What the generator does
WordPress signs login cookies and nonces with eight constants in wp-config.php: AUTH_KEY, SECURE_AUTH_KEY, LOGGED_IN_KEY, NONCE_KEY and their _SALT counterparts. When these values are unpredictable, forging a valid session cookie becomes very hard, even if the database leaks.
The tool gives you the eight values in three formats: define() lines for a classic install, .env lines for Bedrock and Roots projects, and JSON for automation scripts. Use it for a new install, after a suspected compromise or when someone with access leaves the team.
How to use it
- Choose the output format: PHP
define(),.envor JSON. - Press “Generate keys”. Every press creates eight new values.
- Copy the code or download it as a file.
- In
wp-config.php, replace the eight lines under the “Authentication unique keys and salts” comment. In Bedrock, update the same names in.env. - Save the file and tell your team beforehand that everyone will have to log in again.
- When you are done, press “Clear” to remove the values from the page and delete the downloaded file.
If you use WP-CLI, wp config shuffle-salts does the same job on the server. This tool helps when you have no command-line access or want to review the values first.
Character set and randomness
The character set is the same as WordPress core's wp_generate_password(64, true, true), which the setup wizard uses when it cannot reach api.wordpress.org/secret-key/1.1/salt/. It has 92 characters:
| Group | Characters |
|---|---|
| Letters and digits (62) | a–z, A–Z, 0–9 |
| Special (10) | !@#$%^&*() |
| Extra special (20) | -_[]{}<>~+=,.;:/?|, the backtick and the space |
Single quotes, double quotes and backslashes are not in the set, so a value cannot break a PHP single-quoted string, a single-quoted .env value or a JSON string. The space belongs to the WordPress set and is harmless inside quotes.
Random bytes come from crypto.getRandomValues; Math.random is never used, and without Web Crypto the tool refuses to generate keys. A byte has 256 possible values and 256 is not a multiple of 92, so a plain modulo would favour some characters. The tool therefore discards bytes of 184 and above and maps the rest modulo 92, giving every character the same probability. One 64-character value covers roughly 417 bits of possibilities.
What changing the salts does
Changing the keys invalidates every existing login cookie. Everyone, including you, is logged out and has to sign in again. Passwords do not change, and content and settings are not affected. Nonces in forms that are still open also become invalid, so unfinished actions may fail.
If the constants are missing or still contain the default “put your unique phrase here”, WordPress falls back to values stored in the database. New salts alone are not a clean-up: on a compromised site, also review passwords, administrator accounts and files. The .htaccess redirect generator can help when you tidy up server rules.
Example and interpretation
PHP output keeps the alignment of the WordPress service: on each line the value starts at column 29. The lines below are shortened and only show the layout; do not use these values:
define('AUTH_KEY', 'ORNEK-q7}Lm2 ^v@Xw!8zR<Pc;eT4#Hy/…');
define('SECURE_AUTH_KEY', 'ORNEK-J0k&d$9 [nB~uF,5sW=Ga%1…');
AUTH_KEY='ORNEK-q7}Lm2 ^v@Xw!8zR<Pc;eT4#Hy/…'.env lines use single quotes. The parser Bedrock relies on does not expand $ inside single quotes, while double quotes could change the value. The JSON output is meant for deployment scripts or a secrets manager.
Limits and privacy
- Values are created in your browser's memory only; they are never sent to a server or written to a share link, a cookie or local storage. The share button copies the page address only.
- A clipboard manager may keep what you copy, and a downloaded file stays on your computer. Clear both when you are done.
- The tool never reads or edits your
wp-config.php; you make the change on the server yourself. - Do not put
wp-config.phpor.envin a public repository, where the secrets could be harvested.
Frequently asked questions
Will changing the salts break my site?
No. Every user is logged out and has to sign in again; passwords, content and settings stay the same.
Are the values as strong as api.wordpress.org?
They use the same 92-character set and the same 64-character length. Randomness comes from your browser's cryptographic generator, and the values never travel over the network.
How often should I change them?
There is no fixed rule. A suspicious login, a leak, a person with access leaving the team or a server move are all good reasons.
Is a space inside a value a problem?
No. The space is part of WordPress's own character set and is read as is inside single quotes.
Where do the values go in Bedrock?
In the .env file at the project root, written as AUTH_KEY='...'. Bedrock reads them as environment variables in its configuration.