Notifications
All notifications extend AuthenticationNotification and are sent by mail. Swap one per guard with notifications.classes.<type> (a subclass of AuthenticationNotification), or set it to null to disable it:
| Type | Class | Recipient |
|---|---|---|
magic_link | MagicLinkNotification | account |
email_otp | EmailOtpNotification | account (login and re-authentication codes) |
verify_email | VerifyEmailNotification | account |
reset_password | ResetPasswordNotification | account |
password_changed | PasswordChangedNotification | account (change, reset, set) |
email_change_confirmation | ConfirmEmailChangeNotification | the new address |
email_change_requested | EmailChangeRequestedNotification | the old address |
email_changed | EmailChangedNotification | the old address |
account_exists | AccountExistsNotification | an address already in use |
invitation | InvitationNotification | invitee (invitation locale) |
new_device | NewDeviceLoginNotification | account |
two_factor_enabled / two_factor_disabled | TwoFactorEnabledNotification / TwoFactorDisabledNotification | account |
recovery_code_used | RecoveryCodeUsedNotification | account |
passkey_added / passkey_removed | PasskeyAddedNotification / PasskeyRemovedNotification | account |
account_locked | AccountLockedNotification | account |
refresh_token_reuse | SuspiciousSessionNotification | account (reuse, denied or flagged sign-ins) |
Delivery
- after_response (default) — a known account’s response is not measurably slower than an unknown one’s.
- queue — through an encrypted job (ShouldBeEncrypted) on notifications.connection / queue, so the plaintext link or code never sits readable in the queue store.
- sync — inline, for development.
Links
Emailed links are rendered from config only (no client-supplied redirect) with {frontend}, {app}, {guard}, {email} and {token}. The defaults put the secret in the URL fragment (#token=…), so it never reaches a server log or a Referer header — the frontend reads location.hash and POSTs the token. Do not use the log mail driver outside development.
'guards' => [
'users' => [
'model' => App\Models\User::class,
'notifications' => [
'delivery' => 'queue', // sync|after_response|queue
'queue' => 'mail',
'classes' => [
'magic_link' => App\Notifications\MagicLink::class, // extends AuthenticationNotification
'new_device' => null, // null disables it
],
'frontend_url' => 'https://app.example.com',
'urls' => [
'magic_link' => '{frontend}/auth/magic-link?guard={guard}#token={token}',
],
],
],
],Copy and language
Copy lives in authentication::notifications.* — publish the translations to change it. Accounts get mail in their locale via preferredLocale():
php artisan vendor:publish --tag=authentication-translationsShow your open-source love
This package is free and MIT-licensed. If it saves you time, a one-off donation or a Patreon membership keeps it maintained, tested and documented.
More ways to support, including cryptoBy donating, you agree to our donation terms.
Want this built into your product?
We integrate our packages into custom Laravel and AI builds. Tell us what you're working on and we'll reply within 48 hours.