Generate APP_SECRET with PHP
The default above encodes 16 random bytes as 32 hexadecimal characters. To generate the same format on your own machine, run:
php -r 'echo bin2hex(random_bytes(16)), PHP_EOL;'
Paste the result into your application's APP_SECRET environment variable. Use a distinct value for each application and environment.
Where to configure it
Symfony commonly connects framework.secret to APP_SECRET:
# config/packages/framework.yaml
framework:
secret: '%env(APP_SECRET)%'
For local development, set your generated value in an untracked .env.local override. In production, use the hosting environment or Symfony's secrets vault. The FrameworkBundle 7.2 recipe leaves the base APP_SECRET empty and generates a development value through its dotenv configuration; do not assume a development value also exists in production.
Fix a missing or empty secret
Check the environment used by the running PHP process, the variable name and the framework configuration. After changing deployment configuration, rebuild the Symfony cache and restart the relevant application workers. Avoid pasting configuration dumps containing secrets into logs or support tickets.
APP_SECRET and vault keys have different jobs
APP_SECRET is an application secret; it is not the key pair produced by secrets:generate-keys to protect Symfony's vault. Current Symfony can derive kernel.secret from SYMFONY_DECRYPTION_SECRET when APP_SECRET is absent. Follow the configuration supported by your installed version.
Changing the application secret invalidates signed URIs and Remember Me cookies. Plan the change instead of regenerating it on every deployment. See Symfony's secret configuration and secrets vault documentation, or compare secret formats across frameworks.