.htaccess Generator
Switch on what you need — redirects, HTTPS, security headers, compression, caching — and get a commented .htaccess file for Apache 2.4, with warnings about settings that could lock you out.
- Apache 2.4
- Redirects + HTTPS
- Security headers
- Runs in your browser
Presets
A preset sets all switches at once and keeps your custom redirects. Written for Apache 2.4; parts that need an optional module are wrapped in <IfModule> so a missing module cannot break the site.
This section is switched off, so nothing from it is written to the file.
Behind a proxy the server sees plain HTTP, so the rule reads the X-Forwarded-Proto header instead. Choosing the wrong setup causes a redirect loop.
Old addresses with the extension redirect to the clean ones; the files stay where they are.
Sends every address that is not a real file or folder to one entry file.
Use / for the site root or, for example, /blog/. For Laravel and Symfony the file belongs in the public folder.
Custom redirects
No custom redirects yet.
Path redirects the path and everything below it. Regular expression matches the full path starting with /; use $1, $2 in the target for the captured groups. 301 and 308 are permanent, 302 and 307 temporary, 410 tells search engines the page is gone for good.
One per line or separated by commas. IPv4, IPv6 and ranges such as 198.51.100.0/24.
This section is switched off, so nothing from it is written to the file.
Save this snippet as its own .htaccess file inside each upload folder, for example /wp-content/uploads/ or /uploads/. Uploaded scripts can then no longer be executed.
One per line or separated by commas. IPv4, IPv6 and ranges such as 198.51.100.0/24.
One per line. A part of the name is enough; upper and lower case do not matter.
Optional, including their subdomains.
Optional path of an image shown instead. Leave empty to answer 403.
The password file is created separately — with the htpasswd command or the password tool of your hosting panel — and should be stored outside the public web folder. This generator never asks for or creates passwords.
This section is switched off, so nothing from it is written to the file.
HSTS cannot be undone quickly: until the time runs out, visitors cannot reach the site over HTTP at all. Start with 5 minutes. Preload asks browsers to hard-code your domain — removal takes months, and every subdomain must work over HTTPS.
frame-ancestors is the modern form; X-Frame-Options also works in very old browsers.
How much of the address is passed on when a visitor follows a link.
Advanced. Leave both unset unless you know your site needs them.
This section is switched off, so nothing from it is written to the file.
Fonts are always cached for one year. Use one year and “immutable” only when file names change with every update, for example app.3f9a1c.js.
This section is switched off, so nothing from it is written to the file.
Custom error pages
Paths start with /. Leave a field empty to keep the standard page of the server.
One per line, with scheme and without a path: https://app.example.com
These lines only work with mod_php. With PHP-FPM or FastCGI — the usual setup on modern hosting — a bare php_value line causes a 500 error, which is why the block is wrapped in <IfModule>. There, change the values in .user.ini or in the hosting panel instead.
One per line. A part of the name is enough; upper and lower case do not matter.
.htaccess
Switch on a section to build the file.
Back up the existing .htaccess first. A single syntax error or a missing module makes every page answer “500 Internal Server Error” — if that happens, put the old file back. After uploading, test the home page, an inner page and one redirect.
The file name must be exactly .htaccess. Some browsers and phones drop the leading dot or cannot save such a name — then download htaccess.txt and rename it on the server.
Checks
How to generate an .htaccess file
Every switch adds one block to the file.
- 1
Pick a preset or start empty
WordPress recommended, Static site, Laravel, Single-page app, Security hardening or Speed set all switches at once. Your custom redirects are kept.
- 2
Switch sections on and fill in the details
Redirects and URLs, security, security headers, performance and other settings. The file and the list of checks update as you go.
- 3
Back up, upload and test
Copy or download the file, keep a copy of the old one, upload it to the folder it should apply to, then test the home page, an inner page and one redirect.
What the generated file can do
Blocks that need an optional module are wrapped in <IfModule>.
Redirects and clean URLs
Force HTTPS, add or remove www, trailing slashes and file extensions, move an old domain, and add your own path or regular-expression redirects with 301, 302, 307, 308 or 410.
Proxy and CDN aware
Behind Cloudflare or a load balancer the HTTPS rule reads the <code>X-Forwarded-Proto</code> header, which avoids the usual redirect loop.
Access control
Password protection, allow or block lists of IP addresses, blocked user agents, hotlink protection for images, and 404 for dot files, backups and configuration files.
Security headers
HSTS, X-Content-Type-Options, frame protection, Referrer-Policy, Permissions-Policy and a starter Content-Security-Policy that can run in report-only mode first.
Performance
Gzip and Brotli compression, expiry times per file type with Cache-Control, correct MIME types for modern formats and optional removal of ETags.
Checks before you upload
Flags redirect loops, an IP rule or maintenance mode that would lock you out, invalid addresses, HSTS preload risks and PHP lines that fail under PHP-FPM.
Private by design
Everything runs in your browser. What you type, paste or open is not sent to a server.
Free, no sign-up
No account, no limits, no watermark — on a phone, tablet or computer.
How .htaccess works and how to avoid a 500 error
An .htaccess file is a per-folder configuration file for the Apache web server. Apache reads it on every request and applies its directives to that folder and everything below it, so you can change redirects, headers and access rules without touching the main server configuration. It works only when the host permits it through AllowOverride, which shared hosting normally does. LiteSpeed servers understand most of the same directives. Nginx does not read .htaccess files at all.
Most rules rely on modules: mod_rewrite for redirects and clean URLs, mod_headers for security headers, mod_deflate and mod_expires for compression and caching. This generator writes Apache 2.4 syntax, such as Require all denied instead of the old Deny from all, and lists the modules the file uses. Order matters: redirects come before a front controller such as the WordPress block, otherwise the application answers first and the redirect never runs.
One syntax error or one directive the host does not allow makes every page answer “500 Internal Server Error”. Keep a copy of the working file and put it back if that happens. The classic traps are redirect loops — forcing HTTPS behind a proxy with the standard rule, or a trailing-slash rule that contradicts the CMS — and a 301 that browsers cache for a long time, so test new redirects as 302 first. Treat HSTS with the same care: start with a short time before you raise it.
Redirect status codes in .htaccess
| Code | Meaning | Use it for |
|---|---|---|
| 301 | Moved permanently | A page or domain that has moved for good; search engines transfer the old address to the new one |
| 302 | Found (temporary) | Short-term moves and for testing a rule before making it permanent |
| 307 | Temporary, method kept | Temporary redirects of forms and API calls, because POST stays POST |
| 308 | Permanent, method kept | Permanent redirects of forms and API endpoints |
| 410 | Gone | Content that was removed on purpose and will not come back |
Tips
- After uploading, follow each redirect hop by hop with the Redirect Checker — a chain of several redirects should be reduced to one.
- Before you force HTTPS or enable HSTS, confirm that the certificate covers every host name with the SSL Checker.
- Check that the security and caching headers really arrive with the HTTP Status Checker.
- If your phone or browser cannot save a file whose name starts with a dot, download
htaccess.txtand rename it to.htaccesson the server.
Frequently asked questions
Can’t find your answer? Contact us — we reply quickly.
Where do I put the .htaccess file?
In the folder it should apply to — usually the document root of the site, often called public_html or www. The rules also apply to all sub-folders. The file name is exactly .htaccess, with the leading dot and no extension.
How do I redirect HTTP to HTTPS with .htaccess?
Switch on “Force HTTPS”. The generator writes a mod_rewrite rule that sends every http:// request to https:// with a 301. If the site is behind Cloudflare or another proxy, choose that server setup, otherwise the rule loops.
Why do I get a 500 Internal Server Error after uploading?
The file contains a directive the server does not accept: a syntax error, a module that is not loaded or a setting the host has not allowed. Restore the previous file, then add the sections one at a time. The server’s error log names the exact line.
Does .htaccess work on Nginx?
No. Nginx has no per-folder configuration files; the same rules must be written in the Nginx server configuration. .htaccess works on Apache and, for most directives, on LiteSpeed.
Does an .htaccess file slow down my website?
Slightly. Apache looks for the file in every folder of the path on every request. On normal sites the cost is negligible and far smaller than the gain from compression and caching. If you control the server, the same rules in the main configuration are faster.
Is my data sent to a server?
No. The tool runs entirely in your browser. Your input is not uploaded, logged or stored on our servers.
More free SEO and website tools
Generate tags and files, check status codes, redirects, DNS and certificates — free, without an account.