Get a free website with any plan

See how
APPLICATIONS

Laravel .env and APP_KEY

Last updated

IN SHORT

Laravel requires an APP_KEY in your .env file to encrypt user sessions, cookies, and URLs. Missing keys cause encryption errors and login failures. On Flashcloud, connect via SSH and run php artisan key:generate in your project root, or manually paste a base64 key into .env and run php artisan config:clear to apply it.

Laravel throws "No application encryption key has been specified" or produces garbled sessions and failed logins when APP_KEY is missing or blank in .env. Fix it by generating a key with Artisan and making sure .env actually sits in your app's root with the right permissions. Manual uploads and Git deploys often leave it empty.

Generate and set APP_KEY

If you have SSH access, the cleanest fix is the built-in Artisan command. Connect via SSH access (Security → SSH Access in cPanel, or your own SSH client), cd into your Laravel root, and run:

php artisan key:generate

This writes a fresh base64 key directly into the APP_KEY line of your .env file. It only touches that one line, so it's safe to run even if the rest of your .env is already configured.

If you prefer not to use the command line, generate a key manually and paste it in:

  1. Run php -r "echo 'base64:'.base64_encode(random_bytes(32));" on your local machine, or generate one with any base64-safe 32-byte random string.
  2. Open .env in cPanel's File Manager (enable hidden/dotfile visibility in File Manager's settings, dotfiles don't show by default) and set APP_KEY=base64:... with the value you generated.
  3. Save, then clear cached config so Laravel picks up the change: php artisan config:clear.

Why this breaks things

Laravel uses APP_KEY to encrypt sessions, signed URLs, and anything passed through the Crypt facade. With no key, encryption calls throw outright. With a key that changes between deploys, every existing session and encrypted cookie instantly becomes invalid, users get logged out, and CSRF tokens stop matching. This is why copying a project between environments without carrying over the same .env is a common source of "random" login failures.

Where .env needs to live

Laravel's .env belongs in the project root, one level above public/, which itself should be your domain's document root. If you deployed by uploading a zip through cPanel's File Manager, double-check that the Laravel folder structure wasn't flattened or nested an extra level deep during extraction. That's the single most common reason .env ends up somewhere bootstrap/app.php never looks.

If you're deploying from a repository, cPanel's Git Version Control tool can clone it for you. .env should never be committed to the repo; create or edit it directly on the server after each clone.

Permissions and visibility

.env is a dotfile, so enable hidden/dotfile visibility in File Manager's settings to see it. Permissions of 644 are normal and sufficient. Laravel only needs to read it, not execute it. Avoid setting it to 777; that's a common but unnecessary habit that widens who can read your database credentials and app key.

PHP version and extensions

Modern Laravel releases require a specific minimum PHP version, check your version's requirements before deploying. Set the PHP version for the domain from the PHP Version tile in the portal, this switches the active PHP runtime for that domain between 7.4 and 8.3. If Laravel's installer or composer install complains about a missing extension, check cPanel's Select PHP Version tool, which lists per-extension checkboxes for the account's PHP version. Upload size limits for large deploys are controlled separately, in MultiPHP INI Editor, not the PHP Version tile.

Caching gotchas after changing .env

If you ran php artisan config:cache at any point, Laravel stops reading .env directly and serves values from a compiled cache file instead. Editing .env after that point has no visible effect until you clear it:

php artisan config:clear
php artisan cache:clear

This is the second most common reason a freshly generated APP_KEY "doesn't work". The app is still reading the old cached config, not the new file.

Faster page loads once it's running

Laravel apps run on the same LiteSpeed Web Server every site on Flashcloud gets, and its server-level caching applies site-wide; on most hosting accounts this helps read-heavy routes if you're layering Laravel's own cache drivers on top. See how we make your site fast for how the server and edge layers fit together.

When to open a ticket

If .env is present, readable, and APP_KEY is set but you're still getting encryption or session errors, it's worth ruling out a mismatched PHP version or a missing extension first. If you've checked both and it's still broken, or if you prefer not to use the command line and need help running Artisan commands, open a ticket from Support in the portal. It goes to a real person, not a bot.

Common questions

Why can't I see my .env file in File Manager?

File Manager hides dotfiles by default. Turn on hidden file visibility inside File Manager's settings to view and edit .env. Keep its permissions set to 644 so Laravel can read it safely.

Why are my users getting logged out after a deployment?

Your APP_KEY changed between deploys. Changing this key invalidates all active sessions, cookies, and CSRF tokens immediately. Keep the same APP_KEY across deployments to prevent unexpected logouts.

Why is Laravel still showing an encryption error after I added APP_KEY?

Laravel is reading an old cached configuration instead of your updated .env file. Clear the compiled cache by running php artisan config:clear and php artisan cache:clear. Once cleared, Laravel loads the new key from your .env file.

What permissions should I set on my .env file?

Set permissions to 644. Laravel only requires read access to load your settings. Avoid setting permissions to 777, which needlessly exposes database credentials and keys to other users.

CAN'T FIND IT?

Real humans answer fast.

Hosting with us? Open a ticket and a real person replies - no scripts, no upsells. Still choosing a host? The same team is included with every plan, from day one.