.htaccess Generator
Generate Apache .htaccess configurations instantly. Force HTTPS, set browser caching, block directory listing, add custom redirects — no signup required.
- Runs in your browser
- Your data never leaves your browser
- Free · No Sign-Up
Scan with WeChat to share this tool
Examples, details and FAQ Worked examples, how it compares with other tools, and answers to common questions.
What Each Section Does
- Force HTTPS: Adds a RewriteRule that issues a 301 redirect from any
http://request tohttps://on the same host. Requiresmod_rewrite. - WWW Redirect: Enforces a single canonical form of your domain — either always with
www.or always without it — preventing duplicate-content issues. The target is alwayshttps://, even when Force HTTPS is off. - Directory Index: Sets the files Apache will serve when a directory URL is requested. Listing multiple files defines a fallback order. An empty field, or one with spaces only, writes
index.php index.html. A full-width space between names counts as a space, because Apache splits names only at ASCII white space. - Browser Caching: Uses
mod_expiresto sendExpiresandCache-Control: max-agefor images, CSS/JS, and fonts. Each MIME type gets its ownExpiresByTypeline, so a file only gets the header if Apache serves it with one of the listed types. - Security: Disables directory listing (
Options -Indexes), blocks direct access to.htaccessand.envwithRequire all denied(Apache 2.4), and optionally adds security headers:X-Content-Type-Options: nosniff,X-Frame-Options: SAMEORIGIN,Referrer-Policy, andX-XSS-Protection: 0, which turns off the old browser XSS filter as the OWASP HTTP Headers Cheat Sheet advises. - Custom Redirect: Creates a single-path redirect using the Apache
Redirectdirective. Choose 301 (permanent) or 302 (temporary).
Example: the Default Output
With the default options (Force HTTPS, Directory Index, Browser Caching, and the first three Security boxes), the tool writes the file below. We loaded it into Apache 2.4.67 with AllowOverride All and requested a few paths: /a.ttf came back with Cache-Control: max-age=31536000, while /.env, /.htaccess and a directory without an index file returned 403.
# Force HTTPS
<IfModule mod_rewrite.c>
RewriteEngine On
RewriteCond %{HTTPS} off
RewriteRule ^(.*)$ https://%{HTTP_HOST}%{REQUEST_URI} [L,R=301]
</IfModule>
# Directory Index
DirectoryIndex index.php index.html index.htm
# Browser Caching
<IfModule mod_expires.c>
ExpiresActive On
ExpiresByType image/jpeg "access plus 1 year"
ExpiresByType image/png "access plus 1 year"
ExpiresByType image/gif "access plus 1 year"
ExpiresByType image/svg+xml "access plus 1 year"
ExpiresByType image/webp "access plus 1 year"
ExpiresByType text/css "access plus 1 month"
ExpiresByType application/javascript "access plus 1 month"
ExpiresByType text/javascript "access plus 1 month"
ExpiresByType font/woff "access plus 1 year"
ExpiresByType font/woff2 "access plus 1 year"
ExpiresByType font/ttf "access plus 1 year"
ExpiresByType application/x-font-ttf "access plus 1 year"
ExpiresByType application/vnd.ms-fontobject "access plus 1 year"
</IfModule>
# Security
Options -Indexes
<Files ".htaccess">
Require all denied
</Files>
<Files ".env">
Require all denied
</Files>
Both font/ttf and application/x-font-ttf are listed because the mime.types file shipped with Apache 2.4 maps .ttf to font/ttf, while older configurations use the x- name. With only the old name, TTF files get no caching header.
Example: Remove www and Move an Old Section
Turn on WWW Redirect and pick Remove www under Options, then turn on Custom Redirect and enter a redirect from /old-blog to https://example.com/blog/ (301). The www block goes right after Force HTTPS, and the redirect line goes at the end of the file:
# Remove www
<IfModule mod_rewrite.c>
RewriteEngine On
RewriteCond %{HTTP_HOST} ^www\.(.+)$ [NC]
RewriteRule ^(.*)$ https://%1%{REQUEST_URI} [L,R=301]
</IfModule>
# Custom Redirect
Redirect 301 /old-blog https://example.com/blog/
Each rule issues its own redirect, so a visitor who types http://www.example.com/old-blog follows three hops: to https://www.example.com/old-blog, then https://example.com/old-blog, then https://example.com/blog/. That works, but it is three round trips. Redirect also matches everything below the path and appends the rest: in our test, /old-blog/2024/post went to https://example.com/blog//2024/post with a double slash, while /old-blogger was not matched. Keep the trailing slash the same on both sides to avoid that.
Limits and Common Errors
- 500 Internal Server Error. Every directive in
.htaccessmust be allowed by the directory’s AllowOverride setting. WithAllowOverride FileInfo, theOptions -Indexesline alone made Apache return 500 for the whole directory (“Options not allowed here” in the error log). - 403 on every page.
RewriteRulein.htaccessneedsOptions FollowSymLinksorSymLinksIfOwnerMatch; with both off, Apache rejects every request that reaches the rule (error AH00670). - Redirect loop behind a proxy or CDN.
%{HTTPS}describes the connection Apache itself receives. If a load balancer terminates TLS and talks plain HTTP to Apache, the variable is alwaysoffand Force HTTPS redirects forever. In that setup, test the header your proxy sets instead, or force HTTPS at the proxy. - Force www on subdomains. The rule adds
www.to any host without it:blog.example.combecomeswww.blog.example.com, and an IP address gets the prefix too. Use it only when the site answers on the bare domain alone. - Exact file names only. The
.envblock protects a file named exactly.env;.env.localor.env.productionare still served. Keep such files outside the document root. - The From path must start with a slash. The Redirect documentation says the old URL-path begins with a slash and “A relative path is not allowed”. Apache 2.4.67 loaded
Redirect 301 old-page https://example.test/newwithout an error, and a request for/old-pagewas not redirected. So when the From path does not start with/, the tool leaves the redirect line out and shows an error in the status line under Copy; the other rules can still be copied. - No spaces inside the paths. A space in the From path or the To URL gives the
Redirectline four arguments, and Apache 2.4.67 answered 500 for the whole directory (“Redirect takes one, two or three arguments”). The tool shows an error and leaves the line out. Write a space in the To URL as%20; for a From path with a space, edit the file by hand and put the path in quotes (Redirect 301 “/old page” …worked in the same test). - One custom redirect per output; for several, copy the
Redirectline and edit it. There is no Basic Auth, CORS or gzip/Brotli section. Keep a copy of your current.htaccessbefore you replace it.
Nginx, Caddy and other servers ignore this file. To protect a directory with a password, create the credentials file with the htpasswd generator; for a full set of response headers, the CSP header generator covers Content-Security-Policy.
FAQ
What is a .htaccess file?
.htaccess is a directory-level configuration file used by Apache web servers. It lets you override server settings per directory — including URL redirects, caching rules, access control, and security headers — without editing the main server config. Apache only reads the directives that the AllowOverride setting for that directory permits.
Will this work on Nginx or other servers?
.htaccess is Apache-specific (LiteSpeed also reads it). Nginx uses a different config syntax and does not read .htaccess files. If you are on Nginx, these rules need to be translated into nginx.conf directives.
Why does my site return 500 Internal Server Error after uploading the file?
Apache answers 500 when .htaccess contains a directive that AllowOverride does not allow for that directory, for example Options -Indexes when Options is not in AllowOverride. The error log names the directive ("Options not allowed here"). Remove that line or ask your host to allow it.
Is it safe to block access to .htaccess itself?
Yes, and it does no harm if the server already does it: the httpd.conf shipped with Apache 2.4 has a <Files ".ht*"> block with Require all denied. The generated block uses the same Apache 2.4 Require directive (mod_authz_core). The Apache 2.2 Order / Deny lines work in 2.4 only when mod_access_compat is loaded.
What is the difference between 301 and 302 redirects?
301 is a permanent redirect — browsers and search engines cache it and update links. 302 is a temporary redirect — clients check back each time. Use 301 for domain migrations or canonical URL changes, and 302 for short-term redirects.
Is my configuration sent anywhere or saved?
No. The file is built in your browser tab from the options you set. The options are not sent to a server or written to browser storage, so reloading the page brings back the defaults. When you click Copy, the site's analytics records a usage event with the tool name and the action, not the paths, URLs or file content.