NextAuth Secret Generator — AUTH_SECRET for Auth.js

A random secret for Auth.js v5 or NextAuth v4, ready for your environment.

Copy the result before closing this tab.

Generate a 32-byte secret in standard base64 for Auth.js or NextAuth. Store it as AUTH_SECRET (NEXTAUTH_SECRET for older NextAuth configurations). Rotating it can invalidate existing sessions.

Generate a NextAuth or Auth.js secret

The default is 32 random bytes encoded as standard base64: 44 characters, including one padding character. This matches the CLI's output format, with a fresh random value on every generation. Select your Auth.js version above to copy the correct environment-variable line.

npx auth secret

For the OpenSSL alternative documented by Auth.js, run openssl rand -base64 33. The 33-byte option above produces that format: 44 base64 characters without padding. The defaults contain 256 and 264 random bits respectively. See the Auth.js deployment guide.

AUTH_SECRET or NEXTAUTH_SECRET?

Choose the variable for your version
VersionEnvironment variableWhere it belongs
Auth.js v5AUTH_SECRETServer environment
NextAuth v4NEXTAUTH_SECRETServer environment

Keep the variable out of client-side bundles: do not add a NEXT_PUBLIC_ prefix. Set it in the hosting environment for deployed applications. A value in a local .env file does not automatically configure production.

Fix MissingSecret or NO_SECRET

  1. Generate a fresh value and use the variable name for your installed major version.
  2. Set it in the environment of the running server process, including the appropriate preview or production deployment.
  3. Restart or redeploy so the process receives the value. Check for an empty variable or a conflicting explicit secret option without printing the secret in logs.

See Auth.js MissingSecret and NextAuth v4 secret configuration. Keep a stable secret between ordinary deployments to avoid unnecessary session invalidation.

How the value is used and rotated

Auth.js derives cryptographic keys from the secret; its default JWT session strategy uses encrypted tokens. This is a different configuration from a standalone HS256 signing key.

Auth.js supports an array in its secret configuration for rotation. Put the new value first and retain the old value during the transition, following your integration's documentation. Do not put a comma-separated list into one AUTH_SECRET variable and assume it becomes an array. Removing old keys can invalidate existing sessions. See the Auth.js secret API.

For other stacks, use the framework secret comparison to select the correct format and local command.

FAQ

How do I generate a NextAuth secret?

Run npx auth secret or generate a value above. The default format is 32 random bytes encoded as 44 standard-base64 characters. Choose NEXTAUTH_SECRET for v4 or AUTH_SECRET for Auth.js v5.

How do I fix MissingSecret?

Set the secret in the running server's environment, using the name for your major version, then restart or redeploy. Check for an empty variable or a conflicting explicit secret option without logging its value.

Is AUTH_SECRET an HS256 signing key?

It is configuration for Auth.js key derivation, including encrypted tokens in the default JWT session strategy. A standalone JWT HMAC signing key has different requirements.

Why does the value end in an equals sign?

Standard base64 of 32 bytes includes one padding character. Keep it. The 33-byte option produces 44 characters without padding.

Should I generate a new secret on every deployment?

No. Keep a stable secret for an application and rotate deliberately. Replacing it without a transition can invalidate existing sessions.

How generation works

About & privacy

Generated on your device

Web Crypto provides the randomness. Generation works offline after the page has loaded.

No tracking or saved values

No analytics scripts, accounts, cookies or local storage. Values stay in this tab until you copy them.

Browser and device security

A compromised browser or device can expose values. For production private keys, use a trusted local tool.

Other generators

All generators ↗