Skip to main content
This endpoint requires a valid CSRF token. Requests without a matching CSRF token will be rejected with a 419 Page Expired response. Include the token as the X-XSRF-TOKEN header (read from the XSRF-TOKEN cookie) or as a _token field in the form body.

Endpoint

Middleware: auth — only accessible when the user is currently authenticated. Unauthenticated requests will be redirected to /login.

Request

Parameters

string
required
CSRF token read from the XSRF-TOKEN cookie. Laravel sets this cookie on each response. Pass its decoded value in this header. Alternatively, send the token as a _token field in the request body.
No additional request body parameters are required.

Response

This endpoint does not return a JSON body. It responds with an HTTP redirect. On success, three things happen server-side:
  1. The user is logged out via Auth::guard('web')->logout().
  2. The session is fully invalidated ($request->session()->invalidate()).
  3. A new CSRF token is generated ($request->session()->regenerateToken()).
Any session cookie held by the client is no longer valid after this call.

Example

After a successful logout the XSRF-TOKEN cookie is rotated. Any cached CSRF token must be discarded and re-read from the cookie set on the redirect response before making further state-changing requests.