Artisan commands
Dead rows — revoked or expired longer ago than prune.after — are force-deleted by RefreshTokens::prune() or the refresh-tokens:prune command (a thin shell over it). The package does not self-schedule; you schedule it:
// routes/console.php
use Illuminate\Support\Facades\Schedule;
Schedule::command('refresh-tokens:prune')->daily();php artisan refresh-tokens:prune # uses config('refresh-tokens.prune.after')
php artisan refresh-tokens:prune --days=7 # override retention (min 1)RefreshTokens::prune(); // int — uses config('refresh-tokens.prune.after')
RefreshTokens::prune(days: 7); // override retention- refresh-tokens:prune — force-deletes dead rows and reports how many it removed.
- --days / days: — overrides the retention; it must be an integer of at least 1 (0 or a non-integer is rejected, prune(0) throws InvalidTokenConfigurationException, and so does a configured prune.after below 1).
- about --only=refresh-tokens — prints the secret-safe configuration summary.
Why the one-day floor: pruning tokens revoked minutes ago would destroy reuse-detection evidence — a rotated token pruned right after revocation, then re-presented by a thief, finds no row and fires no family revoke. Keep the retention comfortably longer than your access-token TTL.
Using model:prune
The model is Prunable, so Laravel’s own command works too — its prunable() query reads the same prune.after window. But a bare php artisan model:prune only discovers models under app/Models, so it never finds the package’s model. Name it — or your subclass, if you swapped refresh-tokens.model:
php artisan model:prune --model="RoundlyConsulting\RefreshTokens\Models\RefreshToken"If you schedule model:prune for your own models as well, run refresh-tokens:prune alongside it rather than relying on discovery.
Show your open-source love
This package is free and MIT-licensed. If it saves you time, a one-off donation or a Patreon membership keeps it maintained, tested and documented.
More ways to support, including cryptoBy donating, you agree to our donation terms.
Want this built into your product?
We integrate our packages into custom Laravel and AI builds. Tell us what you're working on and we'll reply within 48 hours.