NewWe open-sourced 50+ Laravel packages
Custom AI apps, agents and automation — Roundly ConsultingRoundly
All packages

The package dispatches five synchronous events in RoundlyConsulting\Passkeys\Events. Each carries only safe identifiers through the Passkey model — never key material:

EventPayloadFired when
PasskeyRegistered$passkeyA registration verified and the credential was persisted.
PasskeyAuthenticated$passkeyAn assertion verified successfully.
PasskeySignCountRegressed$passkey, $stored, $receivedThe counter didn’t advance and sign_count_policy is flag.
PasskeyRevoked$passkeyAfter revoke() soft-deleted the credential.
PasskeyRenamed$passkey, $previousNameAfter rename() saved the new name.

Listen the usual Laravel way:

use Illuminate\Support\Facades\Event;
use RoundlyConsulting\Passkeys\Events\PasskeyAuthenticated;
use RoundlyConsulting\Passkeys\Events\PasskeyRenamed;
use RoundlyConsulting\Passkeys\Events\PasskeyRevoked;
use RoundlyConsulting\Passkeys\Events\PasskeySignCountRegressed;

Event::listen(function (PasskeyAuthenticated $event): void {
    $user = $event->passkey->authenticatable;
    // audit-log a successful passkey sign-in
});

Event::listen(function (PasskeySignCountRegressed $event): void {
    // possible cloned authenticator — alert / lock / require re-enrolment
    logger()->warning('Passkey counter regressed', [
        'passkey' => $event->passkey->id,
        'stored' => $event->stored,
        'received' => $event->received,
    ]);
});

Event::listen(function (PasskeyRevoked $event): void {
    // e.g. end sessions established with this credential, notify the owner
});

Event::listen(function (PasskeyRenamed $event): void {
    // audit: $event->previousName → $event->passkey->name
});

PasskeySignCountRegressed fires only under the flag policy; under reject the regression throws SignCountRegression instead. The stored counter is never lowered, so a cloned authenticator is flagged on every assertion it makes, not just the first. Passkeys::fake() fires PasskeyRevoked and PasskeyRenamed too, so listeners stay testable.

Show your open-source love

This package is free and MIT-licensed. If it saves you time, a one-off donation or a Patreon membership keeps it maintained, tested and documented.

More ways to support, including crypto

By donating, you agree to our donation terms.

Want this built into your product?

We integrate our packages into custom Laravel and AI builds. Tell us what you're working on and we'll reply within 48 hours.