NewWe open-sourced 50+ Laravel packages
Custom AI apps, agents and automation — Roundly ConsultingRoundly
All packages
Auth for Laravel

Notifications

All notifications extend AuthenticationNotification and are sent by mail. Swap one per guard with notifications.classes.<type> (a subclass of AuthenticationNotification), or set it to null to disable it:

TypeClassRecipient
magic_linkMagicLinkNotificationaccount
email_otpEmailOtpNotificationaccount (login and re-authentication codes)
verify_emailVerifyEmailNotificationaccount
reset_passwordResetPasswordNotificationaccount
password_changedPasswordChangedNotificationaccount (change, reset, set)
email_change_confirmationConfirmEmailChangeNotificationthe new address
email_change_requestedEmailChangeRequestedNotificationthe old address
email_changedEmailChangedNotificationthe old address
account_existsAccountExistsNotificationan address already in use
invitationInvitationNotificationinvitee (invitation locale)
new_deviceNewDeviceLoginNotificationaccount
two_factor_enabled / two_factor_disabledTwoFactorEnabledNotification / TwoFactorDisabledNotificationaccount
recovery_code_usedRecoveryCodeUsedNotificationaccount
passkey_added / passkey_removedPasskeyAddedNotification / PasskeyRemovedNotificationaccount
account_lockedAccountLockedNotificationaccount
refresh_token_reuseSuspiciousSessionNotificationaccount (reuse, denied or flagged sign-ins)

Delivery

  • after_response (default) — a known account’s response is not measurably slower than an unknown one’s.
  • queue — through an encrypted job (ShouldBeEncrypted) on notifications.connection / queue, so the plaintext link or code never sits readable in the queue store.
  • sync — inline, for development.

Links

Emailed links are rendered from config only (no client-supplied redirect) with {frontend}, {app}, {guard}, {email} and {token}. The defaults put the secret in the URL fragment (#token=…), so it never reaches a server log or a Referer header — the frontend reads location.hash and POSTs the token. Do not use the log mail driver outside development.

'guards' => [
    'users' => [
        'model' => App\Models\User::class,
        'notifications' => [
            'delivery' => 'queue',       // sync|after_response|queue
            'queue' => 'mail',
            'classes' => [
                'magic_link' => App\Notifications\MagicLink::class,   // extends AuthenticationNotification
                'new_device' => null,                                  // null disables it
            ],
            'frontend_url' => 'https://app.example.com',
            'urls' => [
                'magic_link' => '{frontend}/auth/magic-link?guard={guard}#token={token}',
            ],
        ],
    ],
],

Copy and language

Copy lives in authentication::notifications.* — publish the translations to change it. Accounts get mail in their locale via preferredLocale():

php artisan vendor:publish --tag=authentication-translations

Show your open-source love

This package is free and MIT-licensed. If it saves you time, a one-off donation or a Patreon membership keeps it maintained, tested and documented.

More ways to support, including crypto

By donating, you agree to our donation terms.

Want this built into your product?

We integrate our packages into custom Laravel and AI builds. Tell us what you're working on and we'll reply within 48 hours.