Laravel: 419 Page Expired (CSRF token mismatch)
Laravel rejected a POST because the CSRF token was missing, expired or didn’t match the session.
Seen on:
PHP
Meaning
Every non-GET form must include @csrf. 419 also appears when the session expired, the session cookie isn’t sent (domain/HTTPS settings), or AJAX requests don’t include the X-CSRF-TOKEN header.
Common causes
- Form missing
@csrf - Session expired (long idle page)
- Session cookie not stored (SESSION_DOMAIN / SECURE_COOKIE mismatch)
- AJAX without the X-CSRF-TOKEN header
- Load balancer with file sessions on multiple servers
⚡ Quick fix
- Add
@csrfto forms - Send the token in AJAX: meta tag + header
- Check SESSION_DOMAIN and SESSION_SECURE_COOKIE
- Use database/Redis sessions behind load balancers
Detailed fix by platform
JavaScript
fetch(url, { method: 'POST', headers: { 'X-CSRF-TOKEN': document.querySelector('meta[name=csrf-token]').content } })
How to diagnose
- Token — Is _token in the request?
- Cookie — Is the session cookie sent back?
- Expiry — How long was the page open?
🧠 Still stuck? Analyze your error
Paste the full message, response headers or stack trace — we'll detect the platform and point to the most likely cause.
Was this page helpful?
Report a correction or suggest an improvement
Last updated 2 Oct 2026