.htaccess Generator

Generate Apache .htaccess configurations instantly. Force HTTPS, set browser caching, block directory listing, add custom redirects — no signup required.

  • Runs in your browser
  • Your data never leaves your browser
  • Free · No Sign-Up
.htaccess
 

Choose an option to preview the configuration.

Read the full guide Htaccess Generator Online: Apache Rules Without the Manual
Examples, details and FAQ Worked examples, how it compares with other tools, and answers to common questions.

What Each Section Does

  • Force HTTPS: Adds a RewriteRule that issues a 301 redirect from any http:// request to https:// on the same host. Requires mod_rewrite.
  • WWW Redirect: Enforces a single canonical form of your domain — either always with www. or always without it — preventing duplicate-content issues. The target is always https://, even when Force HTTPS is off.
  • Directory Index: Sets the files Apache will serve when a directory URL is requested. Listing multiple files defines a fallback order. An empty field, or one with spaces only, writes index.php index.html. A full-width space between names counts as a space, because Apache splits names only at ASCII white space.
  • Browser Caching: Uses mod_expires to send Expires and Cache-Control: max-age for images, CSS/JS, and fonts. Each MIME type gets its own ExpiresByType line, so a file only gets the header if Apache serves it with one of the listed types.
  • Security: Disables directory listing (Options -Indexes), blocks direct access to .htaccess and .env with Require all denied (Apache 2.4), and optionally adds security headers: X-Content-Type-Options: nosniff, X-Frame-Options: SAMEORIGIN, Referrer-Policy, and X-XSS-Protection: 0, which turns off the old browser XSS filter as the OWASP HTTP Headers Cheat Sheet advises.
  • Custom Redirect: Creates a single-path redirect using the Apache Redirect directive. Choose 301 (permanent) or 302 (temporary).

Example: the Default Output

With the default options (Force HTTPS, Directory Index, Browser Caching, and the first three Security boxes), the tool writes the file below. We loaded it into Apache 2.4.67 with AllowOverride All and requested a few paths: /a.ttf came back with Cache-Control: max-age=31536000, while /.env, /.htaccess and a directory without an index file returned 403.

# Force HTTPS
<IfModule mod_rewrite.c>
  RewriteEngine On
  RewriteCond %{HTTPS} off
  RewriteRule ^(.*)$ https://%{HTTP_HOST}%{REQUEST_URI} [L,R=301]
</IfModule>

# Directory Index
DirectoryIndex index.php index.html index.htm

# Browser Caching
<IfModule mod_expires.c>
  ExpiresActive On
  ExpiresByType image/jpeg "access plus 1 year"
  ExpiresByType image/png "access plus 1 year"
  ExpiresByType image/gif "access plus 1 year"
  ExpiresByType image/svg+xml "access plus 1 year"
  ExpiresByType image/webp "access plus 1 year"
  ExpiresByType text/css "access plus 1 month"
  ExpiresByType application/javascript "access plus 1 month"
  ExpiresByType text/javascript "access plus 1 month"
  ExpiresByType font/woff "access plus 1 year"
  ExpiresByType font/woff2 "access plus 1 year"
  ExpiresByType font/ttf "access plus 1 year"
  ExpiresByType application/x-font-ttf "access plus 1 year"
  ExpiresByType application/vnd.ms-fontobject "access plus 1 year"
</IfModule>

# Security
Options -Indexes
<Files ".htaccess">
  Require all denied
</Files>
<Files ".env">
  Require all denied
</Files>

Both font/ttf and application/x-font-ttf are listed because the mime.types file shipped with Apache 2.4 maps .ttf to font/ttf, while older configurations use the x- name. With only the old name, TTF files get no caching header.

Example: Remove www and Move an Old Section

Turn on WWW Redirect and pick Remove www under Options, then turn on Custom Redirect and enter a redirect from /old-blog to https://example.com/blog/ (301). The www block goes right after Force HTTPS, and the redirect line goes at the end of the file:

# Remove www
<IfModule mod_rewrite.c>
  RewriteEngine On
  RewriteCond %{HTTP_HOST} ^www\.(.+)$ [NC]
  RewriteRule ^(.*)$ https://%1%{REQUEST_URI} [L,R=301]
</IfModule>

# Custom Redirect
Redirect 301 /old-blog https://example.com/blog/

Each rule issues its own redirect, so a visitor who types http://www.example.com/old-blog follows three hops: to https://www.example.com/old-blog, then https://example.com/old-blog, then https://example.com/blog/. That works, but it is three round trips. Redirect also matches everything below the path and appends the rest: in our test, /old-blog/2024/post went to https://example.com/blog//2024/post with a double slash, while /old-blogger was not matched. Keep the trailing slash the same on both sides to avoid that.

Limits and Common Errors

  • 500 Internal Server Error. Every directive in .htaccess must be allowed by the directory’s AllowOverride setting. With AllowOverride FileInfo, the Options -Indexes line alone made Apache return 500 for the whole directory (“Options not allowed here” in the error log).
  • 403 on every page. RewriteRule in .htaccess needs Options FollowSymLinks or SymLinksIfOwnerMatch; with both off, Apache rejects every request that reaches the rule (error AH00670).
  • Redirect loop behind a proxy or CDN. %{HTTPS} describes the connection Apache itself receives. If a load balancer terminates TLS and talks plain HTTP to Apache, the variable is always off and Force HTTPS redirects forever. In that setup, test the header your proxy sets instead, or force HTTPS at the proxy.
  • Force www on subdomains. The rule adds www. to any host without it: blog.example.com becomes www.blog.example.com, and an IP address gets the prefix too. Use it only when the site answers on the bare domain alone.
  • Exact file names only. The .env block protects a file named exactly .env; .env.local or .env.production are still served. Keep such files outside the document root.
  • The From path must start with a slash. The Redirect documentation says the old URL-path begins with a slash and “A relative path is not allowed”. Apache 2.4.67 loaded Redirect 301 old-page https://example.test/new without an error, and a request for /old-page was not redirected. So when the From path does not start with /, the tool leaves the redirect line out and shows an error in the status line under Copy; the other rules can still be copied.
  • No spaces inside the paths. A space in the From path or the To URL gives the Redirect line four arguments, and Apache 2.4.67 answered 500 for the whole directory (“Redirect takes one, two or three arguments”). The tool shows an error and leaves the line out. Write a space in the To URL as %20; for a From path with a space, edit the file by hand and put the path in quotes (Redirect 301 “/old page” … worked in the same test).
  • One custom redirect per output; for several, copy the Redirect line and edit it. There is no Basic Auth, CORS or gzip/Brotli section. Keep a copy of your current .htaccess before you replace it.

Nginx, Caddy and other servers ignore this file. To protect a directory with a password, create the credentials file with the htpasswd generator; for a full set of response headers, the CSP header generator covers Content-Security-Policy.

FAQ

What is a .htaccess file?

.htaccess is a directory-level configuration file used by Apache web servers. It lets you override server settings per directory — including URL redirects, caching rules, access control, and security headers — without editing the main server config. Apache only reads the directives that the AllowOverride setting for that directory permits.

Will this work on Nginx or other servers?

.htaccess is Apache-specific (LiteSpeed also reads it). Nginx uses a different config syntax and does not read .htaccess files. If you are on Nginx, these rules need to be translated into nginx.conf directives.

Why does my site return 500 Internal Server Error after uploading the file?

Apache answers 500 when .htaccess contains a directive that AllowOverride does not allow for that directory, for example Options -Indexes when Options is not in AllowOverride. The error log names the directive ("Options not allowed here"). Remove that line or ask your host to allow it.

Is it safe to block access to .htaccess itself?

Yes, and it does no harm if the server already does it: the httpd.conf shipped with Apache 2.4 has a <Files ".ht*"> block with Require all denied. The generated block uses the same Apache 2.4 Require directive (mod_authz_core). The Apache 2.2 Order / Deny lines work in 2.4 only when mod_access_compat is loaded.

What is the difference between 301 and 302 redirects?

301 is a permanent redirect — browsers and search engines cache it and update links. 302 is a temporary redirect — clients check back each time. Use 301 for domain migrations or canonical URL changes, and 302 for short-term redirects.

Is my configuration sent anywhere or saved?

No. The file is built in your browser tab from the options you set. The options are not sent to a server or written to browser storage, so reloading the page brings back the defaults. When you click Copy, the site's analytics records a usage event with the tool name and the action, not the paths, URLs or file content.