Mask Query Bindings in Laravel Exception Messages | Mohamed Said       [Skip to content](#main)  [ ![](https://cdn.msaied.com/01KT78WE565VEMM3PSNQAAB0MH.png) Mohamed SaidLaravel Backend Engineer ](https://www.msaied.com/public) - [Home](https://www.msaied.com/public)
- [Projects](https://www.msaied.com/public/projects)
- [Articles](https://www.msaied.com/public/articles)
- [Certificates](https://www.msaied.com/public/certificates)
- [About](https://www.msaied.com/public#about)

           [  Contact](https://www.msaied.com/public#contact) Menu 

Menu
----

Close 

 - [HomeStart here](https://www.msaied.com/public)
- [ProjectsCase studies](https://www.msaied.com/public/projects)
- [ArticlesEngineering notes](https://www.msaied.com/public/articles)
- [CertificatesCredentials](https://www.msaied.com/public/certificates)
- [AboutHow I work](https://www.msaied.com/public#about)
- [ContactGet in touch](https://www.msaied.com/public#contact)

  [Start a conversation](https://www.msaied.com/public#contact) [WhatsApp](https://wa.me/201094619204) [Email](mailto:hello@msaied.com) 

 1. [Home](https://www.msaied.com/public)
2. /
3. [Articles](https://www.msaied.com/public/articles)
4. /
5. [Laravel](https://www.msaied.com/public/articles?category=laravel)
6. /
7. Mask Query Bindings in Laravel Exception Messages

   [Laravel](https://www.msaied.com/public/articles?category=laravel) [Tips &amp; Tricks](https://www.msaied.com/public/articles?category=tips-tricks) 

 Mask Query Bindings in Laravel Exception Messages
==================================================

 Laravel 13.27 adds a per-connection option to prevent bound query values from appearing in QueryException messages, keeping PII out of logs, failed job records, and APM traces.

 ![](https://cdn.msaied.com/01M22N44A70A5MC2S599JP0MPH.webp) [Mohamed Said](https://www.msaied.com/public#person) Published 27 Aug 2026 · Updated 28 Aug 2026 · 3 min read

ShareCopy linkCopied

 ![Mask Query Bindings in Laravel Exception Messages](https://cdn.msaied.com/603/3011313796d00cd5c4e1ead00e1e9ba1.png) 

  On this page +1. [The Problem: Bound Values End Up Everywhere](#the-problem-bound-values-end-up-everywhere)
2. [The Fix: mask\_bindings\_in\_exception\_messages](#the-fix-codemask-bindings-in-exception-messagescode)
3. [Enabling It in config/database.php](#enabling-it-in-codeconfigdatabasephpcode)
4. [What the Message Looks Like After Masking](#what-the-message-looks-like-after-masking)
5. [Key Takeaways](#key-takeaways)

 The Problem: Bound Values End Up Everywhere
-------------------------------------------

When a database query fails in Laravel, the framework throws a `QueryException` whose message contains the full SQL statement with every bound value interpolated inline. This is intentional — a message like `SQL: insert into "users" ("email") values (?)` tells you almost nothing about what went wrong, while the interpolated version pinpoints the offending row immediately.

The trouble is that exception messages do not stay in one place. Consider this realistic `QueryException` message:

```typescript
SQLSTATE[23000]: Integrity constraint violation: 1062 Duplicate entry 'ada@example.com'
for key 'users_email_unique' (Connection: mysql, SQL: insert into `users`
(`email`, `name`, `national_id`) values (ada@example.com, Ada Lovelace, 640312-4185))

```

Every bound value — an email address, a full name, a government identifier — is now a plain string inside an exception. That string travels to:

- **Application log files** written by your logging stack.
- **The `failed_jobs` table**, because `DatabaseFailedJobProvider::log()` casts the exception to a string before inserting it.
- **APM and OpenTelemetry agents**, which record the exception on the active span.
- **Any third-party error-reporting service** your application sends exceptions to.

Anywhere exceptions are persisted or transmitted, a copy of those bindings now lives.

The Fix: `mask_bindings_in_exception_messages`
----------------------------------------------

Laravel 13.27 introduces a per-connection configuration key that stops the interpolation before the message is built.

### Enabling It in `config/database.php`

```php
'connections' => [
    'mysql' => [
        'driver' => 'mysql',
        // ...
        'mask_bindings_in_exception_messages' => env('DB_MASK_BINDINGS', false),
    ],
],

```

The key is already present in the framework's own `config/database.php` for all five default connections. If your application has never published that file, you do not need to publish it — just set the environment variable:

```php
DB_MASK_BINDINGS=true

```

### What the Message Looks Like After Masking

With the option enabled, bound values are replaced by their original `?` placeholders:

```sql
SQLSTATE[23000]: Integrity constraint violation: 1062 Duplicate entry 'ada@example.com'
for key 'users_email_unique' (Connection: mysql, SQL: insert into `users`
(`email`, `name`, `national_id`) values (?, ?, ?))

```

The database error itself (including the duplicate-entry value surfaced by MySQL) is still present, but none of the application-supplied bindings appear in the message.

Key Takeaways
-------------

- Laravel's `QueryException` interpolates bound values into its message by default, which can expose PII in logs, `failed_jobs`, and observability tooling.
- Laravel 13.27 adds `mask_bindings_in_exception_messages` as a per-connection option in `config/database.php`.
- Setting `DB_MASK_BINDINGS=true` is sufficient for applications that have not published the database config file.
- Masking is opt-in and per-connection, so you can apply it selectively to connections that handle sensitive data.
- The SQL structure and the database-level error message remain intact; only the application-supplied binding values are withheld.

---

*Source: [Mask Query Bindings in Laravel Exception Messages — Laravel News](https://laravel-news.com/laravel-mask-query-bindings)*

- [Laravel](https://www.msaied.com/public/articles?search=Laravel)
- [Security](https://www.msaied.com/public/articles?search=Security)
- [QueryException](https://www.msaied.com/public/articles?search=QueryException)
- [PII](https://www.msaied.com/public/articles?search=PII)
- [Database](https://www.msaied.com/public/articles?search=Database)

 Frequently asked questions 
---------------------------

  Does enabling mask\_bindings\_in\_exception\_messages affect all database connections automatically?No. The option is configured per connection inside the `connections` array in `config/database.php`. You can enable it on specific connections that handle sensitive data while leaving others unchanged.

   Will masking bindings make it harder to debug query failures?The SQL structure, table names, column names, and the database-level error message (including any values the database engine itself surfaces, such as a duplicate-entry value) are still present in the exception message. Only the application-supplied bound values are replaced with `?` placeholders.

   Do I need to publish config/database.php to use this feature?No. Laravel 13.27 ships the key in the framework's own `config/database.php` for all five default connections. Applications that have never published that file can simply set the `DB\_MASK\_BINDINGS=true` environment variable.

   ![Mohamed Said](https://cdn.msaied.com/01M22N44A70A5MC2S599JP0MPH.webp)About the author
----------------

[Mohamed Said](https://www.msaied.com/public#person)Senior Backend Engineer specializing in Laravel, scalable SaaS platforms, APIs, and cloud infrastructure. I build secure, high-performance web applications that help businesses grow.

[About](https://www.msaied.com/public#about) [GitHub ↗](https://github.com/EG-Mohamed) [LinkedIn ↗](https://www.linkedin.com/in/msaiedm/) [WhatsApp ↗](https://wa.me/201094619204) [Email Address ↗](mailto:hello@msaied.com) [My CV ↗](https://drive.google.com/file/u/0/d/1MF20IPRJyzfy32mhEutjL5EpSls0w2Q8/view)  

   [Previous articlewhereBinary(): How to Run Case-Sensitive MySQL Queries in Laravel 13.27](https://www.msaied.com/public/articles/wherebinary-how-to-run-case-sensitive-mysql-queries-in-laravel-1327) [Next articlePessimistic Locking in Laravel Eloquent with refreshForUpdate()](https://www.msaied.com/public/articles/pessimistic-locking-in-laravel-eloquent-with-refreshforupdate)  

   On this page
-------------

1. [The Problem: Bound Values End Up Everywhere](#the-problem-bound-values-end-up-everywhere)
2. [The Fix: mask\_bindings\_in\_exception\_messages](#the-fix-codemask-bindings-in-exception-messagescode)
3. [Enabling It in config/database.php](#enabling-it-in-codeconfigdatabasephpcode)
4. [What the Message Looks Like After Masking](#what-the-message-looks-like-after-masking)
5. [Key Takeaways](#key-takeaways)

 ###  Have a technical challenge?

 Tell me what you’re building. I reply within two working days.

[Start a conversation](https://www.msaied.com/public#contact) 

   Related articles
-----------------

 [ ![](https://cdn.msaied.com/740/cce86edc21eddcbdd2f2454fadaf9c70.png)  · 3 min read### The Pipeline Pattern in Laravel: Custom Pipelines Beyond Middleware

5 Oct 2026 ](https://www.msaied.com/public/articles/the-pipeline-pattern-in-laravel-custom-pipelines-beyond-middleware-1) [ ![](https://cdn.msaied.com/739/2d6897fdcdcf090613f96f72a64b8a78.png)  · 4 min read### MySQL Full-Text Search in Laravel: Indexes, Relevance Scoring, and Boolean Mode

4 Oct 2026 ](https://www.msaied.com/public/articles/mysql-full-text-search-in-laravel-indexes-relevance-scoring-and-boolean-mode) [ ![](https://cdn.msaied.com/738/073696a3fefe18bec825beec5ac658f5.png)  · 4 min read### Laravel Queue Rate-Limited Middleware: Throttling Jobs Without Losing Work

4 Oct 2026 ](https://www.msaied.com/public/articles/laravel-queue-rate-limited-middleware-throttling-jobs-without-losing-work) 

  Have a technical challenge?
----------------------------

Tell me what you’re building. I reply within two working days.

 [Discuss your project ↗](https://www.msaied.com/public#contact) 

  © 2026 Mohamed Said · Built with Laravel, meant to last.Senior Backend Engineer specializing in Laravel, scalable SaaS platforms, APIs, and cloud infrastructure. I build secure, high-performance web applications that help businesses grow.

 - [Home](https://www.msaied.com/public)
- [Articles](https://www.msaied.com/public/articles)
- [Certificates](https://www.msaied.com/public/certificates)
- [GitHub](https://github.com/EG-Mohamed)
- [LinkedIn](https://www.linkedin.com/in/msaiedm/)
- [WhatsApp](https://wa.me/201094619204)
- [Email Address](mailto:hello@msaied.com)
- [My CV](https://drive.google.com/file/u/0/d/1MF20IPRJyzfy32mhEutjL5EpSls0w2Q8/view)
- [Sitemap](https://www.msaied.com/public/sitemap.xml)
