Skip to content
ansezz.

▸ Free tool

Laravel Encrypt and Decrypt.

Decrypt a Laravel Crypt payload or cookie with your APP_KEY, or make a payload Laravel can read. It all runs in your browser.

▸ Nothing leaves your browser

Your key, payload and text stay on this page. There is no upload, no logging and no share link. Prefer a local or staging key anyway.

Paste it from .env, with the base64: prefix.

Detect uses AES-256-CBC to encrypt.

Decrypt

Paste a payload to start.

Decrypted value

 
Payload fields (no key needed)
 

Encrypt

Leave it off for Crypt::encryptString() and encrypted casts on strings.

Payload

 

How Laravel encrypts

This follows Illuminate\Encryption\Encrypter in Laravel 12. For a CBC cipher:

  • Pick a random 16 byte iv. Encrypt the text (or its serialize() form) with AES and the key from APP_KEY, and base64 it into value.
  • Compute mac as hash_hmac('sha256', iv . value, key), using the base64 strings, and leave tag empty.
  • JSON encode {iv, value, mac, tag} and base64 the result. That string is the payload.

GCM ciphers use a 12 byte iv, an empty mac and a base64 16 byte auth tag in tag. On decrypt, Laravel checks the iv length, then the MAC (CBC) or the tag (GCM), and only then decrypts.

Tested against real Laravel output: payloads made by illuminate/encryption 12 with all four ciphers decrypt here, and payloads made here decrypt in PHP with decrypt() and decryptString(). With a fixed iv, this page and PHP produce the exact same payload.

Source: Encrypter.php on GitHub and the Laravel encryption docs.

Questions, answered

Is it safe to paste my APP_KEY here?

The page never sends your key, payload or text anywhere. Decryption runs with the Web Crypto API built into your browser, there is no analytics on the inputs, and nothing is saved in the URL or in storage. Still, treat a production APP_KEY like a password: use a local or staging key when you can, and rotate the key if it was ever exposed.

What does a Laravel encrypted payload look like?

It is base64 of a small JSON object, so it usually starts with "eyJ". The JSON has four fields: iv (the random starting vector), value (the encrypted data), mac (an HMAC-SHA256 used by CBC ciphers) and tag (the auth tag used by GCM ciphers). Paste one into the decrypt box and the page shows these fields even before you enter a key.

What is the difference between encrypt and encryptString?

Crypt::encrypt() runs PHP serialize() on the value first, so a string hello becomes s:5:"hello"; before it is encrypted. Crypt::encryptString() encrypts the text as it is. The decrypt box shows the raw text and, when it is a serialized PHP value, the value inside. For encrypting, tick or untick Serialize to match the PHP call you will use to read it.

Which ciphers does Laravel support?

AES-256-CBC (the default), AES-128-CBC, AES-256-GCM and AES-128-GCM, set by the cipher option in config/app.php. CBC payloads carry a MAC that Laravel checks before decrypting. GCM payloads carry a 16 byte auth tag instead and an empty mac. This tool supports all four and can detect which one a payload uses.

Why do I get The MAC is invalid?

The key does not match the one that encrypted the payload, or the payload was changed or cut short while copying. Check that you copied the whole APP_KEY including the base64: prefix, that the payload came from the same environment, and that a key rotation did not happen in between. Laravel can also try old keys listed in APP_PREVIOUS_KEYS.

Can I decrypt Laravel cookies with this?

Yes. Copy the cookie value from your browser, it may be URL encoded and the page decodes that. After decryption a Laravel cookie starts with a 40 character hash of the cookie name followed by a | sign. The page points that prefix out and shows the real value after it. With the default session drivers, the session cookie only holds a session ID and the data lives on the server.

▸ Last verified:

Need this in production?

Building a Laravel SaaS? I design and ship multi-tenant Laravel apps, from first commit to production.

Laravel SaaS MVP

Keep reading