Can't access the PrestaShop back office
"Invalid token", a page that keeps reloading, credentials rejected even though they're correct: access to the PrestaShop admin is a single point of failure. Without it, you can't manage orders, stock or prices.
Why the back office locks up
The PrestaShop back office relies on a system of tokens and cookies tied to an encryption key specific to each install, the COOKIE_KEY defined in app/config/parameters.php (1.7/8) or config/settings.inc.php (1.6). If this key changes between two environments, or if the ps_employee table holds an out-of-sync token, login fails with an "Invalid token" message or simply bounces back to the login page.
Redirect loops usually come from a conflict between the URL declared in the ps_shop_url table (domain and SSL domain) and the URL actually used by the browser, often after a domain name change, a move to HTTPS, or a backup restored on a different server.
Finally, a badly uninstalled admin module can leave an orphaned entry in ps_tab or ps_menu, causing an error when a menu tab is clicked.
What I see regularly
- "Invalid token, please reload the page" message on a loop
- Endless redirect between /admin and the login page
- Credentials rejected even though they're correct, or a forgotten password with no reset email received
- Back office menu incomplete, or a tab that errors on click
- Access that works over HTTP but not HTTPS, or the other way round
- A renamed admin folder that's lost its access
How I restore access
-
Checking the cookie key
I compare the COOKIE_KEY in the configuration file with what the current session expects, and check it wasn't changed by mistake during a file transfer.
-
Checking the shop URLs
I check the ps_shop_url table and the SSL settings (PS_SSL_ENABLED) to make sure they match the domain actually being served.
-
Targeted reset
If needed, I regenerate an employee password directly in the database with the correct hashing algorithm, without touching other accounts or orders.
-
Menu cleanup
I fix or rebuild the ps_tab entries tied to a removed module, so the back office menu becomes consistent again.
Most frequent causes
-
Hosting migration
The database was restored on a new server, but the configuration file still points to the old key or the old domain.
-
Forced HTTPS switch
The SSL certificate was enabled on the server without updating PS_SSL_ENABLED or the URLs in the database, breaking the redirect.
-
Badly uninstalled third-party module
A back office tab or widget stays referenced in the database even though the module's files were deleted.
Related pages
-
Cannot log in to the admin area
The same symptom seen more broadly: WordPress, PrestaShop and the causes they share.
-
PrestaShop emails not received
When the password reset email never arrives, the same sending configuration is often to blame.
-
Misconfigured multistore
Each shop has its own domain in ps_shop_url: one mismatch is enough to cause a redirect loop.
-
Clearing the PrestaShop cache
Which folders to delete depending on the version, and what to leave alone.
Describe your need in one minute
A few targeted questions so I can reply with an estimate rather than another questionnaire.