Generate a NextAuth or Auth.js secret
The default is 32 random bytes encoded as standard base64: 44 characters, including one padding character. This matches the CLI's output format, with a fresh random value on every generation. Select your Auth.js version above to copy the correct environment-variable line.
npx auth secret
For the OpenSSL alternative documented by Auth.js, run openssl rand -base64 33. The 33-byte option above produces that format: 44 base64 characters without padding. The defaults contain 256 and 264 random bits respectively. See the Auth.js deployment guide.
AUTH_SECRET or NEXTAUTH_SECRET?
| Version | Environment variable | Where it belongs |
|---|---|---|
| Auth.js v5 | AUTH_SECRET | Server environment |
| NextAuth v4 | NEXTAUTH_SECRET | Server environment |
Keep the variable out of client-side bundles: do not add a NEXT_PUBLIC_ prefix. Set it in the hosting environment for deployed applications. A value in a local .env file does not automatically configure production.
Fix MissingSecret or NO_SECRET
- Generate a fresh value and use the variable name for your installed major version.
- Set it in the environment of the running server process, including the appropriate preview or production deployment.
- Restart or redeploy so the process receives the value. Check for an empty variable or a conflicting explicit
secretoption without printing the secret in logs.
See Auth.js MissingSecret and NextAuth v4 secret configuration. Keep a stable secret between ordinary deployments to avoid unnecessary session invalidation.
How the value is used and rotated
Auth.js derives cryptographic keys from the secret; its default JWT session strategy uses encrypted tokens. This is a different configuration from a standalone HS256 signing key.
Auth.js supports an array in its secret configuration for rotation. Put the new value first and retain the old value during the transition, following your integration's documentation. Do not put a comma-separated list into one AUTH_SECRET variable and assume it becomes an array. Removing old keys can invalidate existing sessions. See the Auth.js secret API.
For other stacks, use the framework secret comparison to select the correct format and local command.