NewWe open-sourced 50+ Laravel packages
Custom AI apps, agents and automation — Roundly ConsultingRoundly
All packages
Certificates for Laravel

Attaching to models

Add the HasCertificates trait to any Eloquent model that owns domains — a tenant, a site, a team. Certificates attach through the nullable certifiable morph on the registry. Issue one through the facade with owner(), or use the trait’s requestCertificate() shorthand, which calls the same CertificatesManager::issue():

use Illuminate\Database\Eloquent\Model;
use RoundlyConsulting\Certificates\Concerns\HasCertificates;
use RoundlyConsulting\Certificates\Facades\Certificates;

class Tenant extends Model
{
    use HasCertificates;
}

Certificates::for('shop.example.com')->owner($tenant)->issue(); // issue, owned by $tenant

$tenant->requestCertificate('shop.example.com');           // the same shorthand, via the manager
$tenant->requestCertificate('shop.example.com', 'acme');   // ...on a specific driver
$tenant->certificateFor('shop.example.com');               // ?Certificate — the latest
$tenant->hasCertificateFor('shop.example.com');            // bool
$tenant->certificates()->get();                            // every certificate it owns
$tenant->activeCertificates();
$tenant->expiringCertificates(days: 14);
  • certificates() — the MorphMany relation, using the configured registry model.
  • requestCertificate($domain, ?$driver) — issue a certificate owned by the model, through the manager, so Certificates::fake() records it.
  • certificateFor($domain) — the model’s latest certificate for a primary domain, or null.
  • hasCertificateFor($domain) — whether the model has any certificate for the domain.
  • activeCertificates() — the model’s certificates in the active() scope.
  • expiringCertificates(?$days) — expiring within $days, default renewal.threshold_days.

Owner from the builder

The builder attaches the owner alongside SANs, a driver and meta:

Certificates::for('shop.example.com')
    ->alsoFor('www.shop.example.com')
    ->owner($tenant)
    ->using('acme')
    ->issue();

Lifecycle through the facade

The trait only issues and reads. Renew, revoke and expire an owned certificate through the facade:

use RoundlyConsulting\Certificates\Facades\Certificates;

Certificates::renew($tenant->certificateFor('shop.example.com'));
Certificates::for('shop.example.com')->revoke('tenant closed');

The owner matters beyond lookups: when no explicit or configured notifiable exists, expiry alerts go to the certificate’s certifiable owner (see Expiry monitoring). Use key_type uuid or ulid when owners have UUID or ULID keys.

Show your open-source love

This package is free and MIT-licensed. If it saves you time, a one-off donation or a Patreon membership keeps it maintained, tested and documented.

More ways to support, including crypto

By donating, you agree to our donation terms.

Want this built into your product?

We integrate our packages into custom Laravel and AI builds. Tell us what you're working on and we'll reply within 48 hours.