.htaccess Generator

Switch on what you need — redirects, HTTPS, security headers, compression, caching — and get a commented .htaccess file for Apache 2.4, with warnings about settings that could lock you out.

  • Apache 2.4
  • Redirects + HTTPS
  • Security headers
  • Runs in your browser

Presets

A preset sets all switches at once and keeps your custom redirects. Written for Apache 2.4; parts that need an optional module are wrapped in <IfModule> so a missing module cannot break the site.

.htaccess

Back up the existing .htaccess first. A single syntax error or a missing module makes every page answer “500 Internal Server Error” — if that happens, put the old file back. After uploading, test the home page, an inner page and one redirect.

The file name must be exactly .htaccess. Some browsers and phones drop the leading dot or cannot save such a name — then download htaccess.txt and rename it on the server.

Checks

    How it works

    How to generate an .htaccess file

    Every switch adds one block to the file.

    1. 1

      Pick a preset or start empty

      WordPress recommended, Static site, Laravel, Single-page app, Security hardening or Speed set all switches at once. Your custom redirects are kept.

    2. 2

      Switch sections on and fill in the details

      Redirects and URLs, security, security headers, performance and other settings. The file and the list of checks update as you go.

    3. 3

      Back up, upload and test

      Copy or download the file, keep a copy of the old one, upload it to the folder it should apply to, then test the home page, an inner page and one redirect.

    Why ToolCMB

    What the generated file can do

    Blocks that need an optional module are wrapped in &lt;IfModule&gt;.

    Redirects and clean URLs

    Force HTTPS, add or remove www, trailing slashes and file extensions, move an old domain, and add your own path or regular-expression redirects with 301, 302, 307, 308 or 410.

    Proxy and CDN aware

    Behind Cloudflare or a load balancer the HTTPS rule reads the <code>X-Forwarded-Proto</code> header, which avoids the usual redirect loop.

    Access control

    Password protection, allow or block lists of IP addresses, blocked user agents, hotlink protection for images, and 404 for dot files, backups and configuration files.

    Security headers

    HSTS, X-Content-Type-Options, frame protection, Referrer-Policy, Permissions-Policy and a starter Content-Security-Policy that can run in report-only mode first.

    Performance

    Gzip and Brotli compression, expiry times per file type with Cache-Control, correct MIME types for modern formats and optional removal of ETags.

    Checks before you upload

    Flags redirect loops, an IP rule or maintenance mode that would lock you out, invalid addresses, HSTS preload risks and PHP lines that fail under PHP-FPM.

    Private by design

    Everything runs in your browser. What you type, paste or open is not sent to a server.

    Free, no sign-up

    No account, no limits, no watermark — on a phone, tablet or computer.

    How .htaccess works and how to avoid a 500 error

    An .htaccess file is a per-folder configuration file for the Apache web server. Apache reads it on every request and applies its directives to that folder and everything below it, so you can change redirects, headers and access rules without touching the main server configuration. It works only when the host permits it through AllowOverride, which shared hosting normally does. LiteSpeed servers understand most of the same directives. Nginx does not read .htaccess files at all.

    Most rules rely on modules: mod_rewrite for redirects and clean URLs, mod_headers for security headers, mod_deflate and mod_expires for compression and caching. This generator writes Apache 2.4 syntax, such as Require all denied instead of the old Deny from all, and lists the modules the file uses. Order matters: redirects come before a front controller such as the WordPress block, otherwise the application answers first and the redirect never runs.

    One syntax error or one directive the host does not allow makes every page answer “500 Internal Server Error”. Keep a copy of the working file and put it back if that happens. The classic traps are redirect loops — forcing HTTPS behind a proxy with the standard rule, or a trailing-slash rule that contradicts the CMS — and a 301 that browsers cache for a long time, so test new redirects as 302 first. Treat HSTS with the same care: start with a short time before you raise it.

    Redirect status codes in .htaccess

    CodeMeaningUse it for
    301Moved permanentlyA page or domain that has moved for good; search engines transfer the old address to the new one
    302Found (temporary)Short-term moves and for testing a rule before making it permanent
    307Temporary, method keptTemporary redirects of forms and API calls, because POST stays POST
    308Permanent, method keptPermanent redirects of forms and API endpoints
    410GoneContent that was removed on purpose and will not come back

    Tips

    • After uploading, follow each redirect hop by hop with the Redirect Checker — a chain of several redirects should be reduced to one.
    • Before you force HTTPS or enable HSTS, confirm that the certificate covers every host name with the SSL Checker.
    • Check that the security and caching headers really arrive with the HTTP Status Checker.
    • If your phone or browser cannot save a file whose name starts with a dot, download htaccess.txt and rename it to .htaccess on the server.
    FAQ

    Frequently asked questions

    Can’t find your answer? Contact us — we reply quickly.

    Where do I put the .htaccess file?

    In the folder it should apply to — usually the document root of the site, often called public_html or www. The rules also apply to all sub-folders. The file name is exactly .htaccess, with the leading dot and no extension.

    How do I redirect HTTP to HTTPS with .htaccess?

    Switch on “Force HTTPS”. The generator writes a mod_rewrite rule that sends every http:// request to https:// with a 301. If the site is behind Cloudflare or another proxy, choose that server setup, otherwise the rule loops.

    Why do I get a 500 Internal Server Error after uploading?

    The file contains a directive the server does not accept: a syntax error, a module that is not loaded or a setting the host has not allowed. Restore the previous file, then add the sections one at a time. The server’s error log names the exact line.

    Does .htaccess work on Nginx?

    No. Nginx has no per-folder configuration files; the same rules must be written in the Nginx server configuration. .htaccess works on Apache and, for most directives, on LiteSpeed.

    Does an .htaccess file slow down my website?

    Slightly. Apache looks for the file in every folder of the path on every request. On normal sites the cost is negligible and far smaller than the gain from compression and caching. If you control the server, the same rules in the main configuration are faster.

    Is my data sent to a server?

    No. The tool runs entirely in your browser. Your input is not uploaded, logged or stored on our servers.

    More free SEO and website tools

    Generate tags and files, check status codes, redirects, DNS and certificates — free, without an account.

    Browse all tools