The cookie secret is a string that signs your session cookies. Without it, anyone could forge a session cookie and impersonate any user.
When the server creates a session cookie, it signs it with the secret — like a wax seal on a letter. When the cookie comes back with the next request, the server checks the seal. If it matches, the cookie is genuine. If not, it's been tampered with and the server rejects it.
pnpm prep generates a strong random secret and saves it to your .env file as COOKIE_SECRET.
pnpm prep handles this for you.COOKIE_SECRET).