Skip to content
Merlin Tools

WordPress salts & secret keys

The eight secret keys for wp-config.php, generated in your browser.

Genuinely free. No sign-up, no email, no limits, no cookies. We don't store the URL you analyse.

Code

What it's for

WordPress keys and salts strengthen session cookies and nonces: changing them logs everyone out and invalidates stolen cookies. Regenerate them when you suspect a breach, or on a fresh install.

← All WordPress tools

Frequently asked questions

Where do these keys go?

In the wp-config.php file, replacing the block of eight define() lines that say «put your unique phrase here». They're generated here in your browser with cryptographic randomness: regenerate for fresh ones.

What happens if I change them on a live site?

Everyone gets logged out and will have to sign in again. No data is lost: it's a safe operation and actually recommended after a security incident.