SECURITY WARNING: Never run commands you don't understand. Always review code before execution. Use at your own risk.
PHP New Added 9 September 2026

Laravel: 419 Page Expired

The CSRF token sent with the form did not match the session, and Laravel answers with 419 rather than 403. Most of the time the session was never stored at all: a session driver pointing at an unreachable Redis, a SESSION_DOMAIN that does not match the host, or a load balancer spreading requests across servers that each keep file sessions locally.

Quick fix

Read the commands before running them. Anything that restarts a service, deletes data or changes permissions should be tried on a non-production system first.

Quick fix
# The token has to be in the form, and in a meta tag for fetch calls
<form method="POST">@csrf</form>
<meta name="csrf-token" content="{{ csrf_token() }}">

# Is a session actually being written?
php artisan tinker --execute="session(['a'=>1]); dump(session()->getId());"
ls -la storage/framework/sessions | tail

# .env: the cookie must match the host the browser sees
SESSION_DRIVER=redis
SESSION_DOMAIN=.example.com
SESSION_SECURE_COOKIE=true

# Config cached from a previous deploy is a classic cause
php artisan config:clear && php artisan config:cache

# A page cached by a CDN serves everybody the same stale token

How to diagnose PHP errors

PHP errors are dominated by per-request resource limits (memory_limit, max_execution_time) and by autoloading. Class-not-found errors are almost never missing code. They are a namespace that does not match the PSR-4 mapping, or a stale Composer autoload map. Laravel adds a caching layer that produces genuinely confusing errors when configuration is cached with the wrong environment.

If the quick fix above does not resolve it, work through these steps. They apply to this whole class of error, not just to this one message, which is usually what saves the time.

  1. Read the real limits from the running process, not from a config file: php -i | grep -E 'memory_limit|max_execution_time'. CLI and FPM have separate configurations.
  2. Regenerate the autoload map with composer dump-autoload -o before investigating a class-not-found error any further.
  3. For Laravel, clear cached config and routes with php artisan optimize:clear. A config cache built in the wrong environment causes errors that survive every code change.
  4. Enable full error display in development (display_errors=On, error_reporting=E_ALL). The default production settings hide the cause.
  5. For PDO connection refusals, test the same credentials with the database's own CLI client to separate PHP configuration from database access.

Tools worth reaching for

  • php -i
  • composer dump-autoload -o
  • php artisan optimize:clear
  • Xdebug
  • tail -f storage/logs/laravel.log

Authoritative references

Primary documentation for this error, worth reading before applying any fix in production.

laravel.com

Related PHP errors

See all 11 PHP errors →

Browse other categories

Something missing or wrong?

This entry is maintained by hand. If the fix is out of date, incomplete, or you have a better one, email a correction and it will be reviewed.