Open source
Crypto for Laravel
composer require roundly-consulting/crypto-for-laravelOverview
Native cryptographic and encoding primitives for Laravel — JWS signing with strict verification, JWK thumbprints, X.509 certificate facts, a strict DER decoder, TOTP/HOTP, WebAuthn signature verification, HMAC, AES-256-GCM authenticated encryption, CSPRNG tokens and strict codecs. It is zero-config and à la carte: no config file, no env reads, every key is an explicit argument, and each primitive works on its own or through a single Crypto facade. Parity with the RFCs is proven by committed test vectors, and it is built only on PHP’s native crypto extensions plus Laravel and Symfony — no third-party crypto library. MIT licensed.
What you get
JWS with pinned algorithms
Compact and flattened JWS across HS, RS, ES and EdDSA — the algorithm is pinned before the signature is ever read.
JWK & X.509 facts
RFC 7517 JWKs with RFC 7638 thumbprints, plus certificate and chain facts. The math is proven; the trust decision stays yours.
TOTP & HOTP
RFC 6238 and RFC 4226 one-time passwords with a timing-flat drift window and otpauth:// enrolment URIs.
WebAuthn verification
A canonical CBOR decoder, COSE key parsing and authenticator data for passkey signature checks.
HMAC, encryption & CSPRNG
Webhook HMAC, peppered digests, constant-time compares, AES-256-GCM encryption bound to its context, and length-bounded random tokens.
Strict codecs & DER
Canonical-only base64url, base64, base32 and hex, plus a bounded X.690 DER decoder for raw extension bytes.
Facade, DI or à la carte
One Crypto facade, an injectable CryptoManager, or each class on its own — no config file, no env reads, keys are explicit arguments.
Documentation
Installation
Install via Composer — the service provider and the Crypto facade auto-register, with no config file, migrations or wiring.
Zero-config design
No config file and no env reads — keys are explicit arguments, and keyed signers are wired in your own service provider.
The Crypto facade
One entry point for the whole toolbox — flat methods plus the keys(), random(), x509() and ecDer() sub-accessors, with a full method table.
DI and direct classes
Inject CryptoManager instead of calling the facade, or use the fronted classes on their own — same code, no action classes, no static calls.
JWS tokens
Sign and strictly verify compact and flattened JWS across HS, RS, ES and EdDSA, with typed claims and opt-in expiry checks.
Signers & algorithms
HS, RS, ES and EdDSA signers pinned to exactly one algorithm each, key-driven verification and the ECDSA DER codec.
Loading & generating keys
Validated key types with zero-config factories, disk and config loaders, generators, load-or-generate and PEM export.
JWK & thumbprints
Serialize public keys as RFC 7517 JWKs and back, compute RFC 7638 thumbprints for ACME, and parse untrusted JWKs strictly.
X.509 certificates & chains
Read certificate facts — names, fingerprints, validity, keys and raw extensions — and prove chain linkage. Trust stays yours.
ASN.1 / DER decoder
A strict, bounded X.690 DER reader for the raw certificate-extension bytes that openssl_x509_parse() can’t give you.
WebAuthn verification
Parse authenticator data and COSE keys with a canonical CBOR decoder, then verify passkey signatures across ES, RS and EdDSA.
TOTP & HOTP
RFC 6238 TOTP and RFC 4226 HOTP with a timing-flat drift window, plus the otpauth:// URI authenticator apps enrol from.
HMAC & hashing
HMAC webhook signatures, deterministic digests with an optional pepper, and constant-time comparison.
Authenticated encryption
AES-256-GCM (RFC 5116) with associated data that binds each ciphertext to its record or purpose — seal and open, keys, nonces and failures.
Random tokens & secrets
CSPRNG bytes, URL-safe, numeric and alphanumeric tokens, custom alphabets and base32 OTP secrets — bounded at both ends.
Codecs
Strict base64url, padded base64, base32 and hex — canonical-only decoding that rejects malformed input instead of mangling it.
Exceptions
Every failure is a typed subtype of CryptoException — catch broadly or precisely, and re-wrap at your own boundary.
Testing
Why there is no Crypto::fake(), plus ready-made test keys, known OTP vectors, throwaway certificate chains and opt-in Pest expectations.
Requirements
PHP 8.4+, Laravel 12 or 13, and ext-openssl, ext-hash and ext-mbstring; ext-sodium only for EdDSA.
Show your open-source love
This package is free and MIT-licensed. If it saves you time, a one-off donation or a Patreon membership keeps it maintained, tested and documented.
More ways to support, including cryptoBy donating, you agree to our donation terms.
Want this built into your product?
We integrate our packages into custom Laravel and AI builds. Tell us what you're working on and we'll reply within 48 hours.