WordPress Salt Generator

Generate the eight authentication keys and salts for wp-config.php. Paste them in to secure your WordPress cookies, or to log every user out after a security incident.

Updated
Generated in your browser with Web Crypto. Never sent or stored.

Replace the eight define() lines between "Authentication unique keys and salts" and "That's all, stop editing!" in wp-config.php.

Uses crypto.getRandomValues.

How to use the WordPress Salt Generator

  1. The eight lines are generated when the page opens. Press Generate for a new set.
  2. Press Copy all.
  3. In wp-config.php, replace the lines from define( 'AUTH_KEY' to define( 'NONCE_SALT' with the copied block and save the file.

How it works

WordPress uses these values to sign login cookies and nonces. The keys are the secrets; the salts are extra input to the same hashes.

  • Each value is 64 characters, the length of WordPress's own wp_generate_password( 64, true, true ).
  • Characters come from the same set: letters, digits, and !@#$%^&*()-_ []{}<>~`+=,.;:/?|. The set has no quote or backslash, so the values are safe in single-quoted PHP strings.
  • Each character is chosen with crypto.getRandomValues, so a value has about 64 × 6.5 ≈ 416 bits of entropy.

Examples

The output has this shape (your values are random):

define( 'AUTH_KEY',         '...64 characters...' );
define( 'SECURE_AUTH_KEY',  '...' );
define( 'LOGGED_IN_KEY',    '...' );
define( 'NONCE_KEY',        '...' );
define( 'AUTH_SALT',        '...' );
define( 'SECURE_AUTH_SALT', '...' );
define( 'LOGGED_IN_SALT',   '...' );
define( 'NONCE_SALT',       '...' );

Limitations

  • Changing the salts logs out every user, including you. That is the point after a breach, but plan it on a busy site.
  • If your host or a security plugin manages the keys, change them there instead so they aren't overwritten.
  • Keep a backup of wp-config.php before editing it.

Frequently asked questions

What do WordPress salts do?

They make the login cookies and nonces WordPress creates hard to forge. Without them, someone who guessed or stole cookie data could build valid cookies.

When should I change my WordPress salts?

After a hack or a suspected leak, when an administrator leaves, or if the keys were ever committed to a public repository. Changing them logs everyone out.

Is this the same as the WordPress.org secret-key service?

It produces the same format and character set. The difference is that these values are made in your browser, so no server ever sees them.

Are the salts sent anywhere?

No. They are generated in your browser and never uploaded.

Often used together with the WordPress Salt Generator.