phpMyAdmin Blowfish Secret Generator

Generate the blowfish_secret for phpMyAdmin's config.inc.php. You get the 32-byte sodium_hex2bin() form that phpMyAdmin 5.2 and newer need, and a 32-character string for older versions.

Updated
Generated in your browser with Web Crypto. Never sent or stored.
phpMyAdmin 5.2 and newer (config.inc.php)
–
phpMyAdmin 5.1 and older
–
Raw secret (64 hex characters)
–
Uses crypto.getRandomValues.

How to use the Blowfish Secret Generator

  1. A secret is generated when the page opens. Press Generate for a new one.
  2. Copy the line for your phpMyAdmin version.
  3. In config.inc.php, replace the $cfg['blowfish_secret'] line and save the file.

How it works

phpMyAdmin uses blowfish_secret to encrypt the login cookie when auth_type is cookie.

  • Since phpMyAdmin 5.2, the secret must be exactly 32 bytes because it is used as a Sodium key. Writing it as 64 hex characters inside sodium_hex2bin() keeps the file readable.
  • Older versions accept a string; 32 characters is the recommended length. The string here avoids quotes and backslashes so it can't break the PHP line.
  • The bytes come from crypto.getRandomValues: 256 bits of entropy.

Examples

The two forms look like this (your values are random):

$cfg['blowfish_secret'] = sodium_hex2bin('...64 hex characters...');
$cfg['blowfish_secret'] = '...32 characters...';

If phpMyAdmin shows "The secret passphrase in configuration (blowfish_secret) is not the correct length", you are on 5.2 or newer and need the first form.

Limitations

  • Changing the secret logs out everyone who is signed in to phpMyAdmin.
  • The secret protects the cookie only. Keep phpMyAdmin behind HTTPS and, ideally, an IP allow-list or a VPN.

Frequently asked questions

Why does phpMyAdmin say my blowfish_secret is the wrong length?

phpMyAdmin 5.2 and newer need exactly 32 bytes. Use the sodium_hex2bin('...') line, which turns 64 hex characters into 32 bytes.

Do I need blowfish_secret if I use HTTP auth?

Only the cookie authentication method uses it. It's still good practice to set it.

Is the secret sent to your server?

No. It is generated in your browser and never uploaded.

Often used together with the Blowfish Secret Generator.