NewWe open-sourced 50+ Laravel packages
Custom AI apps, agents and automation — Roundly ConsultingRoundly
All packages

Require the package, then publish and run the migration. Migrations are publish-only — the package does not load them — and the service provider and the RefreshTokens facade are auto-discovered:

composer require roundly-consulting/refresh-tokens-for-laravel

php artisan vendor:publish --tag="refresh-tokens-migrations"
php artisan migrate

If your owner models are UUID- or ULID-keyed, set key_type before you migrate — the owner_id column is baked into the schema:

REFRESH_TOKENS_KEY_TYPE=ulid

The config file is optional — every key has an env-backed default. Publish it only to override:

php artisan vendor:publish --tag="refresh-tokens-config"

Add the trait

Add HasRefreshTokens to every model that holds sessions — any Authenticatable Eloquent model. Each owner model is an isolated account type in the same table:

use Illuminate\Foundation\Auth\User as Authenticatable;
use RoundlyConsulting\RefreshTokens\Traits\HasRefreshTokens;

final class User extends Authenticatable
{
    use HasRefreshTokens;
}

final class Client extends Authenticatable   // a second, isolated account type
{
    use HasRefreshTokens;
}

The only publish tags the package exposes are refresh-tokens-migrations and refresh-tokens-config. Its companion packages — crypto-for-laravel, enums-for-laravel and package-toolkit-for-laravel — are installed automatically and need no configuration.

Show your open-source love

This package is free and MIT-licensed. If it saves you time, a one-off donation or a Patreon membership keeps it maintained, tested and documented.

More ways to support, including crypto

By donating, you agree to our donation terms.

Want this built into your product?

We integrate our packages into custom Laravel and AI builds. Tell us what you're working on and we'll reply within 48 hours.