PHPackages                             ghostcompiler/laravel-auth - PHPackages - PHPackages  [Skip to content](#main-content)[PHPackages](/)[Directory](/)[Categories](/categories)[Trending](/trending)[Leaderboard](/leaderboard)[Changelog](/changelog)[Analyze](/analyze)[Collections](/collections)[Log in](/login)[Sign up](/register)

1. [Directory](/)
2. /
3. [Authentication &amp; Authorization](/categories/authentication)
4. /
5. ghostcompiler/laravel-auth

ActiveLibrary[Authentication &amp; Authorization](/categories/authentication)

ghostcompiler/laravel-auth
==========================

Headless Laravel authentication security with TOTP 2FA, passkeys, trusted devices, recovery codes, and Socialite-powered social login helpers.

v1.0.3(1mo ago)00MITPHPPHP ^8.2 || ^8.3 || ^8.4 || ^8.5CI passing

Since Jun 18Pushed 3mo agoCompare

[ Source](https://github.com/ghostcompiler/laravel-auth)[ Packagist](https://packagist.org/packages/ghostcompiler/laravel-auth)[ RSS](/packages/ghostcompiler-laravel-auth/feed)WikiDiscussions main Synced 3w ago

READMEChangelog (4)Dependencies (21)Versions (5)Used By (0)

 [![Laravel Auth](https://camo.githubusercontent.com/7a311440d646263aeef835cc3b8d3f30b2c35f8fbf32c26ecf9a971070371ca9/68747470733a2f2f7265732e636c6f7564696e6172792e636f6d2f646a6776666c3174762f696d6167652f75706c6f61642f76313738303636363739312f6c6f676f5f6d716e716e342e706e67)](https://camo.githubusercontent.com/7a311440d646263aeef835cc3b8d3f30b2c35f8fbf32c26ecf9a971070371ca9/68747470733a2f2f7265732e636c6f7564696e6172792e636f6d2f646a6776666c3174762f696d6167652f75706c6f61642f76313738303636363739312f6c6f676f5f6d716e716e342e706e67)

Laravel Auth
============

[](#laravel-auth)

 Premium, headless Laravel authentication hardening library for TOTP 2FA, passkeys, recovery codes, multi-channel OTP, trusted devices, and social authentication.

 [![Laravel](https://camo.githubusercontent.com/1a1623d9cb3822055a983858c4bfbd345d6a36d5d428eb63558a56dcce7bc764/68747470733a2f2f696d672e736869656c64732e696f2f62616467652f4c61726176656c2d31302532302537432532303131253230253743253230313225323025374325323031332d4646324432303f7374796c653d666f722d7468652d6261646765266c6f676f3d6c61726176656c266c6f676f436f6c6f723d7768697465)](https://camo.githubusercontent.com/1a1623d9cb3822055a983858c4bfbd345d6a36d5d428eb63558a56dcce7bc764/68747470733a2f2f696d672e736869656c64732e696f2f62616467652f4c61726176656c2d31302532302537432532303131253230253743253230313225323025374325323031332d4646324432303f7374796c653d666f722d7468652d6261646765266c6f676f3d6c61726176656c266c6f676f436f6c6f723d7768697465) [![PHP Version](https://camo.githubusercontent.com/22a8463a63c7c9f605dbc977742748c940ec017f0a569bcea7fe0f1144b9087a/68747470733a2f2f696d672e736869656c64732e696f2f62616467652f5048502d382e32253230746f253230382e352d3737374242343f7374796c653d666f722d7468652d6261646765266c6f676f3d706870266c6f676f436f6c6f723d7768697465)](https://camo.githubusercontent.com/22a8463a63c7c9f605dbc977742748c940ec017f0a569bcea7fe0f1144b9087a/68747470733a2f2f696d672e736869656c64732e696f2f62616467652f5048502d382e32253230746f253230382e352d3737374242343f7374796c653d666f722d7468652d6261646765266c6f676f3d706870266c6f676f436f6c6f723d7768697465) [![Security Hardened](https://camo.githubusercontent.com/a2b771fe15c6081a8ac4cb30e39a1f1de82ace6c10d07e1733ea7da6231cacdb/68747470733a2f2f696d672e736869656c64732e696f2f62616467652f53656375726974792d48617264656e65642d3362383266363f7374796c653d666f722d7468652d6261646765)](https://camo.githubusercontent.com/a2b771fe15c6081a8ac4cb30e39a1f1de82ace6c10d07e1733ea7da6231cacdb/68747470733a2f2f696d672e736869656c64732e696f2f62616467652f53656375726974792d48617264656e65642d3362383266363f7374796c653d666f722d7468652d6261646765) [![Ghost Compiler](https://camo.githubusercontent.com/929b6dba84633d06d1f92f362e1226d9ae8489c83d8d5294df8817b1192edf88/68747470733a2f2f696d672e736869656c64732e696f2f62616467652f4275696c7425323042792d47686f7374253230436f6d70696c65722d3046313732413f7374796c653d666f722d7468652d6261646765)](https://camo.githubusercontent.com/929b6dba84633d06d1f92f362e1226d9ae8489c83d8d5294df8817b1192edf88/68747470733a2f2f696d672e736869656c64732e696f2f62616467652f4275696c7425323042792d47686f7374253230436f6d70696c65722d3046313732413f7374796c653d666f722d7468652d6261646765)

 [![](https://camo.githubusercontent.com/282aa6342ad83a7e01c0c2e1a47a633d79452a0be93b0358a5d4a33923ac9df5/68747470733a2f2f696d672e736869656c64732e696f2f6769746875622f73746172732f67686f7374636f6d70696c65722f6c61726176656c2d617574683f7374796c653d666f722d7468652d6261646765266c6f676f3d676974687562)](https://camo.githubusercontent.com/282aa6342ad83a7e01c0c2e1a47a633d79452a0be93b0358a5d4a33923ac9df5/68747470733a2f2f696d672e736869656c64732e696f2f6769746875622f73746172732f67686f7374636f6d70696c65722f6c61726176656c2d617574683f7374796c653d666f722d7468652d6261646765266c6f676f3d676974687562) [![](https://camo.githubusercontent.com/c4fdcc2c4e5653a333a5180e2519b30f62807b9f59688836bbbd40c6f15a5daa/68747470733a2f2f696d672e736869656c64732e696f2f7061636b61676973742f64742f67686f7374636f6d70696c65722f6c61726176656c2d617574683f7374796c653d666f722d7468652d6261646765266c6f676f3d7061636b6167697374)](https://camo.githubusercontent.com/c4fdcc2c4e5653a333a5180e2519b30f62807b9f59688836bbbd40c6f15a5daa/68747470733a2f2f696d672e736869656c64732e696f2f7061636b61676973742f64742f67686f7374636f6d70696c65722f6c61726176656c2d617574683f7374796c653d666f722d7468652d6261646765266c6f676f3d7061636b6167697374)

---

Headless Laravel authentication hardening with:

- TOTP 2FA
- recovery codes
- passkeys via WebAuthn
- email, SMS, and WhatsApp OTP
- trusted devices
- Socialite-based social account linking
- runtime tenant OAuth credentials for social login

This package does not replace your login system. It adds security layers on top of your existing auth flow.

Requirements
------------

[](#requirements)

- PHP 8.2+
- Laravel 10, 11, 12, or 13
- database access for package tables
- HTTPS for browser passkey flows
- `laravel/socialite` support for social login helpers

Installation
------------

[](#installation)

```
composer require ghostcompiler/laravel-auth
php artisan ghost:laravel-auth
php artisan migrate
```

Force republishing if you want to overwrite previously published files:

```
php artisan ghost:laravel-auth --force
```

What `ghost:laravel-auth` publishes:

- `config/laravel-auth.php`
- one package migration file
- package OTP views to `resources/views/vendor/laravel-auth`
- SMS and WhatsApp transport stubs to `app/LaravelAuth`

Publish only OTP assets later if needed:

```
php artisan laravel-auth:otp:publish
```

Local Package Development
-------------------------

[](#local-package-development)

To test this package from another Laravel app through a local path repository:

```
{
  "repositories": [
    {
      "type": "path",
      "url": "../laravel-auth",
      "options": {
        "symlink": true
      }
    }
  ],
  "require": {
    "ghostcompiler/laravel-auth": "*"
  }
}
```

Then in the app:

```
composer require ghostcompiler/laravel-auth
php artisan ghost:laravel-auth
php artisan migrate
php artisan optimize:clear
```

If the app does not pick up local changes automatically:

```
composer update ghostcompiler/laravel-auth
composer dump-autoload
php artisan optimize:clear
```

What The Package Adds
---------------------

[](#what-the-package-adds)

Middleware aliases:

- `2fa`
- `laravel-auth.2fa`
- `laravel-auth.enforce`
- `laravel-auth.throttle`

Published config:

- [config/laravel-auth.php](config/laravel-auth.php)

Main facade contract:

- `src/Contracts/LaravelAuthManager.php`

Single package migration:

- [database/migrations/2026\_04\_12\_000001\_create\_laravel\_auth\_schema.php](database/migrations/2026_04_12_000001_create_laravel_auth_schema.php)

Database objects created:

- user table columns:
    - `laravel_auth_totp_secret`
    - `laravel_auth_two_factor_enabled`
    - `laravel_auth_confirmed_at`
- `laravel_auth_recovery_codes`
- `laravel_auth_trusted_devices`
- `laravel_auth_passkeys`
- `laravel_auth_webauthn_challenges`
- `laravel_auth_social_accounts`
- `laravel_auth_otp_challenges`

Current Defaults
----------------

[](#current-defaults)

From the package config:

- `enforce_2fa` is `true`
- 2FA enforcement is pushed into the `web` middleware group
- OTP TTL is 300 seconds
- OTP max attempts is 5
- rate limit decay is 60 seconds
- TOTP uses 6 digits, 30-second period, 1-step window
- trusted devices are bound to user agent by default
- trusted-device IP binding is off by default
- WhatsApp OTP is disabled by default
- social runtime stateless mode defaults to `false`

Recommended Base Route Protection
---------------------------------

[](#recommended-base-route-protection)

```
use Illuminate\Support\Facades\Route;

Route::middleware(['auth', 'laravel-auth.2fa'])->group(function () {
    Route::get('/billing', fn () => 'protected');
    Route::get('/settings/security', fn () => 'security');
});
```

Add throttling to sensitive verification endpoints:

```
Route::post('/security/otp/verify', [SecurityController::class, 'verifyOtp'])
    ->middleware(['auth', 'laravel-auth.throttle:otp']);

Route::post('/security/passkey/verify', [SecurityController::class, 'verifyPasskey'])
    ->middleware(['auth', 'laravel-auth.throttle:passkey']);
```

TOTP 2FA Setup
--------------

[](#totp-2fa-setup)

Enable 2FA for a user:

```
$setup = LaravelAuth::enable2FA(auth()->user());

return response()->json([
    'secret' => $setup['secret'],
    'otpauth_uri' => $setup['otpauth_uri'],
]);
```

Confirm setup:

```
$result = LaravelAuth::confirmTwoFactorSetup(
    auth()->user(),
    $request->string('code')
);

return response()->json([
    'recovery_codes' => $result['recovery_codes'],
]);
```

Disable 2FA:

```
LaravelAuth::disable2FA(auth()->user());
```

Demo 2FA Controller
-------------------

[](#demo-2fa-controller)

```
