NewWe open-sourced 50+ Laravel packages
Custom AI apps, agents and automation — Roundly ConsultingRoundly
All packages

Open source

Auth for Laravel

Install
composer require roundly-consulting/auth-for-laravel
Requires: PHP ^8.4 · Laravel ^12.0|^13.0

Overview

Headless, multi-guard account authentication for Laravel APIs. Password, magic-link, email-code and passkey login; a challenge engine for two-factor and forced enrolment; RS256 access tokens with rotating refresh tokens and device sessions; registration, invitations, email verification and password flows — with opt-in JSON endpoints and an event for every state change. It owns no cryptography and no token format: it composes the Roundly jwt, refresh-tokens, two-factor, passkeys, crypto and qr packages and adds the policy and orchestration on top. MIT-licensed, built only on official Laravel components and Roundly packages — no third-party auth vendors.

What you get

Four ways to sign in

Password, magic link, email code and passwordless passkeys — each switchable per guard.

Challenge engine

Multi-step logins with TOTP, recovery-code and passkey second factors, plus forced enrolment during sign-in.

JWT + rotating sessions

RS256 access tokens with amr, auth_time and sid; rotating refresh tokens and per-device sessions you can end one by one.

Isolated guards

Users, clients, staff — each with its own model, audience, throttles, routes and activity. A token of one never works on another.

Sign-up, invites & email

Open, invite-only or closed registration, invitations with payloads, email verification and a verified email change.

Enumeration-safe by design

Identical answers and timing for known and unknown accounts, HMAC’d secrets at rest, throttling and opt-in lockout.

JSON API, facade & events

Opt-in endpoints per guard, the same flows from PHP through the Authentication facade, DI or actions, and an event for every state change.

Documentation

Installation

Install via Composer, generate the JWT keys, run the installer, wire the jwt guard and user provider, prepare the model and run the doctor.

Configuration

Every global and per-guard config key with its default — login methods, 2FA, passkeys, tokens, registration, throttles and more.

Guards

Isolated audiences of accounts — each with its own model, table, JWT audience, sessions, throttles and routes — and how to add one.

Account model

The Account contract, the HasAuthentication trait, the account columns, account lookups and the disable, lock and locale lifecycle.

The Authentication facade

Tour the Authentication facade — per-guard login and session verbs, seven area sub-contexts, scoping rules and login results.

DI and actions

Skip the facade: inject AuthenticationManager or call a single-purpose action with the guard name first — the full facade method → action map.

Login methods

Password, magic link, email code and passwordless passkey login — what each does, how it is throttled and what every login goes through.

Login challenges

The multi-step challenge engine — second factors, passkey steps and forced enrolment, the policy that picks them and how state stays safe.

Tokens & sessions

RS256 access tokens and their claims, rotating refresh tokens, device sessions, logouts and the invalidation policy.

Re-authentication

A “sudo mode” before sensitive actions — available methods, the second-factor strength rule, gated actions and the route middleware.

Two-factor & passkeys

Let signed-in accounts manage TOTP, recovery codes and passkeys — with re-authentication, invalidation, events and notifications.

Registration & invitations

Open, invite-only or closed sign-up with your own fields and account creator, plus invitations with payloads, previews and resend limits.

Email & passwords

One-time links and codes, email verification modes, verified email change, the password policy, breached-password check and reset flows.

Activity & risk

Throttling, opt-in lockout, the login-activity log, new-device detection, pluggable risk assessment and pruning.

Locale & timezone

Negotiate each request’s locale, store the account’s locale and timezone, and send every notification in the account’s language.

HTTP API

Opt-in JSON endpoints per guard — registration, route groups, every endpoint with its request body, response shapes and error codes.

Middleware

Six middleware aliases — bind a guard, require a verified or active account, demand a recent re-authentication and apply the locale.

Events

42 events for every state change — all final readonly, carrying the guard and never a secret. The hooks for audit logs and statistics.

Notifications

18 localizable mail notifications — swap or disable any per guard, deliver after the response or on an encrypted queue.

Extending

Swap claims, account creation, registration rules, risk, QR, locale, breach checks and fingerprints — plus models and resources.

Artisan commands

Install and wire, scaffold new guards, run the configuration doctor, prune old data and log an account out everywhere.

Testing

Act as an account with a real token pair, assert domain events with Event::fake(), and check login activity and token invalidation.

Security

Guard isolation, enumeration safety, single-use secrets, invalidation and recovery safeguards — and the known limits.

Requirements

PHP 8.4+, Laravel 12 or 13, OpenSSL, bcmath and mbstring, an RSA key pair, a cache with atomic locks and a mail transport.

Show your open-source love

This package is free and MIT-licensed. If it saves you time, a one-off donation or a Patreon membership keeps it maintained, tested and documented.

More ways to support, including crypto

By donating, you agree to our donation terms.

Want this built into your product?

We integrate our packages into custom Laravel and AI builds. Tell us what you're working on and we'll reply within 48 hours.