What the Flask docs tell you to run
Straight from the Flask configuration docs: python -c 'import secrets; print(secrets.token_hex())'. With no argument, token_hex() uses CPython's DEFAULT_ENTROPY of 32 bytes and prints them as 64 lowercase hex characters — that is exactly what the generator above produces, without needing Python installed. Flask signs your session cookie with this key (via itsdangerous), so a weak or shared value lets anyone forge a session; a full-entropy random one closes that off.
How long should a Flask secret key be?
Use a long, cryptographically random value. The default here is 32 random bytes encoded as hex, following the example in Flask’s configuration documentation. Load it from your environment or secret manager; do not hardcode it into the application repository.
Rotating it without logging everyone out
Since Flask 3.1 you can set SECRET_KEY_FALLBACKS to a list of old keys: Flask signs new sessions with SECRET_KEY and still accepts cookies signed with a fallback, so you can rotate without invalidating every live session at once. Keep the key in an environment variable, out of the repository, and use a distinct one per environment. This is the same 32-byte hex shape as a raw hex secret and a close cousin of Django's SECRET_KEY and Rails' secret_key_base — the differences are the length and the encoding, not the idea.