Do these 3 things before closing this tab:
1Fix the driver behind crashes, sound loss and screen glitches2Clear out junk files and repair common Windows errors3Scan for outdated or missing drivers - takes under a minuteSome links on this page are affiliate links: if you buy through them we may earn a commission, at no extra cost to you.
WordPress security keys and salts are secret configuration values that add site-specific secret material to authentication cookies, nonces, and related hashes. They are stored as constants in wp-config.php; they are not your WordPress password, a hardware security key, or encryption for the entire site. Changing them invalidates existing authentication cookies, so users must sign in again.
Where WordPress security keys and salts are stored
The conventional settings appear in wp-config.php, normally near the other database and site configuration values:
define( 'AUTH_KEY', 'put your unique phrase here' );
define( 'SECURE_AUTH_KEY', 'put your unique phrase here' );
define( 'LOGGED_IN_KEY', 'put your unique phrase here' );
define( 'NONCE_KEY', 'put your unique phrase here' );
define( 'AUTH_SALT', 'put your unique phrase here' );
define( 'SECURE_AUTH_SALT', 'put your unique phrase here' );
define( 'LOGGED_IN_SALT', 'put your unique phrase here' );
define( 'NONCE_SALT', 'put your unique phrase here' );
Those example phrases are placeholders. Use long, random, unique values generated for your site; do not copy illustrative values from documentation into a live installation. WordPress describes the four key constants as required for enhanced security. The four salts are recommended, and WordPress can generate missing salts when needed.
What each key and salt does
A key is secret input to a hashing or token calculation. A salt is additional secret or random input used with that calculation. WordPress groups them into four schemes:
#1 Best Overall
| Scheme | Constants | Purpose |
|---|---|---|
| Authentication | AUTH_KEY and AUTH_SALT |
Supports authentication-cookie calculations. |
| Secure authentication | SECURE_AUTH_KEY and SECURE_AUTH_SALT |
Supports authentication when WordPress uses a secure connection. |
| Logged-in status | LOGGED_IN_KEY and LOGGED_IN_SALT |
Supports cookies that identify a logged-in session. |
| Nonce | NONCE_KEY and NONCE_SALT |
Contributes secret material to WordPress nonce generation. |
WordPress exposes wp_salt( $scheme ) for the auth, secure_auth, logged_in, and nonce schemes. The function returns secret material to add to hashes. When suitable constants are defined, WordPress uses them. If a scheme is missing or has unsuitable duplicated values, WordPress can retrieve a stored site value or generate and store a fallback.
This is best understood as secret input to a hash or token calculation. The values do not encrypt every file, hide all traffic, or independently stop attacks.
Rank #2
How the values protect login cookies
When WordPress receives an authentication cookie, it validates the cookie, checks whether it has expired, verifies its hash, and returns a user ID when the cookie is valid. The site-specific keys and salts contribute to that verification. Someone who copies a cookie from another site cannot make it valid on yours merely by reusing the cookie’s visible format.
Free tools Windows power users keep installed
One-click scans. No signup required.
The protection still depends on the rest of the security model: patched software, secure passwords, HTTPS, appropriate account permissions, and protection of the server and configuration file. Keys are one input to cookie validation, not a complete security program.
What happens when you change the keys
Changing the key-and-salt values changes the secret material used to verify existing cookies. WordPress therefore invalidates all existing authentication cookies. Every affected user, including administrators, must log in again.
When rotation is useful
- After accidental disclosure of
wp-config.phpor its secrets. - When transferring responsibility for a site and you want old sessions to end.
- As part of a documented incident-response or credential-rotation plan.
Rotation does not repair malware, remove an attacker who still has server access, patch a vulnerable plugin, or reset every other credential. Investigate and remediate those problems separately.
Rank #4
Rotating with WP-CLI
Administrators who use WP-CLI can run:
wp config shuffle-salts
The command refreshes the salts in wp-config.php. WP-CLI also supports targeting a particular configuration file when your installation requires an explicit path. Keep a verified backup and ensure the file remains valid before ending the session in which you are working.
Keys, salts and nonces are not the same thing
| Term | What it means | What it does not provide |
|---|---|---|
| Key | Secret input used in a WordPress hash or token calculation. | It is not a user’s password or a physical security device. |
| Salt | Additional secret or random input combined with a calculation. | It is not a standalone access-control system. |
| Nonce | A WordPress security token generated with site-specific key and salt material, commonly to help protect requests from cross-site request forgery. | It is not authentication, authorization, a capability check, or guaranteed one-time-use replay protection. |
WordPress explicitly warns that nonces must never be relied on for authentication, authorization, or access control. A protected action should also check the user’s capability, for example with current_user_can(). A valid nonce alone must not grant permission.
Best Value
Protect wp-config.php
The file contains database settings and other sensitive configuration in addition to the security keys and salts. Restrict who can read it, avoid exposing it through backups or downloads, and edit it only through a controlled administrative process.
WordPress hardening guidance discusses placing wp-config.php one directory above the WordPress installation when the server setup supports that arrangement, and limiting file permissions. These are server-specific changes: verify how your hosting stack resolves the file before moving it or changing permissions, and keep a recovery copy outside the web-accessible area.
Quick Recap
Practical checklist
- Generate long, random, site-specific values rather than reusing examples or secrets from another site.
- Keep all four key constants and, preferably, all four salt constants defined.
- Store and transmit
wp-config.phpas a sensitive file. - After suspected disclosure, rotate the values and expect every user to authenticate again.
- Use nonces only for their intended request-protection role and perform separate capability checks.
- Continue patching WordPress, themes, and plugins and use HTTPS; key rotation is not a substitute for those controls.
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

