▸ Free tool
PHP Unserialize, Safely.
Paste PHP serialized data or a Laravel failed_jobs payload and see it as a tree and as JSON. Nothing is instantiated, nothing runs, nothing leaves your browser.
▸ Tested October 5, 2026
Checked against real serialize() output from PHP 8.4 and real failed_jobs rows from Laravel 13.
Tree
JSON
The link keeps the mode and options only. What you paste stays out of the URL.
Reading the serialize() format
PHP's serialize() writes a value as typed tokens:
i:42; for an int, s:5:"hello"; for a string with its length in bytes, a:2:{...} for an array of key and value pairs, and O:4:"User":3:{...} for an object with its class name and property count. PHP 8.1 enums are
E:, and r: and
R: point back at an earlier value by its number,
which the tree shows as #n.
Calling unserialize() on data you do not control
is risky in PHP, because it creates objects and their magic methods run. This
tool reads the same format in JavaScript and only builds plain data, so you
can look inside a session, a cache entry or a queue job without that risk.
Laravel failed jobs
A queued Laravel job is stored as JSON. The useful part is data.command: the job object passed through serialize(). When a job fails for good, Laravel copies that payload into the failed_jobs table next to the exception. Paste the payload column here to see the exact
properties the worker received, which queue and connection it used, and which
models it was given as ModelIdentifier entries.
If the payload is encrypted, the tool tells you and links to the decrypt tool.
Sources, checked October 5, 2026: PHP serialize(), PHP unserialize() security warning, php-src var_unserializer, Laravel failed jobs.
Questions, answered
Is it safe to paste serialized data here?
Yes. The parser is a small JavaScript reader for the serialize() format. It turns the text into plain data and keeps class names as strings, so nothing is instantiated, no __wakeup or __destruct runs, and nothing is sent anywhere. That is the opposite of calling unserialize() on untrusted input in PHP, which is how object injection attacks work.
Why do private and protected properties look strange?
PHP stores them with a NUL byte prefix. A protected property is saved as \0*\0name and a private one as \0ClassName\0name, where ClassName is the class that declared it. The tree shows the clean name with its visibility, and the JSON adds the class to a private name only when a parent and child class use the same name.
I get a string length error. What happened?
The s:N: length counts bytes, not characters, so it breaks if the text was changed after serialize(). Common causes are NUL bytes lost when copying from a log or a database GUI, a search and replace on a database dump, or line endings converted from \n to \r\n. Tick lenient mode to read past wrong lengths. Each fix shows up as a warning so you know the data was damaged.
How do I decode a Laravel failed job?
Copy the payload column from the failed_jobs table, for example with SELECT payload FROM failed_jobs WHERE uuid = '...', and paste it in Laravel failed job mode. The tool reads the JSON, takes data.command and unserializes it. You get the job class, queue, tries, timeout and the models it was given.
Why does my job show ModelIdentifier instead of my model?
Jobs that use the SerializesModels trait store each Eloquent model as a ModelIdentifier: the class, the primary key, loaded relations and the connection. The worker loads a fresh copy from the database when the job runs. That is also why a job fails with ModelNotFoundException if the row was deleted before it ran.
What about encrypted jobs?
If the job implements ShouldBeEncrypted, data.command is a Laravel encrypted string and needs your APP_KEY. The tool spots that and points you to the Laravel encrypt/decrypt tool. Decrypt there, then paste the result here in Serialized PHP mode.
▸ Last verified:
Need this in production?
Building a Laravel SaaS? I design and ship multi-tenant Laravel apps, from first commit to production.
Laravel SaaS MVP
Keep reading
-
▸ Tool
Laravel Encrypt / Decrypt
Decrypt an encrypted job or cookie with your APP_KEY, in the browser.
-
▸ Tool
JSON Formatter & Validator
Format and validate the JSON output or a whole payload.
-
▸ Post
Message queues for document processing
What goes in a job payload and what should stay in storage.
-
▸ Post
Scaling with RabbitMQ
Queue design once a single Redis queue is not enough.