NewWe open-sourced 50+ Laravel packages
Custom AI apps, agents and automation — Roundly ConsultingRoundly
All packages
JWT for Laravel

Security model

Two token families, strictly separated by algorithm and purpose: RS256 user tokens minted by issuer apps and verified everywhere with the public PEM, and HS256 service tokens for machine-to-machine calls only. On top of that:

  • Single-algorithm pinning — alg:none and RS256↔HS256 confusion are structurally impossible.
  • Constant-time HMAC comparison.
  • PEM-as-HMAC rejection — a public key can never be smuggled in as an HMAC secret.
  • HMAC secrets must be at least 32 random bytes (256 bits); a single repeated byte is rejected.
  • RSA keys are checked for type and size — at least 2048 bits.
  • Mandatory iss/aud pinning — an empty pin is a hard misconfiguration, never a vacuous match.
  • Per-call clock leeway with no global state.
  • The crit header is rejected; a present typ must be JWT (RFC 8725 explicit typing).
  • Any token over 8 KB is rejected before decoding.
  • A fail-closed denylist — a token with no jti can never authenticate while denylisting is on.
  • Registered claims always win over caller-supplied extras — overwritten on user tokens, rejected on service tokens — so extra claims can’t spoof identity.
  • Misconfiguration always surfaces as a 500 — a missing key or secret never masquerades as a silent 401.

Zero third-party crypto

The JOSE core — compact JWS signing and verification, base64url, RSA and HMAC key handling — comes from our own crypto-for-laravel, built on PHP’s ext-openssl and hash_hmac. This package owns the JWT policy: claims, guards, denylist and service-token issuer binding. Crypto failures are translated at the boundary, so you keep catching the package’s own exceptions.

Standards-based parity

Verification compatibility with standard JWS/JWT tokens is proven by committed static parity fixtures and the RFC 7515 example vectors, with zero third-party JWT or crypto libraries in composer.json. Architecture tests keep src/ free of third-party JWT dependencies and assert that no crypto primitive is re-implemented in the package.

Out of scope

The package deliberately does not implement refresh-token rotation, 2FA code generation, passkeys, remote key discovery, multi-key kid selection, ES256/EdDSA, JWE encryption or token introspection. It issues and verifies tokens — and publishes its own key with Jwt::jwks() for the route you define.

Show your open-source love

This package is free and MIT-licensed. If it saves you time, a one-off donation or a Patreon membership keeps it maintained, tested and documented.

More ways to support, including crypto

By donating, you agree to our donation terms.

Want this built into your product?

We integrate our packages into custom Laravel and AI builds. Tell us what you're working on and we'll reply within 48 hours.