redis/node-redis · error · Error
SESSION_SECRET environment variable must be set
Error message
SESSION_SECRET environment variable must be set
What it means
The `auth-code-pkce` sample boots an Express app with `express-session`, which requires a signing secret; the sample refuses to start if `SESSION_SECRET` is unset. It is a startup guard in the sample entry, not in the published library.
Solutions
- Create `.env` in the sample with `SESSION_SECRET=<long-random-string>`.
- Export `SESSION_SECRET` in your shell/container environment before launch.
- Use a secret manager / `.env.example` to template the value.
Example fix
# .env (before: missing) # after SESSION_SECRET=replace-with-a-long-random-value
Defensive patterns
Strategy: validation
Validate before calling
function requireEnv(name: string): string {
const v = process.env[name];
if (!v) throw new Error(`${name} environment variable must be set`);
return v;
}
const SESSION_SECRET = requireEnv('SESSION_SECRET'); Type guard
function hasEnv(name: string): boolean { return Boolean(process.env[name]); } Prevention
- Provide a `.env.example` and document required variables.
- Fail fast at startup for missing secrets in all environments.
When it happens
Trigger: Running `packages/entraid/samples/auth-code-pkce` without `SESSION_SECRET` in the environment / `.env`. Throws at module load, before the server listens.
Common situations: Forgot to copy/edit `.env`; CI/container missing the env var; cloned the sample and ran it as-is.
Related errors
- SESSION_SECRET environment variable must be set
- MSAL_CLIENT_ID and MSAL_TENANT_ID environment variables…
- MSAL_CLIENT_ID and MSAL_TENANT_ID environment variables…
- Database not found in
- Invalid authority configuration
AI-assisted analysis of redis/node-redis@90fd0652bc (2026-08-11).
Data as JSON: /api/errors/a6aab0acf4c2cad1.
Report an issue: GitHub.
Appendix: source
Thrown at packages/entraid/samples/auth-code-pkce/index.ts:9
import express, { Request, Response } from 'express';
import session from 'express-session';
import dotenv from 'dotenv';
import { DEFAULT_TOKEN_MANAGER_CONFIG, EntraIdCredentialsProviderFactory } from '../../lib/entra-id-credentials-provider-factory';
dotenv.config();
if (!process.env.SESSION_SECRET) {
throw new Error('SESSION_SECRET environment variable must be set');
}
interface PKCESession extends session.Session {
pkceCodes?: {
verifier: string;
challenge: string;
challengeMethod: string;
};
}
interface AuthRequest extends Request {
session: PKCESession;
}
const app = express();
const sessionConfig = {
secret: process.env.SESSION_SECRET,View on GitHub (pinned to 90fd0652bc)