Open source
Auth for Laravel
composer require roundly-consulting/auth-for-laravelOverview
Headless, multi-guard account authentication for Laravel APIs. Password, magic-link, email-code and passkey login; a challenge engine for two-factor and forced enrolment; RS256 access tokens with rotating refresh tokens and device sessions; registration, invitations, email verification and password flows — with opt-in JSON endpoints and an event for every state change. It owns no cryptography and no token format: it composes the Roundly jwt, refresh-tokens, two-factor, passkeys, crypto and qr packages and adds the policy and orchestration on top. MIT-licensed, built only on official Laravel components and Roundly packages — no third-party auth vendors.
What you get
Four ways to sign in
Password, magic link, email code and passwordless passkeys — each switchable per guard.
Challenge engine
Multi-step logins with TOTP, recovery-code and passkey second factors, plus forced enrolment during sign-in.
JWT + rotating sessions
RS256 access tokens with amr, auth_time and sid; rotating refresh tokens and per-device sessions you can end one by one.
Isolated guards
Users, clients, staff — each with its own model, audience, throttles, routes and activity. A token of one never works on another.
Sign-up, invites & email
Open, invite-only or closed registration, invitations with payloads, email verification and a verified email change.
Enumeration-safe by design
Identical answers and timing for known and unknown accounts, HMAC’d secrets at rest, throttling and opt-in lockout.
JSON API, facade & events
Opt-in endpoints per guard, the same flows from PHP through the Authentication facade, DI or actions, and an event for every state change.
Documentation
Installation
Install via Composer, generate the JWT keys, run the installer, wire the jwt guard and user provider, prepare the model and run the doctor.
Configuration
Every global and per-guard config key with its default — login methods, 2FA, passkeys, tokens, registration, throttles and more.
Guards
Isolated audiences of accounts — each with its own model, table, JWT audience, sessions, throttles and routes — and how to add one.
Account model
The Account contract, the HasAuthentication trait, the account columns, account lookups and the disable, lock and locale lifecycle.
The Authentication facade
Tour the Authentication facade — per-guard login and session verbs, seven area sub-contexts, scoping rules and login results.
DI and actions
Skip the facade: inject AuthenticationManager or call a single-purpose action with the guard name first — the full facade method → action map.
Login methods
Password, magic link, email code and passwordless passkey login — what each does, how it is throttled and what every login goes through.
Login challenges
The multi-step challenge engine — second factors, passkey steps and forced enrolment, the policy that picks them and how state stays safe.
Tokens & sessions
RS256 access tokens and their claims, rotating refresh tokens, device sessions, logouts and the invalidation policy.
Re-authentication
A “sudo mode” before sensitive actions — available methods, the second-factor strength rule, gated actions and the route middleware.
Two-factor & passkeys
Let signed-in accounts manage TOTP, recovery codes and passkeys — with re-authentication, invalidation, events and notifications.
Registration & invitations
Open, invite-only or closed sign-up with your own fields and account creator, plus invitations with payloads, previews and resend limits.
Email & passwords
One-time links and codes, email verification modes, verified email change, the password policy, breached-password check and reset flows.
Activity & risk
Throttling, opt-in lockout, the login-activity log, new-device detection, pluggable risk assessment and pruning.
Locale & timezone
Negotiate each request’s locale, store the account’s locale and timezone, and send every notification in the account’s language.
HTTP API
Opt-in JSON endpoints per guard — registration, route groups, every endpoint with its request body, response shapes and error codes.
Middleware
Six middleware aliases — bind a guard, require a verified or active account, demand a recent re-authentication and apply the locale.
Events
42 events for every state change — all final readonly, carrying the guard and never a secret. The hooks for audit logs and statistics.
Notifications
18 localizable mail notifications — swap or disable any per guard, deliver after the response or on an encrypted queue.
Extending
Swap claims, account creation, registration rules, risk, QR, locale, breach checks and fingerprints — plus models and resources.
Artisan commands
Install and wire, scaffold new guards, run the configuration doctor, prune old data and log an account out everywhere.
Testing
Act as an account with a real token pair, assert domain events with Event::fake(), and check login activity and token invalidation.
Security
Guard isolation, enumeration safety, single-use secrets, invalidation and recovery safeguards — and the known limits.
Requirements
PHP 8.4+, Laravel 12 or 13, OpenSSL, bcmath and mbstring, an RSA key pair, a cache with atomic locks and a mail transport.
Show your open-source love
This package is free and MIT-licensed. If it saves you time, a one-off donation or a Patreon membership keeps it maintained, tested and documented.
More ways to support, including cryptoBy donating, you agree to our donation terms.
Want this built into your product?
We integrate our packages into custom Laravel and AI builds. Tell us what you're working on and we'll reply within 48 hours.