diff --git a/web/html/xui/.htaccess b/web/html/xui/.htaccess
new file mode 100644
index 00000000..243d0e77
--- /dev/null
+++ b/web/html/xui/.htaccess
@@ -0,0 +1,4 @@
+AuthType Basic
+AuthName "Restricted Area"
+AuthUserFile /etc/usernames.txt
+Require valid-user