{"record":{"id":"c82fa8e89b590536","repo":"laravel/framework","slug":"could-not-verify-the-hashed-value-s-configuration","errorCode":null,"errorMessage":"Could not verify the hashed value's configuration.","messagePattern":"Could not verify the hashed value's configuration\\.","errorType":"exception","errorClass":"RuntimeException","httpStatus":null,"severity":"error","filePath":"src/Illuminate/Database/Eloquent/Concerns/HasAttributes.php","lineNumber":1505,"sourceCode":"     * @param  string  $key\n     * @param  mixed  $value\n     * @return string|null\n     *\n     * @throws \\RuntimeException\n     */\n    protected function castAttributeAsHashedString($key, #[\\SensitiveParameter] $value)\n    {\n        if ($value === null) {\n            return null;\n        }\n\n        if (! Hash::isHashed($value)) {\n            return Hash::make($value);\n        }\n\n        /** @phpstan-ignore staticMethod.notFound */\n        if (! Hash::verifyConfiguration($value)) {\n            throw new RuntimeException(\"Could not verify the hashed value's configuration.\");\n        }\n\n        return $value;\n    }\n\n    /**\n     * Decode the given float.\n     *\n     * @param  mixed  $value\n     * @return mixed\n     */\n    public function fromFloat($value)\n    {\n        return match ((string) $value) {\n            'Infinity' => INF,\n            '-Infinity' => -INF,\n            'NaN' => NAN,\n            default => (float) $value,","sourceCodeStart":1487,"sourceCodeEnd":1523,"githubUrl":"https://github.com/laravel/framework/blob/e0f6eb3518ac29fbbca8529e97d0df7fc9f24481/src/Illuminate/Database/Eloquent/Concerns/HasAttributes.php#L1487-L1523","documentation":"Thrown by castAttributeAsHashedString() when an already-hashed value stored on the model fails Hash::verifyConfiguration(). This means the stored hash was produced with different hashing configuration (driver or options) than the currently configured hasher, indicating the hashing setup changed after the value was created. Laravel refuses to silently treat a foreign-config hash as valid.","triggerScenarios":"Reading a 'hashed' cast attribute whose stored value was hashed with a different driver/options than the current Hash config (e.g. stored under bcrypt with rounds 10, now using rounds 12, or stored under argon2i but config is now argon2id). The verifyConfiguration() check runs after isHashed() confirms it is a hash.","commonSituations":"Changing HASH_DRIVER or bcrypt rounds / argon memory-time-cost in config/hashing.php between deploys; seeding/importing data hashed by an external system; rotating hashers without rehashing; local env using bcrypt while production uses argon.","solutions":["Align hashing config (config/hashing.php: driver and options) with what produced the stored values.","Rehash the affected records using the current configuration (read raw, Hash::make(), write back).","If migrating hashers, use a rehash-on-login flow (Hash::needsRehash) instead of leaving stale hashes in place.","Verify the env's HASH_DRIVER matches across all environments that share the data."],"exampleFix":"// before\n// config/hashing.php bcrypt rounds changed from 10 to 12; old hashes throw on read\n\n// after\n// Option A: align config\n'bcrypt' => ['rounds' => env('BCRYPT_ROUNDS', 10)],\n\n// Option B: rehash records\nUser::each(function ($u) {\n    if (Hash::needsRehash($u->getRawOriginal('password'))) {\n        $u->forceFill(['password' => Hash::make($u->getRawOriginal('password'))])->save();\n    }\n});","handlingStrategy":"validation","validationCode":"$value = $model->getRawOriginal($key);\nif ($value !== null && \\Illuminate\\Support\\Facades\\Hash::isHashed($value) && ! \\Illuminate\\Support\\Facades\\Hash::verifyConfiguration($value)) {\n    // rehash with current config before reading\n    $model->{$key} = \\Illuminate\\Support\\Facades\\Hash::make($model->getRawOriginal($key . '_plain') ?? '');\n}","typeGuard":"function hashMatchesCurrentConfig(string $hashed): bool\n{\n    return \\Illuminate\\Support\\Facades\\Hash::verifyConfiguration($hashed);\n}","tryCatchPattern":"try {\n    return $model->{$key};\n} catch (\\RuntimeException $e) {\n    if (str_contains($e->getMessage(), \"hashed value's configuration\")) {\n        report(new \\Exception('Stale hash config detected for model ' . get_class($model)));\n        return null;\n    }\n    throw $e;\n}","preventionTips":["Keep HASH_DRIVER and bcrypt rounds / argon options identical across all environments sharing the data.","Use Hash::needsRehash() during login to migrate old hashes to the current config.","Add a deployment check that compares config/hashing.php against the values used to seed existing data."],"tags":["eloquent","cast","hashing","configuration","security"],"backgroundTag":null,"analyzedSha":"e0f6eb3518ac29fbbca8529e97d0df7fc9f24481","analyzedAt":"2026-08-11T20:52:37.562Z","contentChangedAt":null,"schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}