Web tool · FREE · NO ACCOUNT
WordPress Password Hash and Salt Generator
Generate a password hash in the default WordPress 6.8+ format for manual recovery, or create a complete set of authentication keys and salts for wp-config.php. Both operations run locally. Your password and generated secrets are not submitted to our inspection API.
Uses the WordPress 6.8+ default password format. Passwords and hashes stay in this browser and are never sent to our API. Prefer the normal password reset flow; make a database backup before manual recovery.
Generate fresh wp-config.php keys and salts
Replacing keys and salts signs out existing sessions. Replace the eight existing definitions rather than adding duplicates.
How to use password hashes and salts
- Try WordPress’s normal password reset flow before manual database recovery.
- For a compatible WordPress installation, enter a new password and generate its hash.
- Copy the output and follow your host’s recovery procedure after making a database backup.
- For keys and salts, replace the eight existing wp-config.php definitions. This signs out existing sessions.
Questions and limits
Which password format does this generate?
It generates the default WordPress 6.8+ $wp$2y$ format using SHA-384 HMAC pre-hashing and bcrypt. Older WordPress releases and custom authentication implementations may require another format.
Are passwords sent to a server?
No. Password hashing and salt generation happen in your browser. Do not share the output, include it in support tickets, or save it to a public repository.
Does generating a hash change my account?
No. The tool only creates text. It does not connect to your database or WordPress installation.
What happens when I replace WordPress salts?
Existing authentication cookies become invalid, so users need to sign in again. Replace existing definitions rather than defining the same constants twice.