Every secret Strapi needs, in one block
A Strapi project refuses to boot without a set of secrets in its .env, and the generator above produces all six at once as a paste-ready block: APP_KEYS, API_TOKEN_SALT, ADMIN_JWT_SECRET, JWT_SECRET, TRANSFER_TOKEN_SALT and ENCRYPTION_KEY. That last one is easy to forget — many walkthroughs list only five — and a missing ENCRYPTION_KEY breaks encrypted fields on newer Strapi. If you have hit Middleware "strapi::session": App keys are required, that is the APP_KEYS line this page fills in.
APP_KEYS is four keys, not one
APP_KEYS is a comma-separated list — create-strapi-app generates exactly four — and Strapi rotates the session-signing key across them. The scaffolder makes each value 16 random bytes in standard base64 (a 24-character string ending in ==), and every field uses that same shape. Configuration can change between Strapi versions. Check each variable against the documentation for your installed version and preserve existing secrets when editing an established project.
Why the JWT secrets here are longer than the default
One honest deviation, and you can turn it off. ADMIN_JWT_SECRET and JWT_SECRET sign HS256 JSON Web Tokens, and RFC 7518 §3.2 requires an HS256 key of at least 256 bits — which is 32 bytes, not the 16 the Strapi CLI ships. So this generator emits 32 bytes for those two secrets by default, and 16 for the four that do not sign tokens, matching the CLI everywhere it matters. If you would rather match the output format of create-strapi-app, tick "match create-strapi-app exactly" and every field drops to 16 bytes. Either way, keep the block in .env, out of the repository, and use a fresh one per environment.