Strapi APP_KEYS Generator

Every Strapi .env secret at once — the full six-field block, copy-ready.

Copy the result before closing this tab.

Generate separate random values for Strapi APP_KEYS, API_TOKEN_SALT, ADMIN_JWT_SECRET and JWT_SECRET. These values have different jobs. Store them as environment variables and follow the configuration for your Strapi version.

Every secret Strapi needs, in one block

A Strapi project refuses to boot without a set of secrets in its .env, and the generator above produces all six at once as a paste-ready block: APP_KEYS, API_TOKEN_SALT, ADMIN_JWT_SECRET, JWT_SECRET, TRANSFER_TOKEN_SALT and ENCRYPTION_KEY. That last one is easy to forget — many walkthroughs list only five — and a missing ENCRYPTION_KEY breaks encrypted fields on newer Strapi. If you have hit Middleware "strapi::session": App keys are required, that is the APP_KEYS line this page fills in.

APP_KEYS is four keys, not one

APP_KEYS is a comma-separated list — create-strapi-app generates exactly four — and Strapi rotates the session-signing key across them. The scaffolder makes each value 16 random bytes in standard base64 (a 24-character string ending in ==), and every field uses that same shape. Configuration can change between Strapi versions. Check each variable against the documentation for your installed version and preserve existing secrets when editing an established project.

Why the JWT secrets here are longer than the default

One honest deviation, and you can turn it off. ADMIN_JWT_SECRET and JWT_SECRET sign HS256 JSON Web Tokens, and RFC 7518 §3.2 requires an HS256 key of at least 256 bits — which is 32 bytes, not the 16 the Strapi CLI ships. So this generator emits 32 bytes for those two secrets by default, and 16 for the four that do not sign tokens, matching the CLI everywhere it matters. If you would rather match the output format of create-strapi-app, tick "match create-strapi-app exactly" and every field drops to 16 bytes. Either way, keep the block in .env, out of the repository, and use a fresh one per environment.

FAQ

Middleware "strapi::session": App keys are required — how do I fix it?

Strapi refuses to boot without APP_KEYS in your .env. Generate the full block above and paste it in — APP_KEYS is the line this error is about, but the same run gives you every other secret Strapi needs too.

What secrets go in a Strapi .env?

Six: APP_KEYS, API_TOKEN_SALT, ADMIN_JWT_SECRET, JWT_SECRET, TRANSFER_TOKEN_SALT and ENCRYPTION_KEY. Older guides list only five and omit ENCRYPTION_KEY, which newer Strapi needs for encrypted fields — this generator includes all six.

How many APP_KEYS does Strapi need?

APP_KEYS is a comma-separated list and create-strapi-app generates exactly four. Strapi rotates the session-signing key across them. Each is 16 random bytes in standard base64 — a 24-character value ending in ==.

Why are the JWT secrets here longer than create-strapi-app's?

Because ADMIN_JWT_SECRET and JWT_SECRET sign HS256 tokens, and RFC 7518 requires an HS256 key of at least 32 bytes — the Strapi CLI ships 16. This generator emits 32 bytes for those two by default and 16 for the rest; tick "match create-strapi-app exactly" to reproduce the CLI's output format.

How generation works

About & privacy

Generated on your device

Web Crypto provides the randomness. Generation works offline after the page has loaded.

No tracking or saved values

No analytics scripts, accounts, cookies or local storage. Values stay in this tab until you copy them.

Browser and device security

A compromised browser or device can expose values. For production private keys, use a trusted local tool.

Other generators

All generators ↗