Laravel application secret

Laravel APP_KEY Generator

Generate the same base64: key format used by Laravel's Artisan command. The random bytes are created locally and never sent to this site.

Generate a Laravel application key

Laravel defaults to AES-256-CBC. Choose another cipher only when the application's configuration explicitly uses it.

The selected cipher determines whether Laravel expects 32 or 16 random bytes.

AES-256-CBC256 random bits51 characters with prefix
Generated locallyThe APP_KEY remains in this browser tab. Move it directly to protected deployment configuration.

What is a Laravel APP_KEY?

APP_KEY is the application secret used by Laravel's encryption services. It protects encrypted cookies, sessions, and values created through the framework's encrypter. It is not a user password, database password, API credential, or completed encryption payload.

How this matches Laravel's generator

Laravel's key:generate command asks the framework encrypter for random key bytes sized to the configured cipher, encodes them with standard Base64, then adds the base64: prefix. The default AES-256-CBC result contains 32 random bytes, 44 Base64 characters including padding, and 51 total characters with the prefix.

Which cipher should you choose?

Current Laravel supports AES-128-CBC, AES-256-CBC, AES-128-GCM, and AES-256-GCM. A 128-bit cipher requires 16 random bytes; a 256-bit cipher requires 32. New Laravel applications default to AES-256-CBC, so leave that selection unchanged unless the target application's config/app.php specifies another supported cipher.

Copying the value into configuration

The “Copy .env line” button produces APP_KEY=base64:.... Store that line in the application's protected runtime environment. Never publish a real production key in a repository, client-side bundle, screenshot, log, issue, or support conversation. Use a different key for every application and environment.

What happens when APP_KEY changes?

Replacing an active key logs out authenticated users because Laravel encrypts cookies, including session cookies. Data encrypted with the old key also becomes unreadable unless that key remains available during a planned rotation. Do not overwrite a production key simply because a new one was generated.

Graceful key rotation

Current Laravel supports a comma-delimited APP_PREVIOUS_KEYS setting. Make the new key the current APP_KEY, place the old value in APP_PREVIOUS_KEYS, deploy the change through the protected environment, and remove legacy keys after the required transition period. Laravel encrypts new values with the current key while attempting previous keys for decryption.

Official command and sources

Inside a Laravel project, run php artisan key:generate. Use php artisan key:generate --show when you intentionally need output without modifying the environment file. The format and supported sizes follow Laravel's current KeyGenerateCommand and Encrypter source. Rotation guidance follows the official Laravel encryption documentation.

Related developer tools

PostgreSQL password generator creates random database role credentials. Django secret key generator follows Django's framework-specific format. WordPress salt generator creates that platform's eight configuration constants. Random key generator creates generic key material. Use this page specifically for Laravel's APP_KEY setting.