Set Up Nginx Basic Authentication in Ubuntu 24.04
Nginx basic authentication in Ubuntu 24.04 blocks random visitors from opening specific website folders by asking for a username and password before loading the page. This security layer adds a login screen to private directories like /var/www/html/private so only people you approve can see the content.
You create the login details with a built-in password tool, and then update your Nginx configuration to check those details. Running this setup over HTTPS keeps your login safe from snooping eyes on the network.
Install Apache utilities with `sudo apt install apache2-utils`. Then, create a password file using `sudo htpasswd -Bc /etc/nginx/.htpasswd username` and configure your Nginx server block to use it for protected locations. Finally, reload Nginx using `sudo systemctl reload nginx`.
Protect directories with Nginx basic authentication
You can protect specific website directories in Ubuntu 24.04 with Nginx basic authentication by installing password-hashing tools from Apache. This adds a secure login screen to any folder on your server, stopping visitors from viewing private files unless they type the correct username and password.
sudo apt install apache2-utils
After installing the utilities, continue below to protect a directory with a username and password.
For this post, we’ll protect /var/www/html/sensitive-doc with a password. Anyone who wants to access this directory must type a username and password.
To do that, first, open the default Nginx server block file. You can create a new one, but we will use the default file for this post.
sudo nano /etc/nginx/sites-available/default
Next, add the highlighted block to the server {} section in the file.
# Default server configuration
#
server {
listen 80 default_server;
listen [::]:80 default_server;
root /var/www/html;
index index.html index.htm index.nginx-debian.html;
server_name example.com;
location /sensitive-doc {
auth_basic "Basic Auth";
auth_basic_user_file "/etc/nginx/.htpasswd";
}
location / {
# First attempt to serve request as file, then
# as directory, then fall back to displaying a 404.
try_files $uri $uri/ =404;
}
# pass PHP scripts to FastCGI server
#
..........
..........
Exit and save the file when you're done.
Create accounts
After setting up the config above, use the command below to create an account to log on to the directory.
sudo htpasswd -Bc /etc/nginx/.htpasswd username
Create the protected directory
Creating the directory you want to protect gives Nginx basic authentication in Ubuntu 24.04 a specific folder to lock down. You need to make this folder on your server before you can attach a password file to it and restrict access.
sudo mkdir /var/www/html/sensitive-doc
Once created, enable the Nginx server block and reload its services by running the commands below.
sudo systemctl reload nginx
Next, run the command below and add a basic HTML ‘index.html‘ file.
sudo nano /var/www/html/sensitive-doc/index.html
Copy and paste the lines below into the file and save.
<html>
<title>My basic authentication HTML page</title>
<body>
<p style="width: 100%; font-weight: bold; font-size: 60px; text-align: center;">
Basic authentication is enabled!
</p>
</body>
</html>
Save the file and exit.
Test Nginx basic authentication
Testing your Nginx basic authentication setup in Ubuntu 24.04 lets you check that the password prompt actually appears before anyone can view your files. Open your web browser and try to visit the protected folder address to see the login box pop up.
http://example.com/sensitive-doc/
You will see a prompt to enter a username and password.

You must enter the correct username and password to sign in.

That should do it!
Conclusion:
Setting up Nginx basic authentication provides a simple yet effective way to secure specific directories on your Ubuntu server. By following the steps outlined in this article, you can ensure that sensitive information is protected. Here are the key takeaways:
- Increased Security: Implement basic authentication to control access to sensitive directories.
- Use of SSL/TLS: Prioritize setting up SSL/TLS to encrypt data before transmitting credentials.
- Nginx Configuration: Modify your Nginx server block to enable authentication for designated locations.
- User Management: Easily create and manage user accounts with the
htpasswdcommand. - Testing: Verify that authentication works as expected by accessing the protected directory from a web browser.
- Simple Implementation: Quickly secure your directories with straightforward command-line instructions.
Nginx basic authentication fortifies your web application by ensuring only authorized users can access protected resources like sensitive configuration files. This security step prevents unauthorized access and protects your data from casual snooping.
Was this guide helpful?
About the Author
Richard
Tech Writer, IT Professional
Richard is a writer at Geek Rewind who turns complex IT tasks into clear, step-by-step guides. He draws on years of hands-on experience in system administration and enterprise IT operations, focusing on Windows, Linux and WordPress: the problems people actually run into, and the fixes that work. His server and WordPress guides come from systems he runs himself. Richard builds and maintains the platform behind Geek Rewind, from its Ubuntu servers and Nginx configuration to its custom WordPress plugins. Many new tutorials start with readers' questions, and he's always glad to answer them in the comments.
No comments yet — be the first to share your thoughts!