How to Generate a CRON_SECRET for Vercel Cron Jobs
4 min readUpdated 5 October 2026
To generate a CRON_SECRET, open Cron Secret Generator: a 256-bit random secret is ready instantly. Press Copy as .env line, add it to your host's environment variables as CRON_SECRET, then make your cron route reject any request whose Authorization header is not “Bearer” followed by that secret. On Vercel, Cron sends that header for you once the variable is set.
The tool is free, needs no sign-up and runs in your browser. Secrets come from crypto.getRandomValues on your device and are never saved to History, and the page also gives you ready-to-paste commands and handler code for Next.js, Express, Cloudflare Workers and GitHub Actions.
Step by step
- 1Open Cron Secret GeneratorGo to the Cron Secret Generator. A 256-bit hex secret (64 characters) is generated as soon as the page loads.
- 2Pick a format and strengthChoose Hex, Base64url or A–Z 0–9, and a strength of 128, 256, 384 or 512 bits. 256 is plenty for any scheduled job. Press New secret (Ctrl/⌘ + Enter) for another one.
- 3Name the variableLeave Variable name as CRON_SECRET for Vercel Cron, or rename it (for example REPORT_JOB_SECRET). The commands and code below update to match.
- 4Copy and store itPress Copy or Copy as .env line. Under 1 · Store it, pick .env, Vercel, GitHub or Cloudflare for the exact command that saves the secret on that platform.
- 5Check it in your endpointUnder 2 · Check it in your job, copy the handler for Next.js, Express, Worker or GH Actions, or the Vercel Cron config. Then use the curl tab to test: you should get 401 without the header and 200 with it.
Why a cron endpoint needs a secret
A cron job on Vercel or most other hosts is just an HTTP route, such as /api/cron, that your scheduler calls on a timetable. That URL is public: anyone who finds it in a repo, a log or by guessing can call it as often as they like — sending your emails, running your billing job or hammering your database.
A shared secret fixes this. The scheduler sends it with every run, and the route refuses any request that does not carry it. Because the secret is long and random, guessing it is not realistic.
How CRON_SECRET works on Vercel
Add an environment variable named CRON_SECRET to your Vercel project. From then on, Vercel Cron includes an Authorization header with the value “Bearer ” followed by your secret on every scheduled request. Your route reads that header, compares it with “Bearer ” plus process.env.CRON_SECRET, and returns 401 if they differ. The tool's Next.js tab has this route handler ready to paste.
Schedules live in the crons list of vercel.json, each with a path and a cron expression. Keep in mind that Vercel cron expressions run in UTC — “0 5 * * *” fires at 12:00 noon in Bangkok — and that cron jobs are only triggered on production deployments. After adding or changing the variable, redeploy so the new value is picked up.
Tip: Use Time Zones to translate a UTC schedule into Bangkok time (or any city) before you commit it.
GitHub Actions, Cloudflare Workers and Express
The same idea works on any scheduler that can send a header. The tool covers the common setups:
- GitHub Actions — save the secret as a repository secret, then a scheduled workflow calls your endpoint with curl and the Bearer header.
- Cloudflare Workers — Cron Triggers call your Worker's scheduled() handler directly and need no secret; use one to protect the fetch() handler if it can also run the job over HTTP.
- Express — compare the header with a constant-time check (timingSafeEqual) so the comparison can't leak the secret through timing.
Keeping the secret safe
A secret is only as good as the places it is kept. These rules cover most leaks:
- Never commit it to git. Keep .env files in .gitignore and store the real value in your host's environment settings.
- Never put it in a URL query string, where it ends up in access logs and browser history. Always send it in a header.
- In Next.js, don't give it a NEXT_PUBLIC_ prefix — that would bundle it into code sent to the browser.
- Use a different secret for each project and environment, and to rotate one, generate a new value, update it everywhere and redeploy.
Questions people ask
- What is CRON_SECRET?
- A shared password your scheduler sends with each run, usually as an Authorization: Bearer header, so your cron endpoint can reject anyone else who finds the URL. Vercel Cron sends it automatically when the CRON_SECRET environment variable is set.
- How long should a cron secret be?
- 256 bits — 64 hex characters — is plenty. Longer secrets are fine but add no practical security for a scheduled job.
- Hex, Base64url or A–Z 0–9: which format should I pick?
- All three are safe in headers and .env files. Hex is the most common, Base64url is shorter for the same strength, and A–Z 0–9 suits systems that reject symbols. The tool lengthens each format so the strength stays the same.
- Why does my Vercel cron route return 401?
- Usually the variable isn't set for the Production environment, the project wasn't redeployed after adding it, or the name in your code doesn't match. Test by hand with the curl command from the tool to see which side is wrong.
- Can I use a random password instead?
- You can, but a generated secret is better: it is long, fully random and uses only header-safe characters. For human passwords, use Password Generator instead.
More guides
- How to Format JSON (Beautify, Validate & Fix Errors)Pretty-print JSON instantly, find the exact line and column of any error and fix the usual mistakes. A free JSON formatter that runs in your browser. 4 min read
- How to Merge PDF Files (Free, No Upload)Combine several PDFs into one file in under a minute — on Windows, Mac, iPhone or Android. Free, no sign-up, and your files never leave your device. 3 min read
- How to Compress a PDF (Free, Small Enough for Email)Shrink a PDF for email or chat in seconds: pick a level, compare the size before and after, and download. Free, no sign-up, nothing uploaded. 4 min read

