For the complete documentation index, see llms.txt. Markdown versions are available by appending .md to documentation URLs.

JWT Secret Configuration Guide

Self-Hosted Community - This page applies to self-hosted SigNoz without a license.
Self-Hosted Enterprise - This page applies to self-hosted SigNoz with an active license.

SigNoz issues opaque session tokens by default, and those need no secret. This guide is for administrators who want the JWT provider instead. It covers how to select that provider and set the secret it requires.

How to Set the JWT Secret

  1. Choose a Strong Secret:
    Use a long, random string. Avoid using simple or guessable values.

  2. Set the Environment Variables:
    Set the following to your environment configuration:

    SIGNOZ_TOKENIZER_PROVIDER=jwt
    SIGNOZ_TOKENIZER_JWT_SECRET=your-very-strong-random-secret

    The secret must be set, as SigNoz refuses to start with the jwt provider and an empty secret.

  3. Restart SigNoz:
    After setting the variable, restart your SigNoz services to apply the change.

Best Practices

  • Never share your JWT secret publicly.
  • Rotate the secret periodically and update your environment configuration accordingly.

Is this page helpful

Last updated—September 22, 2026

Edit on GitHub

Is this page helpful

On this page

Last updated—September 22, 2026

Edit on GitHub