▸ Free tool
Laravel Encrypt and Decrypt.
Decrypt a Laravel Crypt payload or cookie with your APP_KEY, or make a payload Laravel can read. It all runs in your browser.
▸ Nothing leaves your browser
Your key, payload and text stay on this page. There is no upload, no logging and no share link. Prefer a local or staging key anyway.
Paste it from .env, with the base64: prefix.
Detect uses AES-256-CBC to encrypt.
Decrypt
Paste a payload to start.
Decrypted value
Payload fields (no key needed)
Encrypt
Leave it off for Crypt::encryptString() and encrypted casts on strings.
Payload
How Laravel encrypts
This follows Illuminate\Encryption\Encrypter in Laravel 12. For a CBC cipher:
- Pick a random 16 byte iv. Encrypt the text (or its
serialize()form) with AES and the key from APP_KEY, and base64 it into value. - Compute mac as
hash_hmac('sha256', iv . value, key), using the base64 strings, and leave tag empty. - JSON encode
{iv, value, mac, tag}and base64 the result. That string is the payload.
GCM ciphers use a 12 byte iv, an empty mac and a base64 16 byte auth tag in tag. On decrypt, Laravel checks the iv length, then the MAC (CBC) or the tag (GCM), and only then decrypts.
Tested against real Laravel output: payloads made by illuminate/encryption 12 with all four ciphers decrypt here, and payloads made here decrypt in
PHP with decrypt() and decryptString(). With a fixed iv, this page and PHP produce the exact same payload.
Source: Encrypter.php on GitHub and the Laravel encryption docs.
Questions, answered
Is it safe to paste my APP_KEY here?
The page never sends your key, payload or text anywhere. Decryption runs with the Web Crypto API built into your browser, there is no analytics on the inputs, and nothing is saved in the URL or in storage. Still, treat a production APP_KEY like a password: use a local or staging key when you can, and rotate the key if it was ever exposed.
What does a Laravel encrypted payload look like?
It is base64 of a small JSON object, so it usually starts with "eyJ". The JSON has four fields: iv (the random starting vector), value (the encrypted data), mac (an HMAC-SHA256 used by CBC ciphers) and tag (the auth tag used by GCM ciphers). Paste one into the decrypt box and the page shows these fields even before you enter a key.
What is the difference between encrypt and encryptString?
Crypt::encrypt() runs PHP serialize() on the value first, so a string hello becomes s:5:"hello"; before it is encrypted. Crypt::encryptString() encrypts the text as it is. The decrypt box shows the raw text and, when it is a serialized PHP value, the value inside. For encrypting, tick or untick Serialize to match the PHP call you will use to read it.
Which ciphers does Laravel support?
AES-256-CBC (the default), AES-128-CBC, AES-256-GCM and AES-128-GCM, set by the cipher option in config/app.php. CBC payloads carry a MAC that Laravel checks before decrypting. GCM payloads carry a 16 byte auth tag instead and an empty mac. This tool supports all four and can detect which one a payload uses.
Why do I get The MAC is invalid?
The key does not match the one that encrypted the payload, or the payload was changed or cut short while copying. Check that you copied the whole APP_KEY including the base64: prefix, that the payload came from the same environment, and that a key rotation did not happen in between. Laravel can also try old keys listed in APP_PREVIOUS_KEYS.
Can I decrypt Laravel cookies with this?
Yes. Copy the cookie value from your browser, it may be URL encoded and the page decodes that. After decryption a Laravel cookie starts with a 40 character hash of the cookie name followed by a | sign. The page points that prefix out and shows the real value after it. With the default session drivers, the session cookie only holds a session ID and the data lives on the server.
▸ Last verified:
Need this in production?
Building a Laravel SaaS? I design and ship multi-tenant Laravel apps, from first commit to production.
Laravel SaaS MVP
Keep reading
-
▸ Tool
Secret & API Key Generator
Generate a fresh APP_KEY or any other random secret.
-
▸ Tool
Base64 Encoder / Decoder
Decode the outer base64 layer by hand to see the JSON envelope.
-
▸ Post
MCP auth and audit logging in a Laravel SaaS
Where encrypted tokens and audit trails fit in a Laravel app.
-
▸ Post
Laravel multi-tenancy: a scalable SaaS architecture
Per-tenant keys and data isolation in a real Laravel SaaS.