PHPackages                             gemvc/library - PHPackages - PHPackages  [Skip to content](#main-content)[PHPackages](/)[Directory](/)[Categories](/categories)[Trending](/trending)[Leaderboard](/leaderboard)[Changelog](/changelog)[Analyze](/analyze)[Collections](/collections)[Log in](/login)[Sign up](/register)

1. [Directory](/)
2. /
3. [Framework](/categories/framework)
4. /
5. gemvc/library

ActiveLibrary[Framework](/categories/framework)

gemvc/library
=============

Server Agnostic (openSwoole/Nginx/Apache) Rest Api Microservice ready Framework/Library

5.10.0(3w ago)221.4k16MITPHP

Since Aug 18Pushed 3w ago5 watchersCompare

[ Source](https://github.com/gemvc/gemvc)[ Packagist](https://packagist.org/packages/gemvc/library)[ Docs](https://gemvc.de)[ RSS](/packages/gemvc-library/feed)WikiDiscussions main Synced 2w ago

READMEChangelog (10)Dependencies (56)Versions (285)Used By (0)

[![gemvc-tracekit](https://private-user-images.githubusercontent.com/211101824/531768259-c730d3b8-877f-4793-9261-34ca392cf692.jpg?jwt=eyJ0eXAiOiJKV1QiLCJhbGciOiJIUzI1NiJ9.eyJpc3MiOiJnaXRodWIuY29tIiwiYXVkIjoicmF3LmdpdGh1YnVzZXJjb250ZW50LmNvbSIsImtleSI6ImtleTUiLCJleHAiOjE3ODU2NTIxNDAsIm5iZiI6MTc4NTY1MTg0MCwicGF0aCI6Ii8yMTExMDE4MjQvNTMxNzY4MjU5LWM3MzBkM2I4LTg3N2YtNDc5My05MjYxLTM0Y2EzOTJjZjY5Mi5qcGc_WC1BbXotQWxnb3JpdGhtPUFXUzQtSE1BQy1TSEEyNTYmWC1BbXotQ3JlZGVudGlhbD1BS0lBVkNPRFlMU0E1M1BRSzRaQSUyRjIwMjYwODAyJTJGdXMtZWFzdC0xJTJGczMlMkZhd3M0X3JlcXVlc3QmWC1BbXotRGF0ZT0yMDI2MDgwMlQwNjI0MDBaJlgtQW16LUV4cGlyZXM9MzAwJlgtQW16LVNpZ25hdHVyZT1kM2YwYWU4ZTIyZDkyMzVmMWQ2ZTAwMGJkNTk4OTMxOWI4YzY3YTEyY2Y5OTY4Yzg5YTM4MDE3ZDg0YjZlMWVhJlgtQW16LVNpZ25lZEhlYWRlcnM9aG9zdCZyZXNwb25zZS1jb250ZW50LXR5cGU9aW1hZ2UlMkZqcGVnIn0.Hxa1G-kQtS5zLGNU1gy7WexwPdL5b5RwkugvsKLNodw)](https://private-user-images.githubusercontent.com/211101824/531768259-c730d3b8-877f-4793-9261-34ca392cf692.jpg?jwt=eyJ0eXAiOiJKV1QiLCJhbGciOiJIUzI1NiJ9.eyJpc3MiOiJnaXRodWIuY29tIiwiYXVkIjoicmF3LmdpdGh1YnVzZXJjb250ZW50LmNvbSIsImtleSI6ImtleTUiLCJleHAiOjE3ODU2NTIxNDAsIm5iZiI6MTc4NTY1MTg0MCwicGF0aCI6Ii8yMTExMDE4MjQvNTMxNzY4MjU5LWM3MzBkM2I4LTg3N2YtNDc5My05MjYxLTM0Y2EzOTJjZjY5Mi5qcGc_WC1BbXotQWxnb3JpdGhtPUFXUzQtSE1BQy1TSEEyNTYmWC1BbXotQ3JlZGVudGlhbD1BS0lBVkNPRFlMU0E1M1BRSzRaQSUyRjIwMjYwODAyJTJGdXMtZWFzdC0xJTJGczMlMkZhd3M0X3JlcXVlc3QmWC1BbXotRGF0ZT0yMDI2MDgwMlQwNjI0MDBaJlgtQW16LUV4cGlyZXM9MzAwJlgtQW16LVNpZ25hdHVyZT1kM2YwYWU4ZTIyZDkyMzVmMWQ2ZTAwMGJkNTk4OTMxOWI4YzY3YTEyY2Y5OTY4Yzg5YTM4MDE3ZDg0YjZlMWVhJlgtQW16LVNpZ25lZEhlYWRlcnM9aG9zdCZyZXNwb25zZS1jb250ZW50LXR5cGU9aW1hZ2UlMkZqcGVnIn0.Hxa1G-kQtS5zLGNU1gy7WexwPdL5b5RwkugvsKLNodw)

[GEMVC](https://www.gemvc.de) — PHP multi-platform REST API framework
=====================================================================

[](#gemvc--php-multi-platform-rest-api-framework)

[![PHP Version](https://camo.githubusercontent.com/a74117f6cfdca449bfb1c98dd9f40f669e7a315e2176a439d1aac1569e30d2f1/68747470733a2f2f696d672e736869656c64732e696f2f62616467652f7068702d253345253344382e322d3737376262342e7376673f7374796c653d666c61742d737175617265266c6f676f3d706870266c6f676f436f6c6f723d7768697465)](https://www.php.net/releases/)[![License](https://camo.githubusercontent.com/942e017bf0672002dd32a857c95d66f28c5900ab541838c6c664442516309c8a/68747470733a2f2f696d672e736869656c64732e696f2f62616467652f6c6963656e73652d4d49542d626c75652e7376673f7374796c653d666c61742d737175617265)](LICENSE)[![Swoole](https://camo.githubusercontent.com/1adc2279a028575b92dd52f70dcbf828d0ad8eb7c5add86e9348715c47a41654/68747470733a2f2f696d672e736869656c64732e696f2f62616467652f53776f6f6c652d537570706f727465642d677265656e2e7376673f7374796c653d666c61742d737175617265266c6f676f3d73776f6f6c65266c6f676f436f6c6f723d7768697465)](https://openswoole.com/)[![Apache](https://camo.githubusercontent.com/36f5edb22be92c2ec3e32b953f37a3fd0e30fac8a281142a1d683865f98c9e30/68747470733a2f2f696d672e736869656c64732e696f2f62616467652f4170616368652d537570706f727465642d4432323132382e7376673f7374796c653d666c61742d737175617265266c6f676f3d617061636865266c6f676f436f6c6f723d7768697465)](https://httpd.apache.org/)[![Nginx](https://camo.githubusercontent.com/929ace7e41944c526c6de318d67d51ca26de1963768b5651a82dc58b38ee0f0d/68747470733a2f2f696d672e736869656c64732e696f2f62616467652f4e67696e782d537570706f727465642d3030393633392e7376673f7374796c653d666c61742d737175617265266c6f676f3d6e67696e78266c6f676f436f6c6f723d7768697465)](https://nginx.org/)[![PHPStan](https://camo.githubusercontent.com/a876ed48834d76bf15693fc02b9a7410d37709300f90373958b22ecdd3f0337e/68747470733a2f2f696d672e736869656c64732e696f2f62616467652f5048505374616e2d4c6576656c253230392d627269676874677265656e2e7376673f7374796c653d666c61742d737175617265)](https://phpstan.org/)

**Latest:** 5.12.0 — rate-limit drivers (`apcu` / `redis` / `both` / `none`) + `requireRateLimit*()`, `ProtectedApiService` / `ProtectedSwooleApiService`, `forUpdate()` + atomic transfer docs. Also **ViewTable**, multi-DB, `requireAuth()`, decimal types, modular CLI.

> **AI coding agents (Claude Code, Antigravity, Cursor, Copilot, …):** start at [`AGENTS.md`](AGENTS.md) (Claude: [`CLAUDE.md`](CLAUDE.md); Antigravity: [`GEMINI.md`](GEMINI.md)), then **mandatory** [`docs/ai/INDEX.md`](docs/ai/INDEX.md) → [`CANONICAL.md`](docs/ai/CANONICAL.md) → [`CORE_REFERENCE.md`](docs/ai/CORE_REFERENCE.md). GEMVC is **not** Laravel/Symfony — do not invent routes or Eloquent. Machine map: [`llms.txt`](llms.txt).

**GEMVC is an ecosystem** of Composer packages (`gemvc/library` + connection, APM, helper, HTTP client, CLI modules). See [docs/guides/ecosystem.md](docs/guides/ecosystem.md).

Start in 30 seconds
-------------------

[](#start-in-30-seconds)

```
composer require gemvc/library
php vendor/bin/gemvc init
# optional codegen + db introspection:
composer require --dev gemvc/cli-dev
```

Same application code runs on **OpenSwoole**, **Apache**, and **Nginx**.

What GEMVC is
-------------

[](#what-gemvc-is)

- **Server-agnostic** — your code works the same on OpenSwoole, Nginx, and Apache
- **4-layer** API → Controller → Model → Table / **ViewTable** — **strongly recommended**. You *can* bypass a layer and the runtime still works; do that only with a clear reason. Skipping layers is how services become hard to test, secure, and reason about.
- **Modular ecosystem** — **`gemvc/helper`** (types, crypto, paths) + **`gemvc/http-client`** (outbound HTTP) + connections, APM, CLI — not one monolith package
- **No routes file** — Apache/Nginx: `/api/{Service}/{method}` maps automatically; OpenSwoole uses `SERVICE_IN_URL_SECTION` / `METHOD_IN_URL_SECTION` (see [architecture.md](docs/guides/architecture.md))
- **~90% security automatic** — sanitize inputs, prepared statements, path protection; you add schema + auth
- **Schema is documentation** — `definePostSchema()` feeds `/api/index/document` + Postman export (types from **`gemvc/helper` → TypeChecker**)
- **Powerful lists** — API allowlists + Controller `createList()` (see below)
- **Outbound HTTP** — **`gemvc/http-client`** sync/async/Swoole-aware (do not invent curl wrappers)
- **Native APM** — **`gemvc/apm-contracts`** + provider (`APM_NAME`); app uses `callController()` / `createModel()` + `APM_*` flags
- **Library or framework** — migrate gradually or `gemvc init` for a full app

Not a Laravel/Symfony replacement — a focused scalpel for REST microservices.

Architecture (quick)
--------------------

[](#architecture-quick)

After the request reaches the server, Bootstrap sanitizes the incoming request and payload, then builds a **single cross-server `Request` object**. From the URL it resolves the target class and method (or returns 404). It instantiates the **API** layer class, injects `Request`, and calls the method.

```
app/api/          → endpoints + validation
app/controller/   → orchestration
app/model/        → business rules / workflows
app/table/        → database (Table or ViewTable)

```

### `app/api/` — endpoints + validation

[](#appapi--endpoints--validation)

Strong request sanitization lives here. As a developer you can:

- Guard a whole service with **`ProtectedApiService`** / **`ProtectedSwooleApiService`** (preferred), or `$this->requireAuth(['role'])` on `ApiService`, or `$this->request->auth(['role'])` per method
- Optional rate limit: global `REQUEST_RATE_LIMIT_PER_SEC` + `REQUEST_RATE_LIMIT_DRIVER` (`apcu`|`redis`|`both`|`none`), or `$this->requireRateLimit()` / `requireRateLimitApcu|Redis|Both()` (IP and/or JWT → 429). No automatic store fallback.
- Define exact POST / GET / PUT / PATCH schemas on each endpoint with powerful types (`string`, `email`, `url`, `ip`, …)
- Then call the Controller — Apache: `callController(...)`; OpenSwoole: `new XController($this->request)` — and pass the sanitized `Request`

No business rules here. Details: [api.md](docs/guides/api.md) · [security](docs/guides/security.md) · [http-lifecycle](docs/guides/http-lifecycle.md) · [api docs](docs/guides/api-documentation.md)

### `app/controller/` — orchestration

[](#appcontroller--orchestration)

Map the sanitized request onto a Model with powerful `mapPostToObject` / `mapPutToObject` / `mapPatchToObject`, prefer `createModel()` so Request/APM reach DB work, call Model methods or `createList()`, and **return `JsonResponse`**.

Keep Controllers thin on domain rules. Details: [controller.md](docs/guides/controller.md)

### `app/model/` — business rules

[](#appmodel--business-rules)

Where logic lives. Two shapes:

1. **Table-backed** — `UserModel extends UserTable`: CRUD, setters (`setPassword`), uniqueness, login, `_` aggregations
2. **Composition** — plain class that holds other Models as properties: inter-model workflows, façades, typed result objects; you expose or hide child methods as you wish

Return style is yours: Model may return `JsonResponse`, or any PHP type (`?self`, DTO, `array`, `bool`, …) while Controller builds `Response::*`.

Details: [model.md](docs/guides/model.md)

### `app/table/` — database

[](#apptable--database)

Columns as typed properties, `$_type_map`. Physical tables: `extends Table` + `defineSchema()`. **SQL views: `extends ViewTable`** + `defineView()` / `viewDependsOn()` — migrate with `gemvc db:migrate` or `--all` (read-only for row writes). Multi-DB via connection packages under the hood.

Details: [database.md](docs/guides/database.md)

### Flagship: lists (`createList`)

[](#flagship-lists-createlist)

One of GEMVC’s strongest DX + security features. **No free-form query SQL** — you allowlist fields in the API; the Controller applies them.

```
// API — allowlist + type-check GET params
$this->request->findable(['name' => 'string', 'email' => 'email']);   // find_like=
$this->request->filterable(['role' => 'string']);                    // filter_by=
$this->request->sortable(['id', 'name', 'created_at']);              // sort_by / sort_by_asc
return $this->callController(new UserController($this->request))->list();

// Controller — one call: filter + LIKE + sort + page + columns + total count + APM
return $this->createList(
    $this->createModel(new UserModel()),
    'id,name,email,role,created_at'
);
```

GET paramAPI methodEffect`find_like=name=ali``findable``WHERE … LIKE``filter_by=role=admin``filterable`exact `WHERE``sort_by` / `sort_by_asc``sortable``ORDER BY``page_number`(built-in)pagination + `getTotalCounts()`Full detail: [controller.md — Lists](docs/guides/controller.md#lists-createlist) · [api.md — List allowlists](docs/guides/api.md#list-allowlists)

### Core packages: `helper` + `http-client`

[](#core-packages-helper--http-client)

Two of the most important GEMVC packages (required with `gemvc/library`):

PackageJobGuide**`gemvc/helper`**`TypeChecker` (schema types), `CryptHelper` (passwords), `ProjectHelper`, File/Image helpers[helper.md](docs/guides/helper.md) · `vendor/gemvc/helper/README.md`**`gemvc/http-client`**Outbound sync/async HTTP (Apache curl / Swoole coroutines) — **not** inbound Request[http-client.md](docs/guides/http-client.md) · `vendor/gemvc/http-client/README.md`**AI:** Prefer these packages over inventing validators, `password_hash` wrappers, or Guzzle/curl clones. Full map: [ecosystem.md](docs/guides/ecosystem.md).

---

Documentation (all under `docs/`)
---------------------------------

[](#documentation-all-under-docs)

**Index:** [docs/README.md](docs/README.md)

### For AI assistants

[](#for-ai-assistants)

GEMVC is **not** Laravel or Symfony. Do **not** invent routes files or Eloquent patterns.

**Front doors (pick your tool, then the same pack):**

ToolStart hereAny agent[`AGENTS.md`](AGENTS.md)Claude Code[`CLAUDE.md`](CLAUDE.md)Antigravity[`GEMINI.md`](GEMINI.md) (overrides `AGENTS.md` on conflict)Cursor[`.cursorrules`](.cursorrules)Catalog / crawlers[`llms.txt`](llms.txt)Then read these three files in order (mandatory):

1. [docs/ai/INDEX.md](docs/ai/INDEX.md) — reading order and hard rules
2. [docs/ai/CANONICAL.md](docs/ai/CANONICAL.md) — 4-layer architecture, `requireAuth()`, CRUD patterns, decimal, multi-DB, CLI split, Do/Don’t
3. [docs/ai/CORE\_REFERENCE.md](docs/ai/CORE_REFERENCE.md) — framework class signatures (Request/Response/Table/ViewTable/Controller) — not HTTP endpoint docs

Optional mirrors: [docs/ai/core-reference.jsonc](docs/ai/core-reference.jsonc), [docs/ai/phpdoc-reference.php](docs/ai/phpdoc-reference.php).

### Guides (humans + deep dives)

[](#guides-humans--deep-dives)

Open a guide only when you need that topic. Prefer the **layer order**: API → controller → model → database, then supporting topics.

Layer / topicGuideEcosystem (not one package)[ecosystem.md](docs/guides/ecosystem.md)**`gemvc/helper`**[helper.md](docs/guides/helper.md)**`gemvc/http-client`**[http-client.md](docs/guides/http-client.md)Internals / request flow[architecture.md](docs/guides/architecture.md)Install → first API call[installation.md](docs/guides/installation.md)**API**[api.md](docs/guides/api.md)**Controller**[controller.md](docs/guides/controller.md)**Model**[model.md](docs/guides/model.md)**Table / DB**[database.md](docs/guides/database.md)HTTP Request lifecycle[http-lifecycle.md](docs/guides/http-lifecycle.md)Security / JWT[security.md](docs/guides/security.md)CLI + cli-dev[cli.md](docs/guides/cli.md) · [cli-reference.md](docs/guides/cli-reference.md)APM[apm.md](docs/guides/apm.md)Auto API docs[api-documentation.md](docs/guides/api-documentation.md)Codegen templates[templates.md](docs/guides/templates.md)Summaries of what each file contains: [docs/README.md](docs/README.md).

### Releases

[](#releases)

- [docs/releases/README.md](docs/releases/README.md) — when to read notes vs changelog (AI: skip unless version task)
- [docs/releases/RELEASE\_NOTES.md](docs/releases/RELEASE_NOTES.md) — narrative what/why/migration
- [docs/releases/CHANGELOG.md](docs/releases/CHANGELOG.md) — short “is feature X in version Y?”

License
-------

[](#license)

[MIT License](LICENSE) · [gemvc.de](https://www.gemvc.de)

###  Health Score

55

—

FairBetter than 97% of packages

Maintenance95

Actively maintained with recent releases

Popularity30

Limited adoption so far

Community18

Small or concentrated contributor base

Maturity64

Established project with proven stability

 Bus Factor1

Top contributor holds 53.1% of commits — single point of failure

How is this calculated?**Maintenance (25%)** — Last commit recency, latest release date, and issue-to-star ratio. Uses a 2-year decay window.

**Popularity (30%)** — Total and monthly downloads, GitHub stars, and forks. Logarithmic scaling prevents top-heavy scores.

**Community (15%)** — Contributors, dependents, forks, watchers, and maintainers. Measures real ecosystem engagement.

**Maturity (30%)** — Project age, version count, PHP version support, and release stability.

###  Release Activity

Cadence

Every ~4 days

Recently: every ~14 days

Total

282

Last Release

21d ago

Major Versions

v1.5.9 → v2.0.02023-11-18

v2.8.6 → v3.0.02024-05-01

v3.28.2 → 4.0.02025-05-11

4.1.0 → 5.0.02025-10-27

### Community

Maintainers

![](https://www.gravatar.com/avatar/e56aef71be22058cb4009cb1ef3b656232c2250df6726d63a812e18fe6f73e3c?d=identicon)[gemvc](/maintainers/gemvc)

---

Top Contributors

[![secure73](https://avatars.githubusercontent.com/u/6285341?v=4)](https://github.com/secure73 "secure73 (316 commits)")[![gemvc](https://avatars.githubusercontent.com/u/211101824?v=4)](https://github.com/gemvc "gemvc (191 commits)")[![roboxon](https://avatars.githubusercontent.com/u/145359440?v=4)](https://github.com/roboxon "roboxon (83 commits)")[![andrenalin282](https://avatars.githubusercontent.com/u/3642202?v=4)](https://github.com/andrenalin282 "andrenalin282 (5 commits)")

---

Tags

ai-readyapacheframeworkmicroservicenginxopenswoolephprest-api

###  Code Quality

TestsPHPUnit

Static AnalysisPHPStan

Type Coverage Yes

### Embed Badge

![Health badge](/badges/gemvc-library/health.svg)

```
[![Health](https://phpackages.com/badges/gemvc-library/health.svg)](https://phpackages.com/packages/gemvc-library)
```

###  Alternatives

[shopware/platform

The Shopware e-commerce core

3.4k1.5M3](/packages/shopware-platform)[shopware/core

Shopware platform is the core for all Shopware ecommerce products.

595.8M672](/packages/shopware-core)[typo3/cms-core

TYPO3 CMS Core

3313.6M5.6k](/packages/typo3-cms-core)[pimcore/skeleton

127202.6k](/packages/pimcore-skeleton)[sulu/skeleton

Project template for starting your new project based on the Sulu content management system

29736.0k](/packages/sulu-skeleton)[forumify/forumify-platform

132.1k18](/packages/forumify-forumify-platform)

PHPackages © 2026

[Directory](/)[Categories](/categories)[Trending](/trending)[Changelog](/changelog)[Analyze](/analyze)
