419 Page Expired 🐘 PHP

Laravel: 419 Page Expired (CSRF token mismatch)

Laravel rejected a POST because the CSRF token was missing, expired or didn’t match the session.

Seen on: PHP

Meaning

Every non-GET form must include @csrf. 419 also appears when the session expired, the session cookie isn’t sent (domain/HTTPS settings), or AJAX requests don’t include the X-CSRF-TOKEN header.

Common causes

  • Form missing @csrf
  • Session expired (long idle page)
  • Session cookie not stored (SESSION_DOMAIN / SECURE_COOKIE mismatch)
  • AJAX without the X-CSRF-TOKEN header
  • Load balancer with file sessions on multiple servers

⚡ Quick fix

  1. Add @csrf to forms
  2. Send the token in AJAX: meta tag + header
  3. Check SESSION_DOMAIN and SESSION_SECURE_COOKIE
  4. Use database/Redis sessions behind load balancers

Detailed fix by platform

JavaScript

  1. fetch(url, { method: 'POST', headers: { 'X-CSRF-TOKEN': document.querySelector('meta[name=csrf-token]').content } })

How to diagnose

  1. Token — Is _token in the request?
  2. Cookie — Is the session cookie sent back?
  3. Expiry — How long was the page open?

🧠 Still stuck? Analyze your error

Paste the full message, response headers or stack trace — we'll detect the platform and point to the most likely cause.