Rendering the QR code
This package never renders a QR image — it hands you $setup->provisioningUri. Draw it wherever suits your stack; two-factor itself ships no image library.
Server-side (SVG)
Install our native qr-for-laravel — an optional suggestion, never installed by this package — and render the URI in one call:
composer require roundly-consulting/qr-for-laraveluse RoundlyConsulting\Qr\Enums\ErrorCorrection;
use RoundlyConsulting\Qr\Facades\Qr;
$setup = TwoFactor::for($user)->start();
$svg = Qr::otpauth($setup->provisioningUri)
->size(240)
->errorCorrection(ErrorCorrection::Medium)
->title(__('Scan with your authenticator app'))
->svg();
// Blade: {{ $svg }} — renders the SVG markup; show {{ $setup->issuer }} next to it
// JSON API: ['qr' => $svg->toDataUri(), 'issuer' => $setup->issuer]
// Controller: return $svg; — an image/svg+xml response
// Raw markup: $svg->toString()Qr::otpauth() encodes the URI unchanged and treats it as a secret: never memoised or cached, served with Cache-Control: no-store and no ETag. The code carries the TOTP secret — show it on the enrolment screen only; never persist, log or e-mail the SVG.
Client-side
Pass $setup->provisioningUri to your front end and draw it there (e.g. qrcode.js, react-qr-code). Send it over the same authenticated response as the rest of the enrolment screen, and don’t keep it once enrolment is confirmed.
Show your open-source love
This package is free and MIT-licensed. If it saves you time, a one-off donation or a Patreon membership keeps it maintained, tested and documented.
More ways to support, including cryptoBy donating, you agree to our donation terms.
Want this built into your product?
We integrate our packages into custom Laravel and AI builds. Tell us what you're working on and we'll reply within 48 hours.