diff --git a/apps/examples/nextjs/.env.local.example b/apps/examples/nextjs/.env.local.example index b754b2f5a7..18912ea935 100644 --- a/apps/examples/nextjs/.env.local.example +++ b/apps/examples/nextjs/.env.local.example @@ -1,4 +1,4 @@ -AUTH_SECRET= # `npx auth secret` or `openssl rand -hex 32` +AUTH_SECRET= # `openssl rand -base64 33` AUTH_AUTH0_ID= AUTH_AUTH0_SECRET= diff --git a/docs/next.config.js b/docs/next.config.js index 9a8de256c6..f0d1f1e26e 100644 --- a/docs/next.config.js +++ b/docs/next.config.js @@ -60,7 +60,7 @@ export default withNextra({ { source: "/:path(.*)", has: [{ type: "host", value: "cli.authjs.dev" }], - destination: "https://github.com/nextauthjs/cli", + destination: "https://authjs.dev/getting-started/installation", permanent: true, }, { diff --git a/docs/pages/getting-started/deployment.mdx b/docs/pages/getting-started/deployment.mdx index 32e673900b..d73f023814 100644 --- a/docs/pages/getting-started/deployment.mdx +++ b/docs/pages/getting-started/deployment.mdx @@ -13,8 +13,8 @@ import { Accordion, Accordions } from "@/components/Accordion" Auth.js libraries require you to set an `AUTH_SECRET` environment variable. This is used to encrypt cookies and tokens. It should be a cryptographically secure random string of at least 32 characters: -```bash npm2yarn -npm exec auth secret +```bash +openssl rand -base64 33 ``` If you are using an [OAuth Provider](/concepts/oauth), your provider will provide you with a **Client ID** and **Client Secret** that you will need to set as environment variables as well (in the case of an OIDC provider, like Auth0, a third `issuer` value might be also required, refer to the provider's specific documentation). @@ -36,7 +36,7 @@ For more information, check out our [environment variables](/guides/environment- ### `AUTH_SECRET` -This is the only strictly required environment variable. It is the secret used to encode the JWT and encrypt things in transit. As mentioned above, we recommend at least a 32 character random string. This can be generated via the CLI with `npm exec auth secret` or via openssl with `openssl rand -base64 33`. +This is the only strictly required environment variable. It is the secret used to encode the JWT and encrypt things in transit. As mentioned above, we recommend at least a 32 character random string. This can be generated with `openssl rand -base64 33`. ### `AUTH_TRUST_HOST` diff --git a/docs/pages/getting-started/installation.mdx b/docs/pages/getting-started/installation.mdx index 0cf9462470..88f1ad9d37 100644 --- a/docs/pages/getting-started/installation.mdx +++ b/docs/pages/getting-started/installation.mdx @@ -44,13 +44,13 @@ Start by installing the appropriate package for your framework. ### Setup Environment The only environment variable that is mandatory is the `AUTH_SECRET`. This is a random value used by the library to encrypt tokens and email -verification hashes. (See [Deployment](/getting-started/deployment) to learn more). You can generate one via the official [Auth.js CLI](https://cli.authjs.dev) running: +verification hashes. (See [Deployment](/getting-started/deployment) to learn more). You can generate one with OpenSSL: ```bash -npx auth secret +openssl rand -base64 33 ``` -This will also add it to your `.env` file, respecting the framework conventions (eg.: Next.js' `.env.local`). +Add the generated value to your framework's environment file as `AUTH_SECRET` (eg.: Next.js' `.env.local`). ### Configure diff --git a/docs/pages/guides/environment-variables.mdx b/docs/pages/guides/environment-variables.mdx index d30d0604bb..f2bdbd6d33 100644 --- a/docs/pages/guides/environment-variables.mdx +++ b/docs/pages/guides/environment-variables.mdx @@ -36,10 +36,10 @@ AUTH_SECRET="This is an example" -`AUTH_SECRET` is a random token used by the library to encrypt tokens and email verification hashes, and it's mandatory to keep things secure (See [Deployment](/getting-started/deployment) to learn more). You can use the CLI to generate an auth secret: +`AUTH_SECRET` is a random token used by the library to encrypt tokens and email verification hashes, and it's mandatory to keep things secure (See [Deployment](/getting-started/deployment) to learn more). You can use OpenSSL to generate an auth secret: -```bash npm2yarn -npm exec auth secret +```bash +openssl rand -base64 33 ``` ## Environment Variable Inference diff --git a/packages/core/src/errors.ts b/packages/core/src/errors.ts index 051fa78522..610da3a065 100644 --- a/packages/core/src/errors.ts +++ b/packages/core/src/errors.ts @@ -307,7 +307,7 @@ export class MissingAuthorize extends AuthError { * * * :::tip - * To generate a random string, you can use the Auth.js CLI: `npx auth secret` + * To generate a random string, you can use `openssl rand -base64 33`. * ::: * @noInheritDoc */ diff --git a/packages/core/src/index.ts b/packages/core/src/index.ts index aef7a3b6ca..bee18ee50e 100644 --- a/packages/core/src/index.ts +++ b/packages/core/src/index.ts @@ -225,7 +225,7 @@ export interface AuthConfig { /** * A random string used to hash tokens, sign cookies and generate cryptographic keys. * - * To generate a random string, you can use the Auth.js CLI: `npx auth secret` + * To generate a random string, you can use `openssl rand -base64 33`. * * @note * You can also pass an array of secrets, in which case the first secret that successfully