NextAuth / Auth.js: [next-auth][error][NO_SECRET] Please define a `secret` in production / MissingSecret

Auth.js needs a secret (NEXTAUTH_SECRET / AUTH_SECRET) in production to sign and encrypt tokens/cookies.

Seen on: REST API

Meaning

Locally it may use a default, but production builds fail or sessions break without it. Changing the secret invalidates existing sessions (JWEDecryptionFailed).

Common causes

  • NEXTAUTH_SECRET/AUTH_SECRET not set in the hosting environment
  • Variable named for the wrong version (v4 vs v5)
  • Secret changed between deployments/instances

⚡ Quick fix

  1. Generate one (npx auth secret / openssl rand -base64 32) and set it in env
  2. Use AUTH_SECRET for Auth.js v5
  3. Keep the same secret across instances

Detailed fix by platform

Shell

  1. bash
    npx auth secret
    # or
    openssl rand -base64 32

How to diagnose

  1. Env — Variable present at runtime?
  2. Version — next-auth v4 or v5?

🔧 Still not fixed?

Many errors look alike. If the steps above didn’t solve it, one of these is probably what you’re facing:

🧠 Still stuck? Analyze your error

Paste the full message, response headers or stack trace — we'll detect the platform and point to the most likely cause.