The supported way to automatically refresh WordPress authentication keys and salts is WP-CLI’s wp config shuffle-salts command. Run it from the WordPress installation, or point it at another configuration file with --config-file=<path>. Rotating the values invalidates existing login cookies, so every user must authenticate again.
What wp config shuffle-salts changes
The command refreshes the salts defined in wp-config.php and runs on WP-CLI’s before_wp_load hook, before WordPress loads. With no key names supplied, it uses the standard WordPress set documented in the WP-CLI command reference.
WordPress documents that changing these values invalidates existing cookies and forces all users to log in again. Plan the rotation during a maintenance window if a site has many active sessions.
Prepare before rotating the salts
- Ensure WP-CLI is installed and that your shell user can read and modify the WordPress configuration.
- Run the command from the correct WordPress installation, especially on servers hosting multiple sites.
- Back up
wp-config.phpthrough your normal, protected backup process. - Tell administrators and users to expect a fresh login after the change.
The keys are secrets. WordPress recommends strong, random values; do not copy the example values shown in sample configuration files. See the wp_salt() reference and the WordPress sample configuration for the documented guidance.
What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
#1 Best Overall
- POWERFUL SECURITY KEY: The Security Key C NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
- WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key C NFC secures 100 of your favorite accounts, including email, password managers, and more.
- FAST & CONVENIENT LOGIN: Plug in your Security Key C NFC via USB-C and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
- TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
- BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
Run the automatic rotation
Use the default configuration file
- Open a shell on the WordPress host.
- Change to the site’s installation directory.
- Run
wp config shuffle-salts. - Confirm that the command completes, then test the site and sign in again.
For example:
cd /var/www/example.com
wp config shuffle-salts
The command updates the configuration in place; protect the resulting file with the same permissions and access controls as before.
Target a configuration file elsewhere
If the configuration is not at the default root path and filename, specify it explicitly:
wp config shuffle-salts --config-file=/srv/example/wp-config.php
Rank #2
- POWERFUL SECURITY KEY: The YubiKey 5 NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
- WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5 NFC secures 100+ of your favorite accounts, including email, password managers, and more
- FAST & CONVENIENT LOGIN: Plug in your YubiKey 5 NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
- MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
- PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts
Use the exact path for the file belonging to the site you intend to change. The official command documentation describes the option and accepted key arguments.
The Tool Desk
Outbyte Driver Updater FREEFix the driver behind crashes, sound loss and screen glitchesFind Drivers →Outbyte PC Repair FREERepair Windows errors before they cause bigger problemsFix Now →Refresh selected keys
WP-CLI accepts one or more key names. Omitting key names refreshes the standard WordPress defaults; supplying names lets an administrator target particular entries when that is required by an established deployment procedure. Avoid partial rotations unless you understand why a subset is appropriate.
The eight standard WordPress keys and salts
| Constant | Role in the standard set |
|---|---|
AUTH_KEY |
Authentication key |
SECURE_AUTH_KEY |
Secure authentication key |
LOGGED_IN_KEY |
Logged-in cookie key |
NONCE_KEY |
Nonce key |
AUTH_SALT |
Authentication salt |
SECURE_AUTH_SALT |
Secure authentication salt |
LOGGED_IN_SALT |
Logged-in cookie salt |
NONCE_SALT |
Nonce salt |
These are the defaults identified by WP-CLI and listed in the WordPress sample configuration.
Rank #3
- POWERFUL SECURITY KEY: The YubiKey 5C NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
- WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5C NFC secures 100+ of your favorite accounts, including email, password managers, and more
- FAST & CONVENIENT LOGIN: Plug in your YubiKey 5C NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
- MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
- PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts
Schedule the command safely
A cron job or deployment workflow can serve as an operational wrapper around the documented command. The official documentation does not prescribe a universal rotation interval, so choose a cadence based on your incident-response, access-management and deployment policies.
A simple wrapper changes to the intended site directory before invoking WP-CLI:
Recommended Free Tools
cd /var/www/example.com && wp config shuffle-salts
- Use an account that can modify only the intended site where possible.
- Keep cron and deployment logs free of the secret values from
wp-config.php. - Coordinate rotations with monitoring and support teams because all current sessions will expire.
- Test the workflow on a staging copy before using it in production.
WP-CLI or manual editing?
| Approach | Best fit | Operational difference |
|---|---|---|
| WP-CLI | Repeatable maintenance, scripts and deployments | Uses the supported shuffle-salts command and can target an explicit configuration path. |
Manual wp-config.php edit |
One-time change when shell access is unavailable | Requires safely generating and inserting every replacement value yourself. |
Both approaches change the configured secrets, so both invalidate existing authentication cookies and require users to sign in again. For repeatable automation, WP-CLI avoids manually assembling the values.
Rank #4
- POWERFUL SECURITY KEY: The Security Key NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
- WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key NFC secures 100 of your favorite accounts, including email, password managers, and more.
- FAST & CONVENIENT LOGIN: Plug in your Security Key NFC via USB-A and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
- TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
- BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
Troubleshoot a rotation
The command cannot find the file
Verify that you are in the correct WordPress installation. If the file is stored elsewhere, rerun the command with --config-file=<path> and check that the path points to the intended site.
The command reports a permissions error
The account running WP-CLI must be able to write the configuration file. Use the site’s normal deployment or maintenance account rather than weakening file permissions, and restore the original ownership and mode after any approved change.
Users are unexpectedly logged out
That is the expected result of a successful key rotation: existing cookies no longer validate. Have users sign in again and verify that new sessions work.
Free tools Windows power users keep installed
One-click scans. No signup required.
The site behaves incorrectly after the change
Check that only the intended wp-config.php was modified, review your backup and deployment logs, and restore the pre-change file if necessary. Then investigate the site’s configuration before retrying.
Quick Recap
Security practices for WordPress salts
- Use unique, randomly generated values rather than examples from documentation.
- Never publish or paste the contents of
wp-config.phpinto tickets, scripts or public repositories. - Restrict read access to the configuration file and protect backups containing it.
- Document the expected login disruption for each automated rotation.
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

