Skip to content

basalt / env/src / secret

Function: secret() ​

> secret(options?): ZodType<string>

Defined in: env/src/secret.ts:41

A Zod schema for a secret env var (JWT signing key, API key, …) that is fail-closed outside development:

  • required unless NODE_ENV is explicitly development or test (an unset NODE_ENV counts as production — a devDefault never applies there);

  • rejected outside development/test if it looks like a placeholder (change-me, secret, …);

  • enforced to a minimum length everywhere.

    APP_SECRET: secret({ devDefault: 'dev-only-insecure-secret-value' })

A fresh app runs out of the box with NODE_ENV=development, and refuses to boot anywhere else until a real secret is set.

Parameters ​

options? ​

SecretOptions = {}

Returns ​

ZodType<string>

Released under the MIT License.