WordPress salts & secret keys
The eight secret keys for wp-config.php, generated in your browser.
Genuinely free. No sign-up, no email, no limits, no cookies. We don't store the URL you analyse.
Code
What it's for
WordPress keys and salts strengthen session cookies and nonces: changing them logs everyone out and invalidates stolen cookies. Regenerate them when you suspect a breach, or on a fresh install.
Frequently asked questions
›Where do these keys go?
In the wp-config.php file, replacing the block of eight define() lines that say «put your unique phrase here». They're generated here in your browser with cryptographic randomness: regenerate for fresh ones.
›What happens if I change them on a live site?
Everyone gets logged out and will have to sign in again. No data is lost: it's a safe operation and actually recommended after a security incident.