What are WordPress salts and security keys?
WordPress combines site-specific keys and salts when signing authentication cookies and creating other security-sensitive hashes. A standard wp-config.php section defines four keys and four matching salts: AUTH, SECURE_AUTH, LOGGED_IN, and NONCE.
Why generate eight separate values?
Each constant has a distinct role. Reusing one value across all eight removes that separation. This generator creates eight independently random 64-character values and checks that the finished values are unique before formatting the PHP block.
Where should the block go?
Open the site's existing wp-config.php, find the authentication unique keys and salts section, and replace all eight current define() lines with the copied block. Do not add a second set with the same constant names. Save a recoverable backup before editing a production configuration file.
What happens after rotation?
Existing WordPress authentication cookies were signed using the previous secrets, so they stop validating after the constants change. Users must log in again. This is useful after suspected configuration exposure, but schedule the change if an immediate site-wide sign-out would disrupt administrators or customers.
How the values match WordPress core
WordPress core's wp_generate_password() can use letters, digits, standard symbols, and an extra-symbol set when creating secret keys and salts. This tool uses that documented full alphabet and 64 characters per value. Apostrophes and backslashes are absent from the core alphabet, so the results remain valid inside the generated single-quoted PHP strings.
Official alternatives
WordPress operates its own secret-key service. If WP-CLI is installed on the target system, wp config shuffle-salts can update the configuration directly. This browser tool is useful when you want local generation and a block you can inspect before applying.
Official sources
The constant names and configuration placement follow the WordPress wp-config.php handbook. The character set follows the documented wp_generate_password() source. The command-line alternative is documented in WP-CLI's config shuffle-salts command.
Related developer tools
Django secret key generator follows Django's framework-specific format. API key generator creates opaque API credentials. Random key generator creates generic raw key material. Use this page specifically for WordPress's eight constants.