Each line is user:hash; the prefix names the scheme: $2y$ bcrypt, $6$ and $5$ SHA-512 and SHA-256 crypt (-5, -2), $apr1$ MD5 (the default), and the insecure {SHA} and crypt. Apache 129 checks the hash on every request, each image included:
for c in 5 10 12 14; do
printf 'x\n' | sudo htpasswd -i -B -C $c /etc/apache2/auth/htpasswd t$c 2>/dev/null
curl -s -o /dev/null -w "cost $c: %{time_total}s\n" -u t$c:x localhost:8108/admin/
donecost 5: 0.002904s cost 10: 0.050395s cost 12: 0.209193s cost 14: 0.851427s
At cost 14 a page with 20 images burns 17 CPU seconds; use 10 to 12. Past "a few hundred entries", the manual's limit for flat files, switch to AuthBasicProvider dbm or dbd.
A group file holds lines such as editors: alice carol. Add AuthGroupFile /etc/apache2/auth/groups to the file of Basic Authentication and make its last line Require group editors: Alice gets 200, and Bob, password right, gets 401 (AH01631: user bob: authorization failure). Keep both files outside the document root, owned root:www-data, mode 640; at 600 every login got a 500 (AH01620: Could not open password file).