SigNoz issues opaque session tokens by default, and those need no secret. This guide is for administrators who want the JWT provider instead. It covers how to select that provider and set the secret it requires.
How to Set the JWT Secret
-
Choose a Strong Secret:
Use a long, random string. Avoid using simple or guessable values. -
Set the Environment Variables:
Set the following to your environment configuration:SIGNOZ_TOKENIZER_PROVIDER=jwt SIGNOZ_TOKENIZER_JWT_SECRET=your-very-strong-random-secretThe secret must be set, as SigNoz refuses to start with the
jwtprovider and an empty secret. -
Restart SigNoz:
After setting the variable, restart your SigNoz services to apply the change.
Best Practices
- Never share your JWT secret publicly.
- Rotate the secret periodically and update your environment configuration accordingly.