.htaccess Generator

Runs in your browserDeveloper Tools#Apache#DevOps

Generate Apache .htaccess rules for HTTPS and www redirects, IP blocking, compression, caching and 301s.

Redirects

www in the address

Security

Speed and pages

  • Back up your current .htaccess first. One wrong line gives an HTTP 500 error for the whole site.
  • For Apache and LiteSpeed hosting (cPanel, Hostinger and similar). Nginx, IIS, Vercel and Netlify ignore this file.
  • On Cloudflare, set SSL/TLS to Full: Flexible SSL with other HTTPS redirects can loop.

.htaccess

# .htaccess made with ToolKit360 for Apache 2.4 and LiteSpeed.
# Back up your current .htaccess first: one wrong line returns an HTTP 500 error for the whole site.

<IfModule mod_rewrite.c>
RewriteEngine On

# Block hidden files and folders such as .env and .git (but allow .well-known)
RewriteRule (^|/)\.(?!well-known(?:/|$)) - [F]

# Send every visitor to HTTPS in one redirect
# Behind Cloudflare or a load balancer, X-Forwarded-Proto tells whether the visitor used HTTPS.
RewriteCond %{HTTPS} !=on
RewriteCond %{HTTP:X-Forwarded-Proto} !https
RewriteRule ^ https://%{HTTP_HOST}%{REQUEST_URI} [L,R=301,NE]
</IfModule>

# Hide folder listings (remove this line if your host shows an error for it)
Options -Indexes

# Compress text files (gzip)
<IfModule mod_deflate.c>
  <IfModule mod_filter.c>
    AddOutputFilterByType DEFLATE text/html text/plain text/css text/xml
    AddOutputFilterByType DEFLATE text/javascript application/javascript application/json
    AddOutputFilterByType DEFLATE application/xml application/rss+xml application/manifest+json
    AddOutputFilterByType DEFLATE image/svg+xml image/x-icon font/ttf font/otf
  </IfModule>
</IfModule>

# Correct types for modern files
<IfModule mod_mime.c>
  AddType image/avif .avif
  AddType image/webp .webp
  AddType image/svg+xml .svg
  AddType font/woff2 .woff2
  AddType font/woff .woff
  AddType application/manifest+json .webmanifest
</IfModule>

# Browser caching: images, CSS and JavaScript for 1 month; pages are always checked
<IfModule mod_expires.c>
  ExpiresActive On
  ExpiresByType text/html "access plus 0 seconds"
  ExpiresByType application/json "access plus 0 seconds"
  ExpiresByType application/xml "access plus 0 seconds"
  ExpiresByType text/css "access plus 1 month"
  ExpiresByType text/javascript "access plus 1 month"
  ExpiresByType application/javascript "access plus 1 month"
  ExpiresByType image/avif "access plus 1 month"
  ExpiresByType image/webp "access plus 1 month"
  ExpiresByType image/jpeg "access plus 1 month"
  ExpiresByType image/png "access plus 1 month"
  ExpiresByType image/gif "access plus 1 month"
  ExpiresByType image/svg+xml "access plus 1 month"
  ExpiresByType image/x-icon "access plus 1 month"
  ExpiresByType image/vnd.microsoft.icon "access plus 1 month"
  ExpiresByType video/mp4 "access plus 1 month"
  ExpiresByType video/webm "access plus 1 month"
  ExpiresByType font/woff2 "access plus 1 year"
  ExpiresByType font/woff "access plus 1 year"
  ExpiresByType font/ttf "access plus 1 year"
  ExpiresByType font/otf "access plus 1 year"
</IfModule>

If your browser saves the file as htaccess or htaccess.txt, rename it to .htaccess before uploading it to your site's root folder.

How to use, limits & privacy

About .htaccess Generator

Make an .htaccess file for Apache or LiteSpeed hosting, such as cPanel and Hostinger, by switching options on and off. It sends visitors to HTTPS and to one version of your domain (with or without www) in a single redirect, blocks hidden files such as .env and .git, blocks IP addresses with valid Apache 2.4 rules, compresses and caches files, and can add 301 redirects, a 404 page, a single-page app fallback and hotlink protection.

How to Use

1

Back up your current file

Download the existing .htaccess from your site's root folder (often public_html) with your host's file manager or FTP, so you can put it back.

2

Choose the options

Turn on what you need. Add your domain if you choose Add www, Remove www or hotlink protection, and fix any field marked in red.

3

Download or copy

Click Download (rename the file to .htaccess if your browser changes the name) or Copy and paste it into your existing file.

4

Upload and test

Upload it to the site's root folder, then open your site over http:// and https://, with and without www. If you see a 500 error, restore the backup.

Privacy & Processing

  • Mode: local
  • Files Leave Browser: Local tool processing; review details below
  • Max Input Size: Device memory limits
  • Account Required: No
  • Data Stored Locally: Nothing is saved; reloading the page resets the options.
  • Network Processing: Assets or models may require an initial download

The file is generated in your browser. Nothing you enter is uploaded or saved.

Rules & Limitations

  • Works on Apache 2.4 and LiteSpeed only. Nginx, IIS, Vercel, Netlify and Cloudflare Pages ignore .htaccess. OpenLiteSpeed reads only the rewrite (redirect) rules from it.
  • One wrong line makes the whole site return HTTP 500, so keep a backup and test straight after uploading.
  • Your host must allow .htaccess overrides. Rules that need a missing module are skipped, but some hosts don't allow Options -Indexes; remove that line if it causes an error.
  • IP blocking replaces other access rules in the same folder, such as password protection. The file explains how to keep a password.
  • On Cloudflare, use SSL/TLS mode Full or Full (strict). The HTTPS rule checks X-Forwarded-Proto so it doesn't loop, but other plugins or rules may.

Top Suggestions

  • Forcing HTTPS after installing a free SSL certificate on cPanel hosting
  • Choosing www or non-www so Google sees one version of the site
  • Blocking spam or attack traffic from specific IP addresses
  • Hosting a React or Vue app on shared Apache hosting
  • Speeding up a WordPress or static site with compression and caching

.htaccess Generator FAQ

How do I redirect HTTP to HTTPS with .htaccess?

Turn on Force HTTPS, copy the file and upload it as .htaccess to your site's root folder. It sends every http:// request to the same page on https:// with one permanent (301) redirect.

Why does my site show a 500 Internal Server Error after editing .htaccess?

Apache rejects the whole file if one line is invalid or uses a module that isn't available. Restore your backup, then add sections one at a time to find the line, and check your host's error log.

How do I block an IP address in .htaccess?

Turn on Block IP addresses and enter one address or range per line, such as 203.0.113.7 or 198.51.100.0/24. The tool writes Require not ip lines inside a RequireAll block, which Apache 2.4 needs; a bare Require not line causes a 500 error.

Should I use www or non-www?

Either works for SEO, as long as one redirects to the other. Pick the one you already use in Google Search Console and links, and use the same choice everywhere.

Why does my site loop with "too many redirects" on Cloudflare?

With Cloudflare's Flexible SSL, your server sees every request as http://, so a simple HTTPS rule redirects forever. Switch Cloudflare to Full SSL; the rules from this tool also check the X-Forwarded-Proto header to avoid the loop.

Is my configuration sent anywhere?

No. The file is built in your browser; your domain, IP addresses and redirects are not uploaded or saved.