How to use Cron Secret Generator
- 1Pick a format and strength.
- 2Copy the secret (or the .env line).
- 3Store it on your host and check it in your cron endpoint.
What it does
- 128–512-bit secrets
- Hex, Base64url or A–Z 0–9
- Vercel, GitHub & Cloudflare commands
- Next.js, Express & Worker checks
FAQ
- What is CRON_SECRET?
- A shared password your scheduler sends with each run (usually as an Authorization: Bearer header) so your cron endpoint can reject anyone else who finds the URL. Vercel Cron sends it automatically when the CRON_SECRET environment variable is set.
- How long should a cron secret be?
- 256 bits (64 hex characters) is plenty for any scheduled job. Longer is fine but adds no practical security.
- Is the secret generated securely?
- Yes. It comes from your browser's cryptographically secure random generator (crypto.getRandomValues), is created on your device and is never saved to History.

