Error: secretOrPrivateKey must have a value (jsonwebtoken sign)
jwt.sign() got an empty secret — the environment variable holding the JWT secret isn’t loaded.
Seen on:
REST API
Meaning
dotenv not loaded before use, wrong variable name, missing variable in production/CI, or reading the key file failed silently.
Common causes
- process.env.JWT_SECRET undefined (dotenv not loaded or wrong name)
- Variable missing in deployment environment
- Key file path wrong
⚡ Quick fix
- Load dotenv at the very top of the entry file
- Validate required env vars at startup
- Check the deployment’s environment settings
Detailed fix by platform
JavaScript
- javascript
import "dotenv/config"; const secret = process.env.JWT_SECRET; if (!secret) throw new Error("JWT_SECRET is not set");
How to diagnose
- Env — Variable present at runtime?
- Load order — dotenv before imports using it?
🔧 Still not fixed?
Many errors look alike. If the steps above didn’t solve it, one of these is probably what you’re facing:
Similar errors
Most viewed in Authentication
Other ways to find it
🧠 Still stuck? Analyze your error
Paste the full message, response headers or stack trace — we'll detect the platform and point to the most likely cause.
Was this page helpful?
Report a correction or suggest an improvement
Last updated 7 Oct 2026