All packages
Sentinel for Laravel
Standards
Which standards Sentinel implements and how (baseline verified on 2 October 2026):
| Standard | Applied as |
|---|---|
| RFC 2104 / FIPS 198-1 (HMAC) | HMAC via crypto; seal subkeys HKDF-derived with length = hash output. |
| NIST SP 800-107r1 | Key length ≥ the security strength; field tags truncated to 128 bits. |
| NIST SP 800-131A r2 | HMAC keys < 112 bits disallowed — Sentinel requires ≥ 256 bits of root key. |
| NIST SP 800-57 Pt 1 r5 | Cryptoperiods → activates_at / signs_until / verifies_until; revocation is separate. |
| FIPS 186-5 + RFC 8032 | ECDSA P-256/P-384 and EdDSA Ed25519 as approved signature schemes. |
| RFC 5869 (HKDF) | Per-purpose subkeys; Appendix A vectors as known-answer tests. |
| RFC 8785 (JCS) | Canonical JSON serialization (deviation: exact integers). |
| RFC 8725 (JWT BCP) §3.1–3.2 | Pin the algorithm per key, never trust a stored or received alg, no none. |
| RFC 9421 (HTTP Message Signatures) | Inbound/outbound profile; Appendix B.2.4–B.2.6 as known-answer tests, B.2.1–B.2.3 (rsa-pss-sha512) rejected as unsupported. |
| RFC 9530 (Digest Fields) | Content-Digest with sha-256 / sha-512; deprecated algorithms ignored. |
| RFC 9651 (Structured Fields) | Own parser and serializer, validated against the httpwg structured-field-tests suite. |
| RFC 9457 (Problem Details) | application/problem+json for idempotency and signature rejections. |
| draft-ietf-httpapi-idempotency-key-header-07 | An expired Internet-Draft: Idempotency-Key as an sf-string; POST/PATCH; 400 / 422 / 409; documented expiry; Idempotent-Replayed as the de-facto replay header. |
| OWASP ASVS 5.0 V11 | Key lifecycle and inventory, validated implementations, crypto agility, ≥ 128-bit security, constant-time compares, fail secure, CSPRNG nonces, approved signature algorithms. |
| OWASP ASVS 5.0 V2.3 | Business-logic atomicity and double-submission resistance → idempotency keys + locking. |
How it is proven
- Every row of the detection matrix is encoded in a test, in both columns — database only and with an anchor.
- A property test runs 200 seeded sequences of 25 random operations — writes, tampering, seal deletion, snapshot restores, acknowledgements, rotations, re-seals, deletes, checkpoints and ledger checks — against a pure reference model, comparing statuses, versions and ledger findings after every step.
- Real-engine tests race eight forked processes on PostgreSQL and MySQL: seals, first seals, idempotency keys, nonces, client nonces, checkpoints and row locks.
- Architecture tests pin that only one class calls hash_hkdf, only one reads the time, crypto primitives live in three classes, constant-time compares go through crypto, and internals are marked @internal.
- Coverage is gated at 95 % overall and 100 % on Actions, Canonical, Engine, Http\Signatures, Http\StructuredFields, Keys and Ledger.
- A secret-hygiene suite asserts that no secret reaches exceptions, logs, about, dumps, serialization, events or command output, and that every material-bearing parameter carries #[\SensitiveParameter].
Show your open-source love
This package is free and MIT-licensed. If it saves you time, a one-off donation or a Patreon membership keeps it maintained, tested and documented.
More ways to support, including cryptoBy donating, you agree to our donation terms.
Want this built into your product?
We integrate our packages into custom Laravel and AI builds. Tell us what you're working on and we'll reply within 48 hours.