{"record":{"id":"6f513e377055710d","repo":"laravel/framework","slug":"could-not-encrypt-the-data","errorCode":null,"errorMessage":"Could not encrypt the data.","messagePattern":"Could not encrypt the data\\.","errorType":"exception","errorClass":"EncryptException","httpStatus":null,"severity":"critical","filePath":"src/Illuminate/Encryption/Encrypter.php","lineNumber":114,"sourceCode":"     * Encrypt the given value.\n     *\n     * @param  mixed  $value\n     * @param  bool  $serialize\n     * @return string\n     *\n     * @throws \\Illuminate\\Contracts\\Encryption\\EncryptException\n     */\n    public function encrypt(#[\\SensitiveParameter] $value, $serialize = true)\n    {\n        $iv = random_bytes(openssl_cipher_iv_length(strtolower($this->cipher)));\n\n        $value = \\openssl_encrypt(\n            $serialize ? serialize($value) : $value,\n            strtolower($this->cipher), $this->key, 0, $iv, $tag\n        );\n\n        if ($value === false) {\n            throw new EncryptException('Could not encrypt the data.');\n        }\n\n        $iv = base64_encode($iv);\n        $tag = base64_encode($tag ?? '');\n\n        $mac = self::$supportedCiphers[strtolower($this->cipher)]['aead']\n            ? '' // For AEAD-algorithms, the tag / MAC is returned by openssl_encrypt...\n            : $this->hash($iv, $value, $this->key);\n\n        $json = json_encode(['iv' => $iv, 'value' => $value, 'mac' => $mac, 'tag' => $tag], JSON_UNESCAPED_SLASHES);\n\n        if (json_last_error() !== JSON_ERROR_NONE) {\n            throw new EncryptException('Could not encrypt the data.');\n        }\n\n        return base64_encode($json);\n    }\n","sourceCodeStart":96,"sourceCodeEnd":132,"githubUrl":"https://github.com/laravel/framework/blob/e0f6eb3518ac29fbbca8529e97d0df7fc9f24481/src/Illuminate/Encryption/Encrypter.php#L96-L132","documentation":"Encrypter::encrypt calls openssl_encrypt with the configured key/cipher/iv; if OpenSSL returns false the payload cannot be encrypted and EncryptException('Could not encrypt the data.') is thrown. False here means the underlying library rejected the inputs (bad key/cipher combination after construction, missing tag for AEAD, or an OpenSSL environment issue) even though the constructor's static check passed.","triggerScenarios":"Calling Crypt::encrypt($value) or Encrypter::encrypt() when openssl_encrypt returns false — typically because the AEAD tag was not captured (GCM cipher with a build of PHP/OpenSSL that does not populate $tag), the data serialization produced an unusable string, or the running PHP was compiled without the requested cipher algorithm.","commonSituations":"Deploying aes-128-gcm / aes-256-gcm on a PHP build whose OpenSSL lacks GCM support; container images that swap the OpenSSL library; encrypting values that contain non-serializable resources; PHP downgrade after a server move.","solutions":["Confirm PHP was compiled with the cipher: php -r 'var_dump(in_array(strtolower(\"aes-256-gcm\"), openssl_get_cipher_methods()));'.","If GCM is unavailable, switch config('app.cipher') to aes-256-cbc and regenerate/keep APP_KEY accordingly.","Ensure you are on a PHP version that supports AEAD ($tag population in openssl_encrypt) — PHP 7.1+ with a modern OpenSSL.","If encrypting custom objects, verify the value is serializable before passing it in."],"exampleFix":"// before\n// config/app.php: 'cipher' => 'aes-256-gcm',   (OpenSSL on host lacks GCM)\n\n// after\n// config/app.php: 'cipher' => 'aes-256-cbc',\n// verify support\nif (! in_array('aes-256-cbc', openssl_get_cipher_methods())) {\n    throw new RuntimeException('Required cipher not available.');\n}","handlingStrategy":"validation","validationCode":"$cipher = strtolower(config('app.cipher', 'aes-128-cbc'));\n\nif (! in_array($cipher, openssl_get_cipher_methods(), true)) {\n    throw new RuntimeException(\"Cipher {$cipher} is not available in this PHP/OpenSSL build.\");\n}\n\nCrypt::encrypt($value);","typeGuard":"function cipherIsAvailable(string $cipher): bool {\n    return in_array(strtolower($cipher), openssl_get_cipher_methods(), true);\n}","tryCatchPattern":"use Illuminate\\Contracts\\Encryption\\EncryptException;\n\ntry {\n    return Crypt::encrypt($value);\n} catch (EncryptException $e) {\n    report(new \\RuntimeException('Encryption failed: '.$e->getMessage()));\n    throw $e;\n}","preventionTips":["Verify openssl_get_cipher_methods() contains the configured cipher on every deploy target.","Standardize on a cipher supported by all PHP/OpenSSL builds in your fleet.","Surface EncryptException through monitoring — silent encryption failures corrupt stored data."],"tags":["encryption","security","openssl","configuration","runtime"],"backgroundTag":null,"analyzedSha":"e0f6eb3518ac29fbbca8529e97d0df7fc9f24481","analyzedAt":"2026-08-11T20:52:37.562Z","contentChangedAt":null,"schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}