secretOrPrivateKey must have a value 🔐 Authentication

Error: secretOrPrivateKey must have a value (jsonwebtoken sign)

jwt.sign() got an empty secret — the environment variable holding the JWT secret isn’t loaded.

Seen on: REST API

Meaning

dotenv not loaded before use, wrong variable name, missing variable in production/CI, or reading the key file failed silently.

Common causes

  • process.env.JWT_SECRET undefined (dotenv not loaded or wrong name)
  • Variable missing in deployment environment
  • Key file path wrong

⚡ Quick fix

  1. Load dotenv at the very top of the entry file
  2. Validate required env vars at startup
  3. Check the deployment’s environment settings

Detailed fix by platform

JavaScript

  1. javascript
    import "dotenv/config";
    const secret = process.env.JWT_SECRET;
    if (!secret) throw new Error("JWT_SECRET is not set");

How to diagnose

  1. Env — Variable present at runtime?
  2. Load order — dotenv before imports using it?

🔧 Still not fixed?

Many errors look alike. If the steps above didn’t solve it, one of these is probably what you’re facing:

🧠 Still stuck? Analyze your error

Paste the full message, response headers or stack trace — we'll detect the platform and point to the most likely cause.