Why Your Laravel APP_KEY is a Secret

Опубликовано: 25 Июль 2026
на канале: Josh Cirre
3,722
114

*Thanks so much to Bento for sponsoring this video and the channel this month. Check them out if you want an email service (and more) that just works. – https://bentonow.com/?via=joshcirre*

Something happened recently where a bunch of Laravel applictions were discovered to have public production APP_KEY's stored in their git repository. How could this happen? What should you do about it? How do you prevent it from happening? What even is an APP_KEY for Laravel and is it a secret?

Let's talk about it.

The Hacker News Article: https://thehackernews.com/2025/07/ove...
GitGuardian Article: https://blog.gitguardian.com/exploiti...
Rotating App Keys: https://laravel.com/docs/12.x/encrypt...
Encrypted Environment Variables: https://laravel.com/docs/12.x/configu...
---
🤔 *I'm still trying out Zed!:*    • No More VSCode? My Thoughts After Using Ze...  

📹 *Watch My VSCode Setup Video:*    • My Minimal and Beautiful VSCode Setup  

🎓 *Make VSCode Awesome – Caleb Porzio's Course (support me with this link):* https://gumroad.com/a/636621331


Timestamps:

00:00 What actually happened?
00:28 Thank you Bento
01:50 What are Laravel App Keys?
03:50 What happens when they get leaked?
08:29 Here's how to prevent it
16:24 Encrypted environment variables
19:00 You have to stay safe and smart