Web tool · FREE · NO ACCOUNT

WordPress Password Hash and Salt Generator

Generate a password hash in the default WordPress 6.8+ format for manual recovery, or create a complete set of authentication keys and salts for wp-config.php. Both operations run locally. Your password and generated secrets are not submitted to our inspection API.

Uses the WordPress 6.8+ default password format. Passwords and hashes stay in this browser and are never sent to our API. Prefer the normal password reset flow; make a database backup before manual recovery.

Generate fresh wp-config.php keys and salts

Replacing keys and salts signs out existing sessions. Replace the eight existing definitions rather than adding duplicates.

How to use password hashes and salts

  1. Try WordPress’s normal password reset flow before manual database recovery.
  2. For a compatible WordPress installation, enter a new password and generate its hash.
  3. Copy the output and follow your host’s recovery procedure after making a database backup.
  4. For keys and salts, replace the eight existing wp-config.php definitions. This signs out existing sessions.

Questions and limits

Which password format does this generate?

It generates the default WordPress 6.8+ $wp$2y$ format using SHA-384 HMAC pre-hashing and bcrypt. Older WordPress releases and custom authentication implementations may require another format.

Are passwords sent to a server?

No. Password hashing and salt generation happen in your browser. Do not share the output, include it in support tickets, or save it to a public repository.

Does generating a hash change my account?

No. The tool only creates text. It does not connect to your database or WordPress installation.

What happens when I replace WordPress salts?

Existing authentication cookies become invalid, so users need to sign in again. Replace existing definitions rather than defining the same constants twice.