redis/node-redis · error · Error

SESSION_SECRET environment variable must be set

Error message

SESSION_SECRET environment variable must be set

What it means

The `auth-code-pkce` sample boots an Express app with `express-session`, which requires a signing secret; the sample refuses to start if `SESSION_SECRET` is unset. It is a startup guard in the sample entry, not in the published library.

Solutions

  1. Create `.env` in the sample with `SESSION_SECRET=<long-random-string>`.
  2. Export `SESSION_SECRET` in your shell/container environment before launch.
  3. Use a secret manager / `.env.example` to template the value.

Example fix

# .env (before: missing)
# after
SESSION_SECRET=replace-with-a-long-random-value
Defensive patterns

Strategy: validation

Validate before calling

function requireEnv(name: string): string {
  const v = process.env[name];
  if (!v) throw new Error(`${name} environment variable must be set`);
  return v;
}
const SESSION_SECRET = requireEnv('SESSION_SECRET');

Type guard

function hasEnv(name: string): boolean { return Boolean(process.env[name]); }

Prevention

When it happens

Trigger: Running `packages/entraid/samples/auth-code-pkce` without `SESSION_SECRET` in the environment / `.env`. Throws at module load, before the server listens.

Common situations: Forgot to copy/edit `.env`; CI/container missing the env var; cloned the sample and ran it as-is.

Related errors


AI-assisted analysis of redis/node-redis@90fd0652bc (2026-08-11). Data as JSON: /api/errors/a6aab0acf4c2cad1. Report an issue: GitHub.

Appendix: source

Thrown at packages/entraid/samples/auth-code-pkce/index.ts:9

import express, { Request, Response } from 'express';
import session from 'express-session';
import dotenv from 'dotenv';
import { DEFAULT_TOKEN_MANAGER_CONFIG, EntraIdCredentialsProviderFactory } from '../../lib/entra-id-credentials-provider-factory';

dotenv.config();

if (!process.env.SESSION_SECRET) {
  throw new Error('SESSION_SECRET environment variable must be set');
}

interface PKCESession extends session.Session {
  pkceCodes?: {
    verifier: string;
    challenge: string;
    challengeMethod: string;
  };
}

interface AuthRequest extends Request {
  session: PKCESession;
}

const app = express();

const sessionConfig = {
  secret: process.env.SESSION_SECRET,

View on GitHub (pinned to 90fd0652bc)