laravel/framework · error · RuntimeException

Could not verify the hashed value's configuration.

Error message

Could not verify the hashed value's configuration.

What it means

Thrown by castAttributeAsHashedString() when an already-hashed value stored on the model fails Hash::verifyConfiguration(). This means the stored hash was produced with different hashing configuration (driver or options) than the currently configured hasher, indicating the hashing setup changed after the value was created. Laravel refuses to silently treat a foreign-config hash as valid.

Solutions

  1. Align hashing config (config/hashing.php: driver and options) with what produced the stored values.
  2. Rehash the affected records using the current configuration (read raw, Hash::make(), write back).
  3. If migrating hashers, use a rehash-on-login flow (Hash::needsRehash) instead of leaving stale hashes in place.
  4. Verify the env's HASH_DRIVER matches across all environments that share the data.

Example fix

// before
// config/hashing.php bcrypt rounds changed from 10 to 12; old hashes throw on read

// after
// Option A: align config
'bcrypt' => ['rounds' => env('BCRYPT_ROUNDS', 10)],

// Option B: rehash records
User::each(function ($u) {
    if (Hash::needsRehash($u->getRawOriginal('password'))) {
        $u->forceFill(['password' => Hash::make($u->getRawOriginal('password'))])->save();
    }
});
Defensive patterns

Strategy: validation

Validate before calling

$value = $model->getRawOriginal($key);
if ($value !== null && \Illuminate\Support\Facades\Hash::isHashed($value) && ! \Illuminate\Support\Facades\Hash::verifyConfiguration($value)) {
    // rehash with current config before reading
    $model->{$key} = \Illuminate\Support\Facades\Hash::make($model->getRawOriginal($key . '_plain') ?? '');
}

Type guard

function hashMatchesCurrentConfig(string $hashed): bool
{
    return \Illuminate\Support\Facades\Hash::verifyConfiguration($hashed);
}

Try / catch

try {
    return $model->{$key};
} catch (\RuntimeException $e) {
    if (str_contains($e->getMessage(), "hashed value's configuration")) {
        report(new \Exception('Stale hash config detected for model ' . get_class($model)));
        return null;
    }
    throw $e;
}

Prevention

When it happens

Trigger: Reading a 'hashed' cast attribute whose stored value was hashed with a different driver/options than the current Hash config (e.g. stored under bcrypt with rounds 10, now using rounds 12, or stored under argon2i but config is now argon2id). The verifyConfiguration() check runs after isHashed() confirms it is a hash.

Common situations: Changing HASH_DRIVER or bcrypt rounds / argon memory-time-cost in config/hashing.php between deploys; seeding/importing data hashed by an external system; rotating hashers without rehashing; local env using bcrypt while production uses argon.

Related errors


AI-assisted analysis of laravel/framework@e0f6eb3518 (2026-08-11). Data as JSON: /api/errors/c82fa8e89b590536. Report an issue: GitHub.

Appendix: source

Thrown at src/Illuminate/Database/Eloquent/Concerns/HasAttributes.php:1505

     * @param  string  $key
     * @param  mixed  $value
     * @return string|null
     *
     * @throws \RuntimeException
     */
    protected function castAttributeAsHashedString($key, #[\SensitiveParameter] $value)
    {
        if ($value === null) {
            return null;
        }

        if (! Hash::isHashed($value)) {
            return Hash::make($value);
        }

        /** @phpstan-ignore staticMethod.notFound */
        if (! Hash::verifyConfiguration($value)) {
            throw new RuntimeException("Could not verify the hashed value's configuration.");
        }

        return $value;
    }

    /**
     * Decode the given float.
     *
     * @param  mixed  $value
     * @return mixed
     */
    public function fromFloat($value)
    {
        return match ((string) $value) {
            'Infinity' => INF,
            '-Infinity' => -INF,
            'NaN' => NAN,
            default => (float) $value,

View on GitHub (pinned to e0f6eb3518)