Symfony APP_SECRET Generator

A random hexadecimal secret for Symfony's framework configuration.

Copy the result before closing this tab.

Generate a Symfony APP_SECRET as 32 hex characters from 16 random bytes. Set it in the environment read by framework.secret; keep production secrets separate from development values and plan rotation of signed cookies and URIs.

Generate APP_SECRET with PHP

The default above encodes 16 random bytes as 32 hexadecimal characters. To generate the same format on your own machine, run:

php -r 'echo bin2hex(random_bytes(16)), PHP_EOL;'

Paste the result into your application's APP_SECRET environment variable. Use a distinct value for each application and environment.

Where to configure it

Symfony commonly connects framework.secret to APP_SECRET:

# config/packages/framework.yaml
framework:
    secret: '%env(APP_SECRET)%'

For local development, set your generated value in an untracked .env.local override. In production, use the hosting environment or Symfony's secrets vault. The FrameworkBundle 7.2 recipe leaves the base APP_SECRET empty and generates a development value through its dotenv configuration; do not assume a development value also exists in production.

Fix a missing or empty secret

Check the environment used by the running PHP process, the variable name and the framework configuration. After changing deployment configuration, rebuild the Symfony cache and restart the relevant application workers. Avoid pasting configuration dumps containing secrets into logs or support tickets.

APP_SECRET and vault keys have different jobs

APP_SECRET is an application secret; it is not the key pair produced by secrets:generate-keys to protect Symfony's vault. Current Symfony can derive kernel.secret from SYMFONY_DECRYPTION_SECRET when APP_SECRET is absent. Follow the configuration supported by your installed version.

Changing the application secret invalidates signed URIs and Remember Me cookies. Plan the change instead of regenerating it on every deployment. See Symfony's secret configuration and secrets vault documentation, or compare secret formats across frameworks.

How generation works

About & privacy

Generated on your device

Web Crypto provides the randomness. Generation works offline after the page has loaded.

No tracking or saved values

No analytics scripts, accounts, cookies or local storage. Values stay in this tab until you copy them.

Browser and device security

A compromised browser or device can expose values. For production private keys, use a trusted local tool.

Other generators

All generators ↗