Installation
Require the package with Composer. The service provider and the global Crypto facade alias are auto-discovered — there is no config file to publish, no migration to run and nothing to wire:
composer require roundly-consulting/crypto-for-laravelWhat the service provider registers
The provider is deliberately minimal and never constructs an object that holds a secret. It registers the stateless, key-less services as container singletons, so you can resolve or inject them:
- Jose\Jws — compact and flattened JWS signing and verification.
- Cose\CborDecoder and Asn1\DerDecoder — the strict CBOR and DER parsers.
- Signature\KeyVerifier — key-driven signature verification.
- CryptoManager — the target behind the Crypto facade.
use RoundlyConsulting\Crypto\CryptoManager;
use RoundlyConsulting\Crypto\Jose\Jws;
use RoundlyConsulting\Crypto\Signature\KeyVerifier;
// Key-less, stateless services are container singletons — resolve or inject them:
$jws = app(Jws::class);
$verifier = app(KeyVerifier::class);
$crypto = app(CryptoManager::class); // the Crypto facade targetAnything keyed — an Hs, Rs, Es or EdDSA signer — is built by your own service provider from your own config. See Zero-config design.
Verify the install
The package adds a Crypto section to php artisan about. It reports capabilities only — never key material, a secret or a path — including whether EdDSA is available on this host:
php artisan about # "Crypto" section: JOSE / JWS, JWK / X.509, EdDSA (Ed25519)Show your open-source love
This package is free and MIT-licensed. If it saves you time, a one-off donation or a Patreon membership keeps it maintained, tested and documented.
More ways to support, including cryptoBy donating, you agree to our donation terms.
Want this built into your product?
We integrate our packages into custom Laravel and AI builds. Tell us what you're working on and we'll reply within 48 hours.