Get a free website with any plan

See how
WORDPRESS

Regenerating authentication keys and salts

Last updated

IN SHORT

WordPress authentication keys and salts in wp-config.php sign login cookies and session data. Regenerating them on your Flashcloud hosting account immediately invalidates every active user session across all browsers. It forces an instant logout for everyone without altering passwords or database content, making it a critical step after a suspected compromise.

WordPress uses eight authentication keys and salts, stored in wp-config.php, to sign login cookies, nonces, and session data. Regenerating them invalidates every active session, everywhere, immediately. It's the fastest way to force a full logout after a suspected compromise, a shared-computer scare, or routine hygiene after cleaning up a hacked site.

The keys look like this in wp-config.php: AUTH_KEY, SECURE_AUTH_KEY, LOGGED_IN_KEY, NONCE_KEY, and their _SALT counterparts. Changing any of them breaks the signature on existing cookies, so WordPress treats every logged-in browser, including yours, as logged out. Everyone has to sign back in with their password.

When to regenerate

A few situations call for it:

  • You suspect an account was compromised and want to kill any session an attacker might be holding, even one you haven't spotted yet.
  • You finished cleaning up a hacked or malware-infected site. Rotating keys after a cleanup is standard practice, alongside resetting admin passwords.
  • You're doing general security hardening and it's been years since the keys were last touched.
  • A developer or contractor had admin access and no longer should.

It's not something to do casually on a live store or busy site without warning users, since everyone gets logged out at once. On a WooCommerce store, logged-in customers get bumped mid-session, though carts tied to cookies rather than accounts can be affected too. See Running a WooCommerce store for more on session behavior. Time it for low-traffic hours if you can, or test the change on a staging copy first if you're nervous about the blast radius.

Method 1: a plugin, from wp-admin

This is the easier path and doesn't require touching files directly. A plugin like Salt Shaker or WPS Hide Login's key rotation feature (check current plugin names in the WordPress plugin directory, since availability changes) does this:

  1. Install and activate a key-rotation plugin from wp-admin → Plugins → Add New.
  2. Run the regenerate action from the plugin's settings page. It edits wp-config.php for you and writes eight new random 64-character keys pulled from WordPress.org's secret-key generator.
  3. You'll be logged out immediately. Log back in with your existing password, since the keys don't touch your password or user data, only session validity.

Once the rotation is done, there's no reason to keep the plugin active. Deactivate or remove it rather than leaving another plugin running in the background. If your site already runs a lot of plugins, this is a good moment to check My WordPress site is slow for guidance on auditing what's actually earning its keep.

Method 2: edit wp-config.php directly

If you're comfortable in File Manager or an SSH session, editing the file yourself is fast and doesn't require installing anything:

  1. Get a fresh set of keys from WordPress.org's secret-key API: https://api.wordpress.org/secret-key/1.1/salt/. It returns eight define() lines with random values, ready to paste in.
  2. Open wp-config.php in File Manager (Services → your hosting → File Manager in the portal) or connect over SFTP and edit it in a text editor.
  3. Find the block that starts with define( 'AUTH_KEY', ...) and ends with define( 'NONCE_SALT', ...). Replace the whole block with the new lines.
  4. Save the file. The change takes effect immediately, no restart needed, since PHP reads wp-config.php fresh on every request.

Back up the file before you edit it, so you've got a fallback if a copy-paste goes wrong and the site throws a fatal error. A malformed define() line, a stray quote, or a missing comma is the usual cause of a white screen after this kind of edit, and it's easy to fix once you know to check that block first.

What doesn't change

Regenerating keys doesn't touch usernames, passwords, post content, or the database at all. It's purely a cookie-signing change. If you actually suspect a compromised password, rotating keys alone isn't enough; reset the affected password too. And if you're not sure the site is clean, key rotation is a step in cleanup, not a substitute for actually finding and removing the malware.

It also doesn't affect server-level caching. If pages seem to serve a logged-in view after rotation when they shouldn't, or vice versa, clear the LiteSpeed Cache from wp-admin → LiteSpeed Cache → Toolbox → Purge All to rule out a stale cached page rather than an actual login issue.

If something breaks

If the site goes white-screen after an edit, that's almost always a syntax error in the block you pasted. Open wp-config.php again and check for a missing quote or semicolon before assuming anything worse happened. If you can't get it sorted or you're not confident editing the file directly, open a ticket through Support in the portal. It's real people, not a bot.

Common questions

Will regenerating keys delete my passwords or user accounts?

No, rotating keys leaves passwords and database data untouched. It only invalidates active login cookies and session tokens. If an attacker stole an account password, you still need to change that password separately.

Why did my site show a white screen after I edited wp-config.php?

You likely introduced a syntax error in the code block you pasted. Open wp-config.php and check for a missing quote, semicolon, or stray character. Restore your backup copy if you cannot find the typo.

Will rotating salts affect shoppers on my WooCommerce site?

Yes, logged-in customers get logged out immediately mid-session. Cookie-based carts can also be disrupted by the change. Schedule your key rotation for low-traffic hours or test the process on a staging copy first.

Should I keep the key rotation plugin active after changing salts?

No, deactivate or delete the plugin once the update finishes. The plugin modifies wp-config.php directly, so leaving it active consumes site resources without providing ongoing value.

CAN'T FIND IT?

Real humans answer fast.

Hosting with us? Open a ticket and a real person replies - no scripts, no upsells. Still choosing a host? The same team is included with every plan, from day one.