NewWe open-sourced 50+ Laravel packages
Custom AI apps, agents and automation — Roundly ConsultingRoundly
All packages
Crypto for Laravel

DI and direct classes

The facade is the recommended default, not the only way in. Crypto has three equivalent entry points, and all three run the same code:

  • The Crypto facade — the shortest form, used throughout these docs.
  • The manager, RoundlyConsulting\Crypto\CryptoManager — the facade root, injected through the constructor. Same API, an explicit dependency and no static calls.
  • The classes the facade fronts — RsaKey, Jws, Token, Certificate and the rest — called directly. The core factories need no container, config or disk.

Inject the manager

CryptoManager is a final container singleton with no constructor arguments, so the injected instance is the exact object the facade calls:

use RoundlyConsulting\Crypto\CryptoManager;

final class IssueApiToken
{
    public function __construct(private CryptoManager $crypto) {}

    public function __invoke(): string
    {
        return $this->crypto->random()->token(48);
    }
}

// Or resolve it — a container singleton, the exact object the facade calls:
app(CryptoManager::class)->keys()->rsa()->generate(3072);

Call the classes directly

Each class works on its own — the form every feature section shows as the alternative to the facade:

use RoundlyConsulting\Crypto\Jose\Jws;
use RoundlyConsulting\Crypto\Random\Token;
use RoundlyConsulting\Crypto\Signature\Key\RsaKey;
use RoundlyConsulting\Crypto\X509\Certificate;

$key         = RsaKey::private($pem);        // core factories need no container, config or disk
$code        = Token::numeric(6);
$certificate = Certificate::fromDer($der);
$jws         = new Jws;

No action classes

Crypto has no action classes. It is stateless computation, so it exposes plain service objects rather than one action per method: the sub-accessors are final, hold no state, and every method forwards to one static factory. The table maps each facade method to the class it fronts:

Facade methodFronts
jws()new Jose\Jws
jwk() · jwkFromArray() · jwkFromJson()Jwk::fromPublicKey() · Jwk::fromArray() · Jwk::fromJson()
x509()->fromPem() · fromDer() · fromBase64()Certificate::fromPem() · fromDer() · fromBase64()
x509()->chain()->fromX5c() · fromPems() · fromPemBundle() · fromCertificates()Chain::fromX5c() · fromPems() · fromPemBundle() · new Chain()
keys()->rsa() · keys()->ec() · keys()->hmac()RsaKey::… · EcKey::… · HmacSecret::… (same method names)
keys()->ed25519()->public*() · private*() · generate()OkpKey::ed25519*() · fromSecretKey() / secretKeyFrom*() · generate()
hs() · rs() · es() · eddsa() · verifier()new Hs · new Rs · new Es · new EdDSA · new KeyVerifier
ecDer()->fromRaw() · toRaw() · isValid()Der::fromRaw() · Der::toRaw() · Der::isValid()
hmac() · digest() · constantTimeEquals()new Hmac · new Digest · ConstantTime::equals()
aes256Gcm()new Aead\Aes256Gcm
derDecoder() · cbor()new DerDecoder · new CborDecoder
coseKey() · authenticatorData()CoseKey::fromCbor() · AuthenticatorData::parse()
totp() · hotp() · provisioningUri()new Totp · new Hotp · ProvisioningUri::totp()
random()->bytes() · token() · numeric() · alphanumeric() · fromAlphabet() · secret()Bytes::generate() · Token::urlSafe() · Token::numeric() · Token::alphanumeric() · Token::fromAlphabet() · Secret::base32()
base64Url* · base64* · base32* · hex* (Encode / Decode)Base64Url · Base64 · Base32 · Hex — ::encode() / ::decode()

Show your open-source love

This package is free and MIT-licensed. If it saves you time, a one-off donation or a Patreon membership keeps it maintained, tested and documented.

More ways to support, including crypto

By donating, you agree to our donation terms.

Want this built into your product?

We integrate our packages into custom Laravel and AI builds. Tell us what you're working on and we'll reply within 48 hours.