laravel/framework · error · RuntimeException
Could not verify the hashed value's configuration.
Error message
Could not verify the hashed value's configuration.
What it means
Thrown by castAttributeAsHashedString() when an already-hashed value stored on the model fails Hash::verifyConfiguration(). This means the stored hash was produced with different hashing configuration (driver or options) than the currently configured hasher, indicating the hashing setup changed after the value was created. Laravel refuses to silently treat a foreign-config hash as valid.
Solutions
- Align hashing config (config/hashing.php: driver and options) with what produced the stored values.
- Rehash the affected records using the current configuration (read raw, Hash::make(), write back).
- If migrating hashers, use a rehash-on-login flow (Hash::needsRehash) instead of leaving stale hashes in place.
- Verify the env's HASH_DRIVER matches across all environments that share the data.
Example fix
// before
// config/hashing.php bcrypt rounds changed from 10 to 12; old hashes throw on read
// after
// Option A: align config
'bcrypt' => ['rounds' => env('BCRYPT_ROUNDS', 10)],
// Option B: rehash records
User::each(function ($u) {
if (Hash::needsRehash($u->getRawOriginal('password'))) {
$u->forceFill(['password' => Hash::make($u->getRawOriginal('password'))])->save();
}
}); Defensive patterns
Strategy: validation
Validate before calling
$value = $model->getRawOriginal($key);
if ($value !== null && \Illuminate\Support\Facades\Hash::isHashed($value) && ! \Illuminate\Support\Facades\Hash::verifyConfiguration($value)) {
// rehash with current config before reading
$model->{$key} = \Illuminate\Support\Facades\Hash::make($model->getRawOriginal($key . '_plain') ?? '');
} Type guard
function hashMatchesCurrentConfig(string $hashed): bool
{
return \Illuminate\Support\Facades\Hash::verifyConfiguration($hashed);
} Try / catch
try {
return $model->{$key};
} catch (\RuntimeException $e) {
if (str_contains($e->getMessage(), "hashed value's configuration")) {
report(new \Exception('Stale hash config detected for model ' . get_class($model)));
return null;
}
throw $e;
} Prevention
- Keep HASH_DRIVER and bcrypt rounds / argon options identical across all environments sharing the data.
- Use Hash::needsRehash() during login to migrate old hashes to the current config.
- Add a deployment check that compares config/hashing.php against the values used to seed existing data.
When it happens
Trigger: Reading a 'hashed' cast attribute whose stored value was hashed with a different driver/options than the current Hash config (e.g. stored under bcrypt with rounds 10, now using rounds 12, or stored under argon2i but config is now argon2id). The verifyConfiguration() check runs after isHashed() confirms it is a hash.
Common situations: Changing HASH_DRIVER or bcrypt rounds / argon memory-time-cost in config/hashing.php between deploys; seeding/importing data hashed by an external system; rotating hashers without rehashing; local env using bcrypt while production uses argon.
Related errors
- Call to undefined cast
- The cast object for the
- The provided class must extend…
- The provided class must extend…
- Add [ ] to fillable property to allow mass assignment on […
AI-assisted analysis of laravel/framework@e0f6eb3518 (2026-08-11).
Data as JSON: /api/errors/c82fa8e89b590536.
Report an issue: GitHub.
Appendix: source
Thrown at src/Illuminate/Database/Eloquent/Concerns/HasAttributes.php:1505
* @param string $key
* @param mixed $value
* @return string|null
*
* @throws \RuntimeException
*/
protected function castAttributeAsHashedString($key, #[\SensitiveParameter] $value)
{
if ($value === null) {
return null;
}
if (! Hash::isHashed($value)) {
return Hash::make($value);
}
/** @phpstan-ignore staticMethod.notFound */
if (! Hash::verifyConfiguration($value)) {
throw new RuntimeException("Could not verify the hashed value's configuration.");
}
return $value;
}
/**
* Decode the given float.
*
* @param mixed $value
* @return mixed
*/
public function fromFloat($value)
{
return match ((string) $value) {
'Infinity' => INF,
'-Infinity' => -INF,
'NaN' => NAN,
default => (float) $value,View on GitHub (pinned to e0f6eb3518)