NewWe open-sourced 50+ Laravel packages
Custom AI apps, agents and automation — Roundly ConsultingRoundly
All packages

Which standards Sentinel implements and how (baseline verified on 2 October 2026):

StandardApplied as
RFC 2104 / FIPS 198-1 (HMAC)HMAC via crypto; seal subkeys HKDF-derived with length = hash output.
NIST SP 800-107r1Key length ≥ the security strength; field tags truncated to 128 bits.
NIST SP 800-131A r2HMAC keys < 112 bits disallowed — Sentinel requires ≥ 256 bits of root key.
NIST SP 800-57 Pt 1 r5Cryptoperiods → activates_at / signs_until / verifies_until; revocation is separate.
FIPS 186-5 + RFC 8032ECDSA P-256/P-384 and EdDSA Ed25519 as approved signature schemes.
RFC 5869 (HKDF)Per-purpose subkeys; Appendix A vectors as known-answer tests.
RFC 8785 (JCS)Canonical JSON serialization (deviation: exact integers).
RFC 8725 (JWT BCP) §3.1–3.2Pin the algorithm per key, never trust a stored or received alg, no none.
RFC 9421 (HTTP Message Signatures)Inbound/outbound profile; Appendix B.2.4–B.2.6 as known-answer tests, B.2.1–B.2.3 (rsa-pss-sha512) rejected as unsupported.
RFC 9530 (Digest Fields)Content-Digest with sha-256 / sha-512; deprecated algorithms ignored.
RFC 9651 (Structured Fields)Own parser and serializer, validated against the httpwg structured-field-tests suite.
RFC 9457 (Problem Details)application/problem+json for idempotency and signature rejections.
draft-ietf-httpapi-idempotency-key-header-07An expired Internet-Draft: Idempotency-Key as an sf-string; POST/PATCH; 400 / 422 / 409; documented expiry; Idempotent-Replayed as the de-facto replay header.
OWASP ASVS 5.0 V11Key lifecycle and inventory, validated implementations, crypto agility, ≥ 128-bit security, constant-time compares, fail secure, CSPRNG nonces, approved signature algorithms.
OWASP ASVS 5.0 V2.3Business-logic atomicity and double-submission resistance → idempotency keys + locking.

How it is proven

  • Every row of the detection matrix is encoded in a test, in both columns — database only and with an anchor.
  • A property test runs 200 seeded sequences of 25 random operations — writes, tampering, seal deletion, snapshot restores, acknowledgements, rotations, re-seals, deletes, checkpoints and ledger checks — against a pure reference model, comparing statuses, versions and ledger findings after every step.
  • Real-engine tests race eight forked processes on PostgreSQL and MySQL: seals, first seals, idempotency keys, nonces, client nonces, checkpoints and row locks.
  • Architecture tests pin that only one class calls hash_hkdf, only one reads the time, crypto primitives live in three classes, constant-time compares go through crypto, and internals are marked @internal.
  • Coverage is gated at 95 % overall and 100 % on Actions, Canonical, Engine, Http\Signatures, Http\StructuredFields, Keys and Ledger.
  • A secret-hygiene suite asserts that no secret reaches exceptions, logs, about, dumps, serialization, events or command output, and that every material-bearing parameter carries #[\SensitiveParameter].

Show your open-source love

This package is free and MIT-licensed. If it saves you time, a one-off donation or a Patreon membership keeps it maintained, tested and documented.

More ways to support, including crypto

By donating, you agree to our donation terms.

Want this built into your product?

We integrate our packages into custom Laravel and AI builds. Tell us what you're working on and we'll reply within 48 hours.