RevealTheme logo

WordPress密钥生成器

为你的wp-config.php生成全新的认证密钥和salt:使用crypto.getRandomValues()在你的浏览器中运行。

define('AUTH_KEY', '9U{,Jns=_M,*)(XDQvs}C34jH53^o&*zf[em1HqqlTt@m29Q8ZiJlDVPlln4tM1U');
define('SECURE_AUTH_KEY', 'ujXc}dT$Qxx7>L*Vw@B_ThL5ZuDG?I9#v$&I.br<?F>LpR?dVm5pBQ$vTy&l>t$D');
define('LOGGED_IN_KEY', 'U>.tZ9)>.J33m%=1Z8S{!I{15V6nWa9O)M=7DmK-?y)<?+1ZS&>2%tS+EE+{4nPH');
define('NONCE_KEY', '>D}3Xs_z0dGMU?[uJD8E6lIvJt_9C}f{Bd[w?s1<q4EoA[0e.BAHKg?dVx!PSex(');
define('AUTH_SALT', 'ISkp3oWn{meXWrG0>E@6T#,.3}1G5Z@!WNF*0R<VKzF72]aOJ!Wz$SGB%$-@%UqG');
define('SECURE_AUTH_SALT', 'C{}d5lELA#>BVuC[a)IIvLdDwUey1Zcw[X7[b,%51OUF,[+xoA9X[z%M.7)cm,KI');
define('LOGGED_IN_SALT', 'w4Ss6tvepK?6tBajKn5=Vo,yb?vZYm_z>8Ra24AB%z4(Q3&pzeL[9F9?<8!63s@<');
define('NONCE_SALT', 'mgVXU07k-T<Uj0Qh(0rZgWrdYRw3Fb<N1U81,DQ91#=g-P5LVa<z&[[+?vdF6&kK');

如何使用本工具

  1. 1

    点击“重新生成”以产生全新的盐值。

  2. 2

    将全部内容复制到剪贴板。

  3. 3

    粘贴并覆盖wp-config.php中现有的AUTH_KEY代码块。

  4. 4

    所有用户都将被登出(Cookie失效)——这是预期的行为。

什么是WordPress密钥生成器?

WordPress在wp-config.php中使用八个常量来加密cookie并为密码哈希加salt。每一个都必须是一段长的随机字符串。官方端点api.wordpress.org/secret-key可以提供这些密钥,但本工具使用你浏览器的加密随机数生成器在本地生成它们,因此它们绝不会经过网络传输。

常见使用场景

  • Setting up a brand-new WordPress install and replacing the placeholder 'put your unique phrase here' lines in wp-config.php.

  • Rotating keys after a suspected compromise to force-log-out every session and invalidate stolen auth cookies.

  • Off-boarding an admin or contractor and wanting to kill any sessions they may still hold.

  • Periodic security hygiene on a production site, swapping in fresh salts every several months.

  • Generating salts on an air-gapped or restricted machine where you would rather not call an external endpoint.

  • Cloning a site to staging and giving the copy its own distinct keys so the two environments do not share cookie signatures.

常见问题

我应该在什么时候轮换salt?
在网站遭到任何入侵之后、删除被入侵的管理员用户时,或作为定期的安全实践(每6至12个月一次)。
为什么要在本地生成?
尽管api.wordpress.org值得信赖,但在本地生成意味着这些机密材料在网络上的暴露为零。

相关工具