NewWe open-sourced 50+ Laravel packages
Custom AI apps, agents and automation — Roundly ConsultingRoundly
All packages
JWT for Laravel

Artisan commands

jwt:generate-keys

php artisan jwt:generate-keys          # writes both PEMs; refuses to overwrite
php artisan jwt:generate-keys --force  # overwrite existing keys
  • Writes the keys to jwt.private_key_path and jwt.public_key_path — by default storage/jwt-private.key and storage/jwt-public.pem. It fails with a clear error if either path is not set (null or blank).
  • Refuses to overwrite existing keys without --force, so you can’t clobber live keys.
  • Creates missing parent directories and resolves relative paths from the application root.
  • Writes the private key with 0600 permissions, locked down before any key material lands in it.

Copy the public key to every verify-only service’s JWT_PUBLIC_KEY_PATH; keep the private key on the issuer.

php artisan about

php artisan about --only=jwt

The package adds a Jwt section reporting the algorithms, whether the signing and verification key files exist (SET / MISSING), whether the issuer and audience are SET or MISSING, the access-token TTL, the service-token mode (per-issuer secrets, shared secret or no secret) and whether the denylist check and claim authorization are ON. It never prints key material, secrets or key paths.

Show your open-source love

This package is free and MIT-licensed. If it saves you time, a one-off donation or a Patreon membership keeps it maintained, tested and documented.

More ways to support, including crypto

By donating, you agree to our donation terms.

Want this built into your product?

We integrate our packages into custom Laravel and AI builds. Tell us what you're working on and we'll reply within 48 hours.