{"record":{"id":"04febb9eb3335147","repo":"laravel/framework","slug":"unsupported-cipher-or-incorrect-key-length-suppor","errorCode":null,"errorMessage":"Unsupported cipher or incorrect key length. Supported ciphers are: {$ciphers}.","messagePattern":"Unsupported cipher or incorrect key length\\. Supported ciphers are: (.+?)\\.","errorType":"exception","errorClass":"RuntimeException","httpStatus":null,"severity":"critical","filePath":"src/Illuminate/Encryption/Encrypter.php","lineNumber":61,"sourceCode":"        'aes-256-gcm' => ['size' => 32, 'aead' => true],\n    ];\n\n    /**\n     * Create a new encrypter instance.\n     *\n     * @param  string  $key\n     * @param  string  $cipher\n     *\n     * @throws \\RuntimeException\n     */\n    public function __construct(#[\\SensitiveParameter] $key, $cipher = 'aes-128-cbc')\n    {\n        $key = (string) $key;\n\n        if (! static::supported($key, $cipher)) {\n            $ciphers = implode(', ', array_keys(self::$supportedCiphers));\n\n            throw new RuntimeException(\"Unsupported cipher or incorrect key length. Supported ciphers are: {$ciphers}.\");\n        }\n\n        $this->key = $key;\n        $this->cipher = $cipher;\n    }\n\n    /**\n     * Determine if the given key and cipher combination is valid.\n     *\n     * @param  string  $key\n     * @param  string  $cipher\n     * @return bool\n     */\n    public static function supported(#[\\SensitiveParameter] $key, $cipher)\n    {\n        if (! isset(self::$supportedCiphers[strtolower($cipher)])) {\n            return false;\n        }","sourceCodeStart":43,"sourceCodeEnd":79,"githubUrl":"https://github.com/laravel/framework/blob/e0f6eb3518ac29fbbca8529e97d0df7fc9f24481/src/Illuminate/Encryption/Encrypter.php#L43-L79","documentation":"Encrypter::__construct validates the key+cipher pair via Encrypter::supported(), which checks that the cipher is one of aes-128-cbc / aes-256-cbc / aes-128-gcm / aes-256-gcm AND that mb_strlen($key) matches the required byte size (16 or 32). If either fails, supported() returns false and the constructor throws. This is usually hit at application boot when APP_KEY and the configured cipher disagree.","triggerScenarios":"Booting the app with APP_KEY set to a value whose length does not match the configured cipher (e.g. a 16-byte key with 'aes-256-cbc'); setting an invalid cipher string in config/app.php; passing a custom key/cipher to new Encrypter() that violates the size map.","commonSituations":"Generating APP_KEY on one project (32-char base64 → 32 raw bytes after decode for aes-256-cbc) and copying it to a project configured for aes-128-cbc; mis-typing the cipher; older Laravel cipher 'aes-256-cbc' vs newer 'aes-128-gcm' mismatch after an upgrade; using a raw hex key of the wrong length.","solutions":["Regenerate the key with the matching cipher: php artisan key:generate --cipher=aes-256-cbc (or whichever your config uses).","Make config('app.cipher') match the key length: 16-byte key → aes-128-*, 32-byte key → aes-256-*.","Verify the key is the raw decoded bytes the Encrypter expects (Laravel's APP_KEY is base64-Encoded, decoded automatically by KeyGuesser/the framework).","If constructing the Encrypter manually, ensure mb_strlen($key, '8bit') equals 16 or 32 before calling new Encrypter($key, $cipher)."],"exampleFix":"// before\n// .env: APP_KEY=base64:shortKey     (decodes to 16 bytes)\n// config/app.php: 'cipher' => 'aes-256-cbc',\n\n// after (align cipher to key)\n// .env: APP_KEY=base64:shortKey\n// config/app.php: 'cipher' => 'aes-128-cbc',\n// or regenerate a 32-byte key\n// $ php artisan key:generate --cipher=aes-256-cbc","handlingStrategy":"validation","validationCode":"use Illuminate\\Encryption\\Encrypter;\n\n$key = (string) config('app.key');\n$cipher = config('app.cipher', 'aes-128-cbc');\n\nif (! Encrypter::supported($key, $cipher)) {\n    throw new RuntimeException('APP_KEY length does not match cipher '.$cipher);\n}\n\nnew Encrypter($key, $cipher);","typeGuard":"function keyMatchesCipher(string $key, string $cipher): bool {\n    return \\Illuminate\\Encryption\\Encrypter::supported($key, $cipher);\n}","tryCatchPattern":null,"preventionTips":["Keep APP_KEY and config('app.cipher') consistent across all environments.","After a key rotation, regenerate using php artisan key:generate --cipher=<your cipher>.","Verify key byte length (16 for aes-128-*, 32 for aes-256-*) before booting."],"tags":["encryption","security","app-key","configuration","bootstrap"],"backgroundTag":null,"analyzedSha":"e0f6eb3518ac29fbbca8529e97d0df7fc9f24481","analyzedAt":"2026-08-11T20:52:37.562Z","contentChangedAt":null,"schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}