WordPress Salt & Security Key Generator
Generate the eight WordPress authentication keys and salts in your browser, as define() lines, an array, or environment variables.
/**
* Authentication unique keys and salts.
*
* Changing these logs every user out. They are not stored anywhere else,
* so there is nothing to keep in step: rotate them whenever you want to.
*/
define( 'AUTH_KEY', 'put your unique phrase here' );
define( 'SECURE_AUTH_KEY', 'put your unique phrase here' );
define( 'LOGGED_IN_KEY', 'put your unique phrase here' );
define( 'NONCE_KEY', 'put your unique phrase here' );
define( 'AUTH_SALT', 'put your unique phrase here' );
define( 'SECURE_AUTH_SALT', 'put your unique phrase here' );
define( 'LOGGED_IN_SALT', 'put your unique phrase here' );
define( 'NONCE_SALT', 'put your unique phrase here' );
Output is valid and updates as you type.
Fix the highlighted fields to update the output.
Generate the eight WordPress authentication keys and salts. They are produced by your own browser’s cryptographic random generator and never sent anywhere, which is the one property that matters for a secret.
How to use
- Pick the format.
define()lines go straight intowp-config.php, above the line that says to stop editing. - Replace all eight existing lines. WordPress uses each of them for a different cookie, and a half-replaced set logs some users out and not others.
- Save the file and reload the site. Everyone, including you, is logged out. That is the expected result, not a mistake.
- Rotate them whenever you suspect a session was stolen, when a contractor’s access ends, or after any breach.
- Never commit them to a public repository. If you have, generate a new set now.
Example
define( 'AUTH_KEY', 'q!X2...' );
define( 'SECURE_AUTH_KEY', 'B7#z...' );
define( 'LOGGED_IN_KEY', 'Lp$4...' );
define( 'NONCE_KEY', 'v8@W...' );
define( 'AUTH_SALT', 'M1^c...' );
define( 'SECURE_AUTH_SALT', 'r6&K...' );
define( 'LOGGED_IN_SALT', 'T3*n...' );
define( 'NONCE_SALT', 'Z9(j...' );
There is nothing to keep in step with these: no database record, no other file. They exist only in wp-config.php, which is why changing them is safe and immediate.
Pitfalls
- Changing the keys logs every user out, including you. On a membership site, tell people first.
- Replacing only some of the eight leaves old cookies partly valid, which produces intermittent logouts that are very hard to debug.
- The four
_KEYconstants and the four_SALTconstants are not interchangeable. Keep the names exactly as WordPress defines them. - A salt generator that runs on someone’s server means that server saw your keys. This one runs in your browser; check any other you use.
- Keys left as
put your unique phrase heremean every cookie on the site is signed with a value anybody can look up. - Committing
wp-config.phpto a repository publishes them. Rotating is the only fix once that has happened. NONCE_SALTaffects form nonces as well as cookies, so a user with a form open when you rotate gets an expired nonce.- Backups contain the old keys. A restore reverts them, and every session issued since is invalidated again.
Compatibility
All eight constants have been read by WordPress since 3.0 and are still current in WordPress 6.x. Any printable ASCII is valid; WordPress.org’s own service issues 64 characters. The generated values come from crypto.getRandomValues, available in every browser since 2014. Nothing is uploaded and nothing is logged.
Frequently asked questions
Will changing these log everyone out?
How often should I rotate them?
Are these the same as a password?
Can I use longer keys?
Where exactly do they go?
wp-config.php, replacing the existing block, before the line about not editing past that point.