In config/site.php, a PHP file rather than a .env. A .php file is executed by the server; a .env is handed out as plain text by anything serving static files from the application root.

Your database credentials and application key live in config/site.php, written by the installer.

🚨 It is a PHP file for a security reason rather than a stylistic one. A .php file requested over the web is executed and returns nothing; a .env file is served as plain text by any server handing out static files from the application root — and plenty do, by default.

A .env still works for development convenience. For anything live, use the file the installer wrote.

Keep config/site.php out of version control and include it in your backups — the application key is what signs sessions, and losing it signs everybody out.

Sign in to say whether this helped.