Salts and security keys
WordPress salts and security keys are eight long random strings in wp-config.php. WordPress uses them to make the login cookies and form tokens it hands out. Replace them and everyone who is logged in has to log in again.
- By
- WP Ministry
- Published
In short
- The eight lines run from AUTH_KEY to NONCE_SALT in wp-config.php. Each one should be long, random and different from the rest.
- Replacing them logs everyone out at once. It changes no password and revokes no application password.
- Replace them when you need every login session ended, such as after a break-in.
WordPress salts and security keys are eight constants in wp-config.php: four keys and four salts, each a long random string. WordPress mixes them into the login cookies and the form tokens it hands out, and uses them again to check each one that comes back. Replace them and every cookie already issued fails that check, so every user has to log in again.
Nobody types them. WordPress's documentation says you do not have to remember them, only make them long, random and complicated.
Where you meet it
In wp-config.php, in the folder WordPress is installed in, as eight lines:
define( 'AUTH_KEY', 'put your unique phrase here' );
define( 'SECURE_AUTH_KEY', 'put your unique phrase here' );
define( 'LOGGED_IN_KEY', 'put your unique phrase here' );
define( 'NONCE_KEY', 'put your unique phrase here' );
define( 'AUTH_SALT', 'put your unique phrase here' );
define( 'SECURE_AUTH_SALT', 'put your unique phrase here' );
define( 'LOGGED_IN_SALT', 'put your unique phrase here' );
define( 'NONCE_SALT', 'put your unique phrase here' );That is how WordPress's sample file ships them. On a working site each line holds a long random string in place of the phrase.
The names come in four pairs, a key and a salt each. AUTH and SECURE_AUTH are for the dashboard's cookie, over plain HTTP and over HTTPS. LOGGED_IN is for the cookie that says who you are on the rest of the site. NONCE is for the tokens in forms and links: see nonce.
A line that is missing, still reads "put your unique phrase here", or has the same value as another line is not used. WordPress makes a value of its own for it and keeps that in the database.
WordPress.org runs a service that returns eight fresh lines of 64 characters each. The salt and security key generator makes them in your browser, and the wp-config.php generator builds a whole file with new ones in it.
What goes wrong
- Everyone is logged out at the same moment, or over and over. Something replaced the keys: a plugin that rotates them, a deployment that writes a new
wp-config.php, or two servers behind one address that hold different keys. How to fix WordPress when it keeps logging you out has the check for each. - A form that was open says "The link you followed has expired." New keys make new tokens, so a page opened before the change holds old ones. Reload it. That message has its own page.
- The keys were replaced after a break-in, and the intruder is still in. New keys end sessions. They do not change a password, and an application password goes on working until it is revoked. Removing malware from a hacked site and dealing with an unknown admin user put the keys in order with the other steps.
How to look at yours
Open wp-config.php and find the eight lines. To replace them, paste eight new lines over the old ones. With WP-CLI, one command does it. It ends every login session on the site, yours included.
wp config shuffle-saltsIt answers Success: Shuffled the salt keys.
Common questions
Will changing the salts break my site?
No. Content, settings and passwords stay as they are. Every user is sent to the login screen once and logs in with the same password as before. A dashboard page left open in a browser needs reloading before its forms work again.
How often should I change them?
WordPress's documentation sets no schedule. It says you can change them at any time to invalidate all existing cookies. Change them when that is what you need: after a break-in, or when someone who should not have a copy of wp-config.php has seen it.
What is the difference between a key and a salt?
In use, very little. WordPress joins each key to its salt and uses the two as one secret. Its documentation calls the four keys required and the four salts recommended, because WordPress generates a salt when none is given. Treat all eight the same way.

