>&lt;Files&gt;<\/code> block within your <code>.htaccess<\/code>:<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Apache<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>AuthType Basic\nAuthName \"File Access Restricted\"\nAuthUserFile \/home\/mybox-login\/public_html\/secret\/.htpasswd\n&lt;Files \"config.php\"&gt;\n  Require valid-user\n&lt;\/Files&gt;\n<\/code><\/pre>\n\n\n\n<h2 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"Practical_Implications\"><\/span>Practical Implications<span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>Path Accuracy:<\/strong> The <code>AuthUserFile<\/code> path must be absolute. If your <code>.htpasswd<\/code> is in the same folder as the <code>.htaccess<\/code>, you can often simply use <code>AuthUserFile .htpasswd<\/code>, but using the full path is more reliable.<\/li>\n\n\n\n<li><strong>Security:<\/strong> Never store sensitive passwords in plain text. Always use the encrypted strings generated by the tools mentioned above.<\/li>\n\n\n\n<li><strong>Website Functionality:<\/strong> Avoid protecting folders required for the public-facing side of your site (like <code>\/css\/<\/code> or <code>\/images\/<\/code>), as this may prevent your website from loading correctly for visitors.<\/li>\n\n\n\n<li><strong>Removal:<\/strong> To stop password protection, simply delete the <code>.htaccess<\/code> file or remove the <code>Auth<\/code> lines from it via FTP.<\/li>\n<\/ul>\n\n\n\n<h2 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"Summary\"><\/span>Summary<span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Using <code>.htpasswd<\/code> provides a straightforward infrastructure-level security layer for your <strong>mybox<\/strong> hosting. It is an effective &#8220;lock&#8221; for directories that should not be indexed by search engines or accessed by the general public.<\/p>\n<\/div>\n","protected":false},"author":1,"featured_media":0,"parent":0,"menu_order":0,"template":"","format":"standard","manualknowledgebasecat":[10,25],"manual_kb_tag":[],"class_list":["post-7461","manual_kb","type-manual_kb","status-publish","format-standard","hentry","manualknowledgebasecat-safety","manualknowledgebasecat-hosting"],"_links":{"self":[{"href":"https:\/\/mybox.com\/help\/en\/wp-json\/wp\/v2\/manual_kb\/7461","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/mybox.com\/help\/en\/wp-json\/wp\/v2\/manual_kb"}],"about":[{"href":"https:\/\/mybox.com\/help\/en\/wp-json\/wp\/v2\/types\/manual_kb"}],"author":[{"embeddable":true,"href":"https:\/\/mybox.com\/help\/en\/wp-json\/wp\/v2\/users\/1"}],"version-history":[{"count":1,"href":"https:\/\/mybox.com\/help\/en\/wp-json\/wp\/v2\/manual_kb\/7461\/revisions"}],"predecessor-version":[{"id":7462,"href":"https:\/\/mybox.com\/help\/en\/wp-json\/wp\/v2\/manual_kb\/7461\/revisions\/7462"}],"wp:attachment":[{"href":"https:\/\/mybox.com\/help\/en\/wp-json\/wp\/v2\/media?parent=7461"}],"wp:term":[{"taxonomy":"manualknowledgebasecat","embeddable":true,"href":"https:\/\/mybox.com\/help\/en\/wp-json\/wp\/v2\/manualknowledgebasecat?post=7461"},{"taxonomy":"manual_kb_tag","embeddable":true,"href":"https:\/\/mybox.com\/help\/en\/wp-json\/wp\/v2\/manual_kb_tag?post=7461"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}