NewWe open-sourced 50+ Laravel packages
Custom AI apps, agents and automation — Roundly ConsultingRoundly
All packages
Refresh Tokens for Laravel

Access-token revocation

By default the package binds a no-op revoker (NullAccessTokenRevoker), so it works standalone. Bind your own adapter to deny access tokens when a session or family is revoked:

use RoundlyConsulting\RefreshTokens\Contracts\AccessTokenRevoker;

$this->app->singleton(AccessTokenRevoker::class, DenylistAccessTokenRevoker::class);

final class DenylistAccessTokenRevoker implements AccessTokenRevoker
{
    public function revoke(#[\SensitiveParameter] string $accessReference): void
    {
        // e.g. add $accessReference to your jwt jti denylist until its TTL expires
    }
}

The package calls revoke() with the row’s access_reference — the value you passed as accessReference on issue or rotation — for every live access reference a revocation kills: logout, revoke-all, session revoke, and the family sweep on reuse detection. php artisan about shows whether a real revoker is BOUND.

Show your open-source love

This package is free and MIT-licensed. If it saves you time, a one-off donation or a Patreon membership keeps it maintained, tested and documented.

More ways to support, including crypto

By donating, you agree to our donation terms.

Want this built into your product?

We integrate our packages into custom Laravel and AI builds. Tell us what you're working on and we'll reply within 48 hours.