Ffile2fix
Sign in Get started

How to fix ".htaccess: Options not allowed here"

/home/user/public_html/.htaccess: Options not allowed here

Your .htaccess contains an Options line, but the server's AllowOverride setting does not let .htaccess files change those options, so Apache returns a 500 error. This is common on shared hosts that forbid FollowSymLinks for security.

Also appears as: /var/www/html/.htaccess: Option FollowSymLinks not allowed here · /var/www/html/.htaccess: Option Indexes not allowed here · /home/user/public_html/.htaccess: Option MultiViews not allowed here · AH00526: ... Options not allowed here

Common causes

  • Options +FollowSymLinks in .htaccess on a cPanel host that only allows SymLinksIfOwnerMatch
  • AllowOverride is set without Options, for example AllowOverride FileInfo AuthConfig
  • AllowOverride Options=Indexes,MultiViews allows only specific options and your file sets another
  • Options -Indexes or +ExecCGI added by a plugin, script installer or copied snippet
  • A migrated .htaccess written for a server with AllowOverride All

How to fix it

  1. Find the Options line. Open .htaccess in the folder named in the error log and look for every Options line, including in subfolders like wp-content/uploads.
  2. Use SymLinksIfOwnerMatch on shared hosting. Replace Options +FollowSymLinks with Options +SymLinksIfOwnerMatch. Most cPanel hosts allow it, and mod_rewrite works with either.
  3. Remove options the host forbids. If Options -Indexes is not allowed, remove the line and add an empty index.html to the folder instead, or ask the host to disable directory listing.
  4. Adjust AllowOverride on a VPS. In the vhost's <Directory> block, add Options to AllowOverride (or list allowed ones: AllowOverride FileInfo AuthConfig Options=Indexes,SymLinksIfOwnerMatch). Run apachectl configtest and reload.
  5. Prefer the main config. On servers you control, set Options in the vhost instead of .htaccess; it is faster and avoids the override check entirely.

.htaccess and Apache vhost

# .htaccess on shared hosting
Options +SymLinksIfOwnerMatch
RewriteEngine On

# Apache vhost on a VPS
<Directory /var/www/example.com/public>
    Options -Indexes +SymLinksIfOwnerMatch
    AllowOverride FileInfo AuthConfig Indexes Options=Indexes,SymLinksIfOwnerMatch
    Require all granted
</Directory>

How to stop it happening again

  • Use SymLinksIfOwnerMatch in .htaccess files you ship to clients
  • Test copied snippets on staging before production
  • Keep server-wide Options in the vhost config, not .htaccess

Frequently asked questions

Why does my host block FollowSymLinks?

On shared servers, FollowSymLinks lets one account symlink to another account's files. SymLinksIfOwnerMatch only follows links owned by the same user, which is safer.

Do rewrite rules need FollowSymLinks?

mod_rewrite in .htaccess requires either FollowSymLinks or SymLinksIfOwnerMatch to be on. Most hosts enable one by default, so you often do not need an Options line at all.

Why does the error only appear in a subfolder?

Apache reads .htaccess in every folder along the path. A plugin-created .htaccess deeper in the tree, such as in uploads/, can contain the forbidden Options line.