What is a Laravel APP_KEY?
APP_KEY is the application secret used by Laravel's encryption services. It protects encrypted cookies, sessions, and values created through the framework's encrypter. It is not a user password, database password, API credential, or completed encryption payload.
How this matches Laravel's generator
Laravel's key:generate command asks the framework encrypter for random key bytes sized to the configured cipher, encodes them with standard Base64, then adds the base64: prefix. The default AES-256-CBC result contains 32 random bytes, 44 Base64 characters including padding, and 51 total characters with the prefix.
Which cipher should you choose?
Current Laravel supports AES-128-CBC, AES-256-CBC, AES-128-GCM, and AES-256-GCM. A 128-bit cipher requires 16 random bytes; a 256-bit cipher requires 32. New Laravel applications default to AES-256-CBC, so leave that selection unchanged unless the target application's config/app.php specifies another supported cipher.
Copying the value into configuration
The “Copy .env line” button produces APP_KEY=base64:.... Store that line in the application's protected runtime environment. Never publish a real production key in a repository, client-side bundle, screenshot, log, issue, or support conversation. Use a different key for every application and environment.
What happens when APP_KEY changes?
Replacing an active key logs out authenticated users because Laravel encrypts cookies, including session cookies. Data encrypted with the old key also becomes unreadable unless that key remains available during a planned rotation. Do not overwrite a production key simply because a new one was generated.
Graceful key rotation
Current Laravel supports a comma-delimited APP_PREVIOUS_KEYS setting. Make the new key the current APP_KEY, place the old value in APP_PREVIOUS_KEYS, deploy the change through the protected environment, and remove legacy keys after the required transition period. Laravel encrypts new values with the current key while attempting previous keys for decryption.
Official command and sources
Inside a Laravel project, run php artisan key:generate. Use php artisan key:generate --show when you intentionally need output without modifying the environment file. The format and supported sizes follow Laravel's current KeyGenerateCommand and Encrypter source. Rotation guidance follows the official Laravel encryption documentation.
Related developer tools
PostgreSQL password generator creates random database role credentials. Django secret key generator follows Django's framework-specific format. WordPress salt generator creates that platform's eight configuration constants. Random key generator creates generic key material. Use this page specifically for Laravel's APP_KEY setting.