What these are
WordPress uses eight secret values — four keys and four salts — to hash the cookies that keep you logged in and to sign nonces. Long, random values make those cookies far harder to forge. They live in wp-config.php as define() constants.
How to use
Generate a set, copy it, and replace the existing eight define() lines in wp-config.php (between the comment markers WordPress ships with). Save, and you're done. If those lines are still the default placeholders, replacing them is an important hardening step.
Changing them logs everyone out
Because the salts hash session cookies, rotating them invalidates every active session — all users must log in again. That side effect makes this a handy “log everyone out now” switch after a suspected compromise or a shared-password change.
Privacy
Keys are generated locally using crypto.getRandomValues. Nothing is transmitted, so the secrets never leave your machine — unlike pasting into a random web service. Related: reset a locked account with the WordPress Password Hash tool.