Can I reuse a session secret across environments?
Use separate secrets for development, staging, and production so a leaked lower-environment value cannot affect production sessions.
// SECRET_KEY_USE_CASE
A session secret protects signed cookies and server-side session data from tampering. Use a long random value, keep it private, and rotate it deliberately when needed.
SESSION_SECRET="..."
Base64URL, 48 characters or longer
Use separate secrets for development, staging, and production so a leaked lower-environment value cannot affect production sessions.
Existing signed sessions may become invalid. Plan rotations during low-risk windows or support multiple secrets if your framework allows it.