↑ ↓ select, Enter open, Esc close

Regenerate WordPress security keys (salts)

Caution: This command changes the system. Understand what it does before you run it.

Adjust the values, the command updates live
user@server
wp config shuffle-salts --path=/var/www/vhosts/example.com/httpdocs

Writes new values for AUTH_KEY, SECURE_AUTH_KEY and the other keys to wp-config.php. This invalidates all login cookies, so everyone has to log in again. A mandatory step after a breach, together with new passwords.

Note: wp-config.php must be writable by the user running the command. The salts are fetched from api.wordpress.org.

Also searched as

  • log out all users wordpress
  • invalidate sessions after hack
  • change salts in wp-config

Related one-liners

All in WP-CLI

Read first, then run.

The commands on myline.de act directly on servers, files and databases. A wrong path or placeholder can delete data irreversibly or make a server unreachable.

  • All commands are provided without warranty and are not tested on every system.
  • Understand what a command does before running it, and check every placeholder.
  • Make a backup first and, if possible, try it on a test system.
  • You run commands at your own risk. Liability for damages is excluded to the extent permitted by law.