JWT_SECRET is the master key of your API: anyone who knows it can sign a token for any database role, including superusers.connect-src 'none'), loads nothing external, and never stores the secret — not in localStorage, cookies, or the URL. It disappears when you close or reload the tab./token, including its role and lifetime. Keep lifetimes short and never share tokens signed with a real secret.Used only to compute the HS256 signature in this tab. Not saved anywhere.
A negative value produces an already expired token — handy for testing how your client handles 401s.
Only needed if the server is configured to require them.