Open source
JWT for Laravel
composer require roundly-consulting/jwt-for-laravelOverview
Native JSON Web Tokens for Laravel. Mint RS256 user tokens on your login app and verify them offline in every other service with only the public key; sign short-lived HS256 service tokens for machine-to-machine calls. Drop-in jwt and service-jwt guards, a self-evicting jti denylist and claim-based authorization plug straight into Laravel’s auth. MIT-licensed, with zero third-party crypto — the JOSE core runs on PHP’s own ext-openssl through our audited crypto-for-laravel.
What you get
RS256 user tokens
Mint on the issuer app that holds the private key; verify offline anywhere with only the public PEM.
HS256 service tokens
Short-lived machine-to-machine tokens with shared or per-issuer secrets, plus a helper for outbound HTTP calls.
Drop-in guards
jwt and service-jwt drivers for config/auth.php — claims mode or Eloquent provider mode, several guards isolated by audience.
One-call logout
A cache-backed jti denylist that evicts itself at exp + leeway, plus token versions to log a user out everywhere.
Claim-based authorization
Permissions baked into the token feed Laravel’s Gate — can() checks with no database query.
Hardened, zero third-party crypto
Algorithm pinning, constant-time HMAC, key-size checks and mandatory iss/aud pins — on PHP’s own ext-openssl via our crypto-for-laravel.
Facade, DI & a recording fake
Jwt::guard() and Jwt::services() handles, an injectable JwtManager, and Jwt::fake() with in-memory keys and actingAs().
Documentation
Installation
Install via Composer, publish the config and generate an RSA keypair on issuer apps — verify-only apps need just the public key.
Configuration
Every config/jwt.php key with its env var and default — keys, pins, lifetimes, guard defaults, denylist and service tokens.
The Jwt facade
One entry point to mint, verify and log out, with Jwt::guard() and Jwt::services() handles, JWKS publishing and a recording fake.
DI and actions
Skip the facade: inject JwtManager for the same API without static calls, or resolve the contracts behind it — there are no action classes.
Minting user tokens
Mint RS256 access tokens with the fluent AccessTokenRequest, plus challenge, email-verify and custom-scope tokens.
Verifying tokens
Verify RS256 user tokens offline with only the public key, read claims through typed accessors and handle failures.
Guards
Wire the jwt and service-jwt guard drivers — claims mode or Eloquent provider mode, the request pipeline and token-version checks.
Multiple guards
Run several jwt guards — users, clients — each isolated by its own audience, with per-guard scope, identity and denylist options.
Service tokens
Short-lived HS256 machine-to-machine tokens: issue them, attach them to outbound HTTP calls, pick a secret mode and verify inbound calls.
Logout & denylist
Log users out by denylisting a token’s jti — a cache-backed store that evicts each entry once the token can no longer verify.
Claim-based authorization
Grant abilities straight from the token’s permissions claim through Laravel’s Gate — can() checks with no database query.
Events
Four lifecycle events — user and service token issued, verification failed, token denied — with safe metadata only.
Artisan commands
Generate a 2048-bit RSA keypair with jwt:generate-keys and inspect the token setup with php artisan about.
Security model
What the package enforces for you — algorithm pinning, key and secret strength, mandatory pins, size caps and fail-closed defaults.
Exceptions
The JwtException hierarchy for token failures, and the misconfiguration exceptions that surface as a 500 instead of a 401.
Extending
Rebind any contract — issuer, verifier, service tokens, denylist — and plug in your own claims-mode identity class.
Testing
Jwt::fake() records every mint, service token and deny over in-memory keys, with actingAs() — or test against a real keypair.
Requirements
PHP 8.4+, Laravel 12 or 13, and the ext-openssl and ext-json extensions. Composer pulls in the crypto, enums and package toolkit packages.
Show your open-source love
This package is free and MIT-licensed. If it saves you time, a one-off donation or a Patreon membership keeps it maintained, tested and documented.
More ways to support, including cryptoBy donating, you agree to our donation terms.
Want this built into your product?
We integrate our packages into custom Laravel and AI builds. Tell us what you're working on and we'll reply within 48 hours.