# Htpasswd in traefik.toml

**URL:** <https://community.traefik.io/t/htpasswd-in-traefik-toml/915>\
**Category:** Traefik v1\
**Tags:** dashboard-api, docker\
**Created:** [July 17, 2019, 11:35am UTC](https://community.traefik.io/t/htpasswd-in-traefik-toml/915 "2019-07-17T11:35:00Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![joenas](https://sea2.discourse-cdn.com/flex020/user_avatar/community.traefik.io/joenas/32/463_2.png) [@joenas](https://community.traefik.io/u/joenas)\
**Post date:** [July 17, 2019, 11:35am UTC](https://community.traefik.io/t/htpasswd-in-traefik-toml/915/1 "2019-07-17T11:35:00Z")

</div>

Hey all! I’ve written a [guide](https://jonnev.se/traefik-with-docker-and-lets-encrypt/) on installing Traefik together with Docker. It also includes adding the dashboard/API with Basic Auth protection. Previously I had the user/password as a label in docker-compose but moved it to traefik.toml. My question is whether I still need to escape $ when doing that or if it’s only applicable in yaml-files? I do escape at the moment and it seems to work but...

---

<div class="post-metadata">

**Author:** ![douglasdtm](https://sea2.discourse-cdn.com/flex020/user_avatar/community.traefik.io/douglasdtm/32/2002_2.png) [@douglasdtm](https://community.traefik.io/u/douglasdtm)\
**Post date:** [August 9, 2019, 6:11pm UTC](https://community.traefik.io/t/htpasswd-in-traefik-toml/915/2 "2019-08-09T18:11:35Z")

</div>

Hi @joenas !

You are probably hitting a docker-compose variable substitution in this case, more info [here](https://docs.docker.com/compose/compose-file/#variable-substitution).

On that case you did right by adding a `$` before the value.

You can also try passing a file directly to the configuration, like:  
`usersFile = "/path/to/.htdigest"` as described in [this](https://docs.traefik.io/configuration/entrypoints/#basic-authentication) section of the docs.

Keep in mind that setting any sensitive information in config files is never a good idea, unless it's just for education as seems to be your case. But if you want to set these types of values in a config I would recommend using environment variables and then doing some variable substitution yourself using tools like `envsubst` ( _GNU_ gettext-runtime).
