NewWe open-sourced 50+ Laravel packages
Custom AI apps, agents and automation — Roundly ConsultingRoundly
All packages

Open source

Crypto for Laravel

Install
composer require roundly-consulting/crypto-for-laravel
Requires: PHP ^8.4 · Laravel ^12.0|^13.0

Overview

Native cryptographic and encoding primitives for Laravel — JWS signing with strict verification, JWK thumbprints, X.509 certificate facts, a strict DER decoder, TOTP/HOTP, WebAuthn signature verification, HMAC, AES-256-GCM authenticated encryption, CSPRNG tokens and strict codecs. It is zero-config and à la carte: no config file, no env reads, every key is an explicit argument, and each primitive works on its own or through a single Crypto facade. Parity with the RFCs is proven by committed test vectors, and it is built only on PHP’s native crypto extensions plus Laravel and Symfony — no third-party crypto library. MIT licensed.

What you get

JWS with pinned algorithms

Compact and flattened JWS across HS, RS, ES and EdDSA — the algorithm is pinned before the signature is ever read.

JWK & X.509 facts

RFC 7517 JWKs with RFC 7638 thumbprints, plus certificate and chain facts. The math is proven; the trust decision stays yours.

TOTP & HOTP

RFC 6238 and RFC 4226 one-time passwords with a timing-flat drift window and otpauth:// enrolment URIs.

WebAuthn verification

A canonical CBOR decoder, COSE key parsing and authenticator data for passkey signature checks.

HMAC, encryption & CSPRNG

Webhook HMAC, peppered digests, constant-time compares, AES-256-GCM encryption bound to its context, and length-bounded random tokens.

Strict codecs & DER

Canonical-only base64url, base64, base32 and hex, plus a bounded X.690 DER decoder for raw extension bytes.

Facade, DI or à la carte

One Crypto facade, an injectable CryptoManager, or each class on its own — no config file, no env reads, keys are explicit arguments.

Documentation

Installation

Install via Composer — the service provider and the Crypto facade auto-register, with no config file, migrations or wiring.

Zero-config design

No config file and no env reads — keys are explicit arguments, and keyed signers are wired in your own service provider.

The Crypto facade

One entry point for the whole toolbox — flat methods plus the keys(), random(), x509() and ecDer() sub-accessors, with a full method table.

DI and direct classes

Inject CryptoManager instead of calling the facade, or use the fronted classes on their own — same code, no action classes, no static calls.

JWS tokens

Sign and strictly verify compact and flattened JWS across HS, RS, ES and EdDSA, with typed claims and opt-in expiry checks.

Signers & algorithms

HS, RS, ES and EdDSA signers pinned to exactly one algorithm each, key-driven verification and the ECDSA DER codec.

Loading & generating keys

Validated key types with zero-config factories, disk and config loaders, generators, load-or-generate and PEM export.

JWK & thumbprints

Serialize public keys as RFC 7517 JWKs and back, compute RFC 7638 thumbprints for ACME, and parse untrusted JWKs strictly.

X.509 certificates & chains

Read certificate facts — names, fingerprints, validity, keys and raw extensions — and prove chain linkage. Trust stays yours.

ASN.1 / DER decoder

A strict, bounded X.690 DER reader for the raw certificate-extension bytes that openssl_x509_parse() can’t give you.

WebAuthn verification

Parse authenticator data and COSE keys with a canonical CBOR decoder, then verify passkey signatures across ES, RS and EdDSA.

TOTP & HOTP

RFC 6238 TOTP and RFC 4226 HOTP with a timing-flat drift window, plus the otpauth:// URI authenticator apps enrol from.

HMAC & hashing

HMAC webhook signatures, deterministic digests with an optional pepper, and constant-time comparison.

Authenticated encryption

AES-256-GCM (RFC 5116) with associated data that binds each ciphertext to its record or purpose — seal and open, keys, nonces and failures.

Random tokens & secrets

CSPRNG bytes, URL-safe, numeric and alphanumeric tokens, custom alphabets and base32 OTP secrets — bounded at both ends.

Codecs

Strict base64url, padded base64, base32 and hex — canonical-only decoding that rejects malformed input instead of mangling it.

Exceptions

Every failure is a typed subtype of CryptoException — catch broadly or precisely, and re-wrap at your own boundary.

Testing

Why there is no Crypto::fake(), plus ready-made test keys, known OTP vectors, throwaway certificate chains and opt-in Pest expectations.

Requirements

PHP 8.4+, Laravel 12 or 13, and ext-openssl, ext-hash and ext-mbstring; ext-sodium only for EdDSA.

Show your open-source love

This package is free and MIT-licensed. If it saves you time, a one-off donation or a Patreon membership keeps it maintained, tested and documented.

More ways to support, including crypto

By donating, you agree to our donation terms.

Want this built into your product?

We integrate our packages into custom Laravel and AI builds. Tell us what you're working on and we'll reply within 48 hours.