NextAuth / Auth.js: [next-auth][error][NO_SECRET] Please define a `secret` in production / MissingSecret
Auth.js needs a secret (NEXTAUTH_SECRET / AUTH_SECRET) in production to sign and encrypt tokens/cookies.
Seen on:
REST API
Meaning
Locally it may use a default, but production builds fail or sessions break without it. Changing the secret invalidates existing sessions (JWEDecryptionFailed).
Common causes
- NEXTAUTH_SECRET/AUTH_SECRET not set in the hosting environment
- Variable named for the wrong version (v4 vs v5)
- Secret changed between deployments/instances
⚡ Quick fix
- Generate one (npx auth secret / openssl rand -base64 32) and set it in env
- Use AUTH_SECRET for Auth.js v5
- Keep the same secret across instances
Detailed fix by platform
Shell
- bash
npx auth secret # or openssl rand -base64 32
How to diagnose
- Env — Variable present at runtime?
- Version — next-auth v4 or v5?
🔧 Still not fixed?
Many errors look alike. If the steps above didn’t solve it, one of these is probably what you’re facing:
Similar errors
Most viewed in Authentication
Other ways to find it
🧠 Still stuck? Analyze your error
Paste the full message, response headers or stack trace — we'll detect the platform and point to the most likely cause.
Was this page helpful?
Report a correction or suggest an improvement
Last updated 7 Oct 2026