NewWe open-sourced 50+ Laravel packages
Custom AI apps, agents and automation — Roundly ConsultingRoundly
All packages
Auth for Laravel

DI and actions

The facade is the recommended default, not the only way in. Three entry points run the same code: the Authentication facade (shortest), the manager RoundlyConsulting\Auth\AuthenticationManager — the facade’s root, a container singleton — injected through the constructor (same API, explicit dependency, no static calls), and actions in RoundlyConsulting\Auth\Actions\* (single-purpose classes with execute(), for composing into your own actions, jobs and commands).

Inject the manager

use RoundlyConsulting\Auth\AuthenticationManager;
use RoundlyConsulting\Auth\Enums\InvalidationReason;

final class ResetSupportPassword
{
    public function __construct(private AuthenticationManager $authentication) {}

    public function __invoke(User $user, string $password): void
    {
        $this->authentication->guard('users')->passwords()->set($user, $password, InvalidationReason::Security);
    }
}

Call an action

Host-facing actions take the guard name first and refuse an account, invitation or passkey of another guard before anything is written:

use RoundlyConsulting\Auth\Actions\Account\LockAccount;
use RoundlyConsulting\Auth\Actions\Invitations\ResendInvitation;
use RoundlyConsulting\Auth\Actions\Passwords\SetPassword;
use RoundlyConsulting\Auth\Enums\InvalidationReason;

// The raw actions — the same code path; the guard name comes first.
app(SetPassword::class)->execute('users', $user, $temporaryPassword, InvalidationReason::Security);
app(LockAccount::class)->execute('users', $user, 3600);
app(ResendInvitation::class)->execute('users', $invitation);   // another guard's invitation → InvitationNotFound

Facade method → action

Facade methodAction
attempt()Login\AttemptPasswordLogin
requestMagicLink() / consumeMagicLink()Login\RequestMagicLink / Login\ConsumeMagicLink
requestEmailOtp() / verifyEmailOtp()Login\RequestEmailOtp / Login\VerifyEmailOtp
passkeyLoginOptions() / loginWithPasskey()Login\BeginPasskeyLogin / Login\CompletePasskeyLogin
register()Registration\RegisterAccount
issueTokens()Tokens\IssueAccountTokens
refresh()Tokens\RefreshTokenPair
sessions()Sessions\ListSessions
logout() / logoutSession()Sessions\LogoutCurrentSession / Sessions\LogoutSession
logoutOthers() / logoutEverywhere()Sessions\LogoutOtherSessions / Sessions\LogoutEverywhere
invalidate()Sessions\InvalidateAccountTokens
disable() / enable()Account\DisableAccount / Account\EnableAccount
lock() / unlock()Account\LockAccount / Account\UnlockAccount
updateLocale()Account\UpdateLocale
activity()Activity\ListLoginActivity
prune()Activity\PruneAuthenticationData
twoFactor()->status() / start()TwoFactor\GetTwoFactorStatus / TwoFactor\StartTwoFactorEnrolment
twoFactor()->confirm() / disable()TwoFactor\ConfirmTwoFactorEnrolment / TwoFactor\DisableTwoFactor
twoFactor()->regenerateRecoveryCodes()TwoFactor\RegenerateRecoveryCodes
passkeys()->all() / registrationOptions()Passkeys\ListPasskeys / Passkeys\BeginPasskeyRegistration
passkeys()->register() / rename() / remove()Passkeys\RegisterPasskey / Passkeys\RenamePasskey / Passkeys\RemovePasskey
passwords()->set() / change()Passwords\SetPassword / Passwords\ChangePassword
passwords()->requestReset() / reset()Passwords\RequestPasswordReset / Passwords\ResetPassword
passwords()->validate()Passwords\ValidatePasswordPolicy
email()->sendVerification() / requestVerification() / resendVerification()Email\SendEmailVerification / Email\RequestEmailVerification / Email\ResendEmailVerification
email()->verify()Email\VerifyEmail
email()->requestChange() / confirmChange()Email\RequestEmailChange / Email\ConfirmEmailChange
invitations()->create() / accept()Invitations\CreateInvitation / Invitations\AcceptInvitation
invitations()->paginate() / preview()Invitations\ListInvitations / Invitations\PreviewInvitation
invitations()->resend() / revoke()Invitations\ResendInvitation / Invitations\RevokeInvitation
invitations()->link()Invitations\SendInvitation (notify: false)
reauthentication()->sendCode() / passkeyOptions()Account\SendReauthenticationCode / Account\BeginPasskeyReauthentication
reauthentication()->confirm() / ensureRecent()Account\Reauthenticate / Account\EnsureRecentlyAuthenticated
challenges()->complete()Challenges\CompleteTwoFactorStep, ConfirmTwoFactorEnrolmentStep, CompletePasskeyStep or CompletePasskeyEnrolmentStep (by method)
challenges()->passkeyOptions() / passkeyEnrolmentOptions()Challenges\BeginPasskeyStep / Challenges\BeginPasskeyEnrolmentStep
challenges()->startTwoFactorEnrolment()Challenges\StartTwoFactorEnrolmentStep
  • The facade, the manager and the package controllers resolve actions from the container, so all three run the same code.
  • Actions tagged @internal are building blocks of these flows, not API: the login pipeline (CompleteFirstFactor, CompleteLogin, EnsureAccountCanLogin, ResolveRequiredSteps, StartLoginChallenge, AssessLoginRisk, DetectNewDevice, RecordLoginActivity), the challenge engine (AdvanceChallenge, FinalizeChallenge, FindActiveChallenge, InvalidateChallenge, RecordChallengeFailure), the four OneTimeTokens actions, VerifyPassword, CreateAccount (replace it through registration.creator), EnforceSessionLimit, BuildAccessTokenRequest and IssueTokenPair (issue through issueTokens(), which also fires TokensIssued).
  • Actions take the same DTOs as the facade, from RoundlyConsulting\Auth\DataTransferObjects — PasswordCredentials, SessionContext, CurrentToken, RegistrationData, InvitationData, AcceptInvitationData, ChallengeFactorData, ReauthenticationData, ChangePasswordData, PasswordResetData, EmailChangeData and LocaleData.

Show your open-source love

This package is free and MIT-licensed. If it saves you time, a one-off donation or a Patreon membership keeps it maintained, tested and documented.

More ways to support, including crypto

By donating, you agree to our donation terms.

Want this built into your product?

We integrate our packages into custom Laravel and AI builds. Tell us what you're working on and we'll reply within 48 hours.