Is this for HS256 or RS256 JWTs?
Use this for symmetric algorithms such as HS256 and HS512. RS256 uses a private/public key pair instead of one shared secret.
// SECRET_KEY_USE_CASE
JWT secrets are used to sign and verify tokens. Weak or reused secrets can let attackers forge tokens, so use a long random value and store it securely.
JWT_SECRET="..."
Base64URL, 64 characters
Use this for symmetric algorithms such as HS256 and HS512. RS256 uses a private/public key pair instead of one shared secret.
No. JWT signing secrets belong on the server. Frontend code can read public tokens but must never contain signing secrets.