Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
2 changes: 1 addition & 1 deletion apps/examples/nextjs/.env.local.example
Original file line number Diff line number Diff line change
@@ -1,4 +1,4 @@
AUTH_SECRET= # `npx auth secret` or `openssl rand -hex 32`
AUTH_SECRET= # `openssl rand -base64 33`

AUTH_AUTH0_ID=
AUTH_AUTH0_SECRET=
Expand Down
2 changes: 1 addition & 1 deletion docs/next.config.js
Original file line number Diff line number Diff line change
Expand Up @@ -60,7 +60,7 @@ export default withNextra({
{
source: "/:path(.*)",
has: [{ type: "host", value: "cli.authjs.dev" }],
destination: "https://github.com/nextauthjs/cli",
destination: "https://authjs.dev/getting-started/installation",
permanent: true,
},
{
Expand Down
6 changes: 3 additions & 3 deletions docs/pages/getting-started/deployment.mdx
Original file line number Diff line number Diff line change
Expand Up @@ -13,8 +13,8 @@ import { Accordion, Accordions } from "@/components/Accordion"

Auth.js libraries require you to set an `AUTH_SECRET` environment variable. This is used to encrypt cookies and tokens. It should be a cryptographically secure random string of at least 32 characters:

```bash npm2yarn
npm exec auth secret
```bash
openssl rand -base64 33
```

If you are using an [OAuth Provider](/concepts/oauth), your provider will provide you with a **Client ID** and **Client Secret** that you will need to set as environment variables as well (in the case of an OIDC provider, like Auth0, a third `issuer` value might be also required, refer to the provider's specific documentation).
Expand All @@ -36,7 +36,7 @@ For more information, check out our [environment variables](/guides/environment-

### `AUTH_SECRET`

This is the only strictly required environment variable. It is the secret used to encode the JWT and encrypt things in transit. As mentioned above, we recommend at least a 32 character random string. This can be generated via the CLI with `npm exec auth secret` or via openssl with `openssl rand -base64 33`.
This is the only strictly required environment variable. It is the secret used to encode the JWT and encrypt things in transit. As mentioned above, we recommend at least a 32 character random string. This can be generated with `openssl rand -base64 33`.

### `AUTH_TRUST_HOST`

Expand Down
6 changes: 3 additions & 3 deletions docs/pages/getting-started/installation.mdx
Original file line number Diff line number Diff line change
Expand Up @@ -44,13 +44,13 @@ Start by installing the appropriate package for your framework.
### Setup Environment

The only environment variable that is mandatory is the `AUTH_SECRET`. This is a random value used by the library to encrypt tokens and email
verification hashes. (See [Deployment](/getting-started/deployment) to learn more). You can generate one via the official [Auth.js CLI](https://cli.authjs.dev) running:
verification hashes. (See [Deployment](/getting-started/deployment) to learn more). You can generate one with OpenSSL:

```bash
npx auth secret
openssl rand -base64 33
```

This will also add it to your `.env` file, respecting the framework conventions (eg.: Next.js' `.env.local`).
Add the generated value to your framework's environment file as `AUTH_SECRET` (eg.: Next.js' `.env.local`).

### Configure

Expand Down
6 changes: 3 additions & 3 deletions docs/pages/guides/environment-variables.mdx
Original file line number Diff line number Diff line change
Expand Up @@ -36,10 +36,10 @@ AUTH_SECRET="This is an example"
</Code.Express>
</Code>

`AUTH_SECRET` is a random token used by the library to encrypt tokens and email verification hashes, and it's mandatory to keep things secure (See [Deployment](/getting-started/deployment) to learn more). You can use the CLI to generate an auth secret:
`AUTH_SECRET` is a random token used by the library to encrypt tokens and email verification hashes, and it's mandatory to keep things secure (See [Deployment](/getting-started/deployment) to learn more). You can use OpenSSL to generate an auth secret:

```bash npm2yarn
npm exec auth secret
```bash
openssl rand -base64 33
```

## Environment Variable Inference
Expand Down
2 changes: 1 addition & 1 deletion packages/core/src/errors.ts
Original file line number Diff line number Diff line change
Expand Up @@ -307,7 +307,7 @@ export class MissingAuthorize extends AuthError {
*
*
* :::tip
* To generate a random string, you can use the Auth.js CLI: `npx auth secret`
* To generate a random string, you can use `openssl rand -base64 33`.
* :::
* @noInheritDoc
*/
Expand Down
2 changes: 1 addition & 1 deletion packages/core/src/index.ts
Original file line number Diff line number Diff line change
Expand Up @@ -225,7 +225,7 @@ export interface AuthConfig {
/**
* A random string used to hash tokens, sign cookies and generate cryptographic keys.
*
* To generate a random string, you can use the Auth.js CLI: `npx auth secret`
* To generate a random string, you can use `openssl rand -base64 33`.
*
* @note
* You can also pass an array of secrets, in which case the first secret that successfully
Expand Down
Loading