DEV Community
Follow
Auth for Laravel — headless multi-guard login with 2FA, passkeys and JWT sessions
Auth for Laravel is an open-source package designed for headless account authentication in API-backed Laravel applications, addressing common security vulnerabilities found in custom implementations. It offers four sign-in methods: password, magic link, email code, and passkey, alongside a robust challenge engine for two-factor authentication, including forced enrollment. The package provides RS256 access tokens with rotating refresh tokens, granular device session management, and features like registration, invitations, email verification, and password resets. It includes a login-activity log, throttling, new-device alerts, and customizable risk rule hooks.Auth for Laravel supports separate guards for different account types (users, clients, staff), each with independent models, configurations, endpoints, and JWT audiences. JSON endpoints are opt-in and configurable per guard, with every state change triggering an event for extensibility. Installation involves a few composer and artisan commands, which publish necessary configurations and migrations, with an install checker for troubleshooting. Developers integrate the package by making their guard's model implement specific authentication contracts and traits.Logging in returns a token pair or a challenge for two-factor authentication, which can be completed using various methods like TOTP codes or passkeys. The package ensures single-use challenges stored as HMAC hashes and counts code attempts before verification to prevent parallel guessing attacks. Route configuration is flexible, allowing customization of prefixes, names, and middleware for each guard, with routes only active if their corresponding feature is enabled.Auth for Laravel carefully handles security defaults: login attempts for unregistered addresses return the same response, throttling occurs before password hashing, and sensitive links/codes are single-use hashes. By default, changes to passwords, emails, or two-factor settings invalidate other sessions, and reusing rotated refresh tokens leads to session termination and alerts. Testing is designed to hit real guards and token checks, and the package provides helpers for acting as an account in tests.While social login and SSO are not built-in, existing SSO callbacks can issue tokens through the package's API. The package requires PHP ^8.4, Laravel 12 or 13, a cache store with atomic locks, and a mail transport. It is MIT licensed, with dependencies primarily limited to Laravel, Symfony, and other Roundly packages.