Claim-based authorization
Set authorize_from_claims to true (JWT_AUTHORIZE_FROM_CLAIMS=true) and abilities listed in the token’s permissions claim are granted through a Gate::before hook:
JWT_AUTHORIZE_FROM_CLAIMS=true// Issuer: bake the abilities into the token.
Jwt::mintAccessToken(
AccessTokenRequest::for($user->id)->permissions('posts.view', 'posts.edit')
);
// Any verifying service, claims mode:
if ($request->user()->can('posts.edit')) {
// allowed straight from the token's permissions claim
}
Route::middleware(['auth:api', 'can:posts.edit'])->post('/posts', StorePostController::class);The hook returns null, not false, on a miss, so your own gates and policies still run.
Which identities participate
- Claims mode — the user is a TokenUser (or any identity implementing RoundlyConsulting\Jwt\UserTokens\Contracts\ChecksPermissions, see Extending), which answers from its own claims: can() works for that user wherever it is checked.
- Provider mode — the user is your Eloquent model, so the hook reads the permissions claim of the token that authenticated it on the request’s active guard (the one auth:<guard> selected, or Auth::shouldUse()).
In provider mode it grants only to that exact user instance: a copy of the same user loaded separately (Gate::forUser(User::find($id))), a user set without a token (actingAs($user, 'api')) or a mistyped permissions claim gets nothing from the token.
Show your open-source love
This package is free and MIT-licensed. If it saves you time, a one-off donation or a Patreon membership keeps it maintained, tested and documented.
More ways to support, including cryptoBy donating, you agree to our donation terms.
Want this built into your product?
We integrate our packages into custom Laravel and AI builds. Tell us what you're working on and we'll reply within 48 hours.