Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Some links on this page are affiliate links: if you buy through them we may earn a commission, at no extra cost to you.

WordPress security keys and salts are secret configuration values that add site-specific secret material to authentication cookies, nonces, and related hashes. They are stored as constants in wp-config.php; they are not your WordPress password, a hardware security key, or encryption for the entire site. Changing them invalidates existing authentication cookies, so users must sign in again.

Where WordPress security keys and salts are stored

The conventional settings appear in wp-config.php, normally near the other database and site configuration values:

define( 'AUTH_KEY',         'put your unique phrase here' );
define( 'SECURE_AUTH_KEY',  'put your unique phrase here' );
define( 'LOGGED_IN_KEY',     'put your unique phrase here' );
define( 'NONCE_KEY',         'put your unique phrase here' );
define( 'AUTH_SALT',         'put your unique phrase here' );
define( 'SECURE_AUTH_SALT',  'put your unique phrase here' );
define( 'LOGGED_IN_SALT',    'put your unique phrase here' );
define( 'NONCE_SALT',        'put your unique phrase here' );

Those example phrases are placeholders. Use long, random, unique values generated for your site; do not copy illustrative values from documentation into a live installation. WordPress describes the four key constants as required for enhanced security. The four salts are recommended, and WordPress can generate missing salts when needed.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

What each key and salt does

A key is secret input to a hashing or token calculation. A salt is additional secret or random input used with that calculation. WordPress groups them into four schemes:

Scheme Constants Purpose
Authentication AUTH_KEY and AUTH_SALT Supports authentication-cookie calculations.
Secure authentication SECURE_AUTH_KEY and SECURE_AUTH_SALT Supports authentication when WordPress uses a secure connection.
Logged-in status LOGGED_IN_KEY and LOGGED_IN_SALT Supports cookies that identify a logged-in session.
Nonce NONCE_KEY and NONCE_SALT Contributes secret material to WordPress nonce generation.

WordPress exposes wp_salt( $scheme ) for the auth, secure_auth, logged_in, and nonce schemes. The function returns secret material to add to hashes. When suitable constants are defined, WordPress uses them. If a scheme is missing or has unsuitable duplicated values, WordPress can retrieve a stored site value or generate and store a fallback.

This is best understood as secret input to a hash or token calculation. The values do not encrypt every file, hide all traffic, or independently stop attacks.

How the values protect login cookies

When WordPress receives an authentication cookie, it validates the cookie, checks whether it has expired, verifies its hash, and returns a user ID when the cookie is valid. The site-specific keys and salts contribute to that verification. Someone who copies a cookie from another site cannot make it valid on yours merely by reusing the cookie’s visible format.

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

The protection still depends on the rest of the security model: patched software, secure passwords, HTTPS, appropriate account permissions, and protection of the server and configuration file. Keys are one input to cookie validation, not a complete security program.

What happens when you change the keys

Changing the key-and-salt values changes the secret material used to verify existing cookies. WordPress therefore invalidates all existing authentication cookies. Every affected user, including administrators, must log in again.

When rotation is useful

  • After accidental disclosure of wp-config.php or its secrets.
  • When transferring responsibility for a site and you want old sessions to end.
  • As part of a documented incident-response or credential-rotation plan.

Rotation does not repair malware, remove an attacker who still has server access, patch a vulnerable plugin, or reset every other credential. Investigate and remediate those problems separately.

Rotating with WP-CLI

Administrators who use WP-CLI can run:

wp config shuffle-salts

The command refreshes the salts in wp-config.php. WP-CLI also supports targeting a particular configuration file when your installation requires an explicit path. Keep a verified backup and ensure the file remains valid before ending the session in which you are working.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Keys, salts and nonces are not the same thing

Term What it means What it does not provide
Key Secret input used in a WordPress hash or token calculation. It is not a user’s password or a physical security device.
Salt Additional secret or random input combined with a calculation. It is not a standalone access-control system.
Nonce A WordPress security token generated with site-specific key and salt material, commonly to help protect requests from cross-site request forgery. It is not authentication, authorization, a capability check, or guaranteed one-time-use replay protection.

WordPress explicitly warns that nonces must never be relied on for authentication, authorization, or access control. A protected action should also check the user’s capability, for example with current_user_can(). A valid nonce alone must not grant permission.

Protect wp-config.php

The file contains database settings and other sensitive configuration in addition to the security keys and salts. Restrict who can read it, avoid exposing it through backups or downloads, and edit it only through a controlled administrative process.

WordPress hardening guidance discusses placing wp-config.php one directory above the WordPress installation when the server setup supports that arrangement, and limiting file permissions. These are server-specific changes: verify how your hosting stack resolves the file before moving it or changing permissions, and keep a recovery copy outside the web-accessible area.

Practical checklist

  • Generate long, random, site-specific values rather than reusing examples or secrets from another site.
  • Keep all four key constants and, preferably, all four salt constants defined.
  • Store and transmit wp-config.php as a sensitive file.
  • After suspected disclosure, rotate the values and expect every user to authenticate again.
  • Use nonces only for their intended request-protection role and perform separate capability checks.
  • Continue patching WordPress, themes, and plugins and use HTTPS; key rotation is not a substitute for those controls.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.