DevOps & Config Tools

.htaccess Generator

Tick what your site needs and get a complete, commented .htaccess file for Apache. The rules are written for Apache 2.4, ordered so that they work together, and wrapped so that a missing module does not take the site down.

  • Runs in your browser
  • No sign-up
  • Free to use
Redirects to one address
Application routing
Custom redirects
Security
Speed
Error pages and defaults

    Save the file as .htaccess in the root folder of your site. Keep a copy of the existing file first: a mistake in .htaccess makes every page return a 500 error until it is fixed.

    How to use .htaccess Generator

    1. Choose the redirects you want: HTTPS, www or non-www, trailing slashes.
    2. Select how requests are routed, and add individual redirects if you have moved pages.
    3. Tick the security and speed options.
    4. Download the file, rename it to .htaccess and upload it to the root of your site.

    .htaccess Generator features

    HTTPS and www redirects

    One permanent redirect to the address you prefer, with a variant for sites behind Cloudflare or a load balancer.

    Routing

    Front controller for PHP frameworks, fallback for single-page apps, or extensionless PHP URLs.

    Individual redirects

    301, 302 and 410 for pages that moved or were removed.

    Security

    No directory listings, blocked dotfiles and backup files, security headers, HSTS, IP blocking and hotlink protection.

    Performance

    gzip and Brotli compression and Expires headers for static files.

    Commented and safe

    Every block is labelled, and module-specific directives are inside IfModule so that the file degrades gracefully.

    When to use .htaccess Generator

    • Setting up a new site on shared hosting.
    • Moving a site to HTTPS or to a new URL structure without losing search rankings.
    • Hardening an existing site against exposed .env and .git files.
    • Improving a page speed score with compression and caching.

    .htaccess Generator FAQ

    Where do I put the .htaccess file?

    In the document root of your site, the folder that contains index.php or index.html, often called public_html. The rules apply to that folder and everything below it. The file name starts with a dot and has no extension; the download is named htaccess.txt because some systems hide or refuse dotfiles, so rename it after uploading.

    My site shows a 500 error after uploading. What now?

    Rename or remove the file and the site comes back. A 500 error means Apache could not accept a directive, usually because the host does not allow it in .htaccess. Add the sections back one at a time to find the one responsible, and check the error log in your hosting panel.

    Does it work on Nginx or LiteSpeed?

    Nginx ignores .htaccess files entirely; use the Nginx Config Generator. LiteSpeed and OpenLiteSpeed read .htaccess and support most of these directives, including the rewrite rules.

    Why does “Force HTTPS” cause a redirect loop?

    Because the site is behind a proxy or CDN that speaks HTTPS to visitors and HTTP to your server. Apache then sees every request as HTTP and redirects forever. Tick the proxy option, which checks the X-Forwarded-Proto header instead.

    Is blocking .env in .htaccess enough?

    It is a useful safety net, and you should have it. The better arrangement keeps such files outside the document root altogether, so that no web server rule is needed to protect them.

    Should I use 301 or 302?

    301 for permanent moves: browsers and search engines remember it and transfer ranking to the new URL. 302 for temporary ones, such as a maintenance page. Because 301s are cached by browsers for a long time, test with 302 first and switch when you are sure.

    What .htaccess is and how Apache reads it

    An .htaccess file is a piece of Apache configuration that lives in a folder of your site. Before serving a request, Apache looks for such files in the requested folder and in every folder above it, and applies their directives. This lets site owners on shared hosting change server behaviour without access to the main configuration. The price is a little performance, since the files are read on every request, which is why administrators with full access prefer the virtual host configuration.

    Most of what people do in .htaccess goes through mod_rewrite. A RewriteRule matches the requested path against a pattern and either redirects the visitor or internally serves a different file. RewriteCond lines in front of a rule add conditions: only when HTTPS is off, only when the host starts with www, only when no real file has that name. Order matters. Redirects that change the address belong first, so that a visitor is sent to the final URL in as few steps as possible, and the catch-all rule that hands requests to an application belongs last.

    Security directives close the most common leaks. Without “Options -Indexes”, a folder without an index file shows its contents to anyone. Dotfiles such as .env and .git can expose passwords and source code if they are reachable. Backup copies of configuration files are served as plain text, since they no longer end in .php. Response headers then instruct browsers to refuse content-type guessing, framing by other sites and, with HSTS, plain HTTP connections.

    Compression and caching are the cheapest performance gains available. Text files shrink by two thirds or more when compressed. Expires headers let browsers reuse images, style sheets and scripts on repeat visits without asking the server. HTML is deliberately not cached, so that visitors always get the current page, which in turn refers to the current versions of the static files.

    Other useful tools