Installation
Require the package, then publish and run the migration. Migrations are publish-only — the package does not load them — and the service provider and the RefreshTokens facade are auto-discovered:
composer require roundly-consulting/refresh-tokens-for-laravel
php artisan vendor:publish --tag="refresh-tokens-migrations"
php artisan migrateIf your owner models are UUID- or ULID-keyed, set key_type before you migrate — the owner_id column is baked into the schema:
REFRESH_TOKENS_KEY_TYPE=ulidThe config file is optional — every key has an env-backed default. Publish it only to override:
php artisan vendor:publish --tag="refresh-tokens-config"Add the trait
Add HasRefreshTokens to every model that holds sessions — any Authenticatable Eloquent model. Each owner model is an isolated account type in the same table:
use Illuminate\Foundation\Auth\User as Authenticatable;
use RoundlyConsulting\RefreshTokens\Traits\HasRefreshTokens;
final class User extends Authenticatable
{
use HasRefreshTokens;
}
final class Client extends Authenticatable // a second, isolated account type
{
use HasRefreshTokens;
}The only publish tags the package exposes are refresh-tokens-migrations and refresh-tokens-config. Its companion packages — crypto-for-laravel, enums-for-laravel and package-toolkit-for-laravel — are installed automatically and need no configuration.
Show your open-source love
This package is free and MIT-licensed. If it saves you time, a one-off donation or a Patreon membership keeps it maintained, tested and documented.
More ways to support, including cryptoBy donating, you agree to our donation terms.
Want this built into your product?
We integrate our packages into custom Laravel and AI builds. Tell us what you're working on and we'll reply within 48 hours.