PHPackages                             grosv/laravel-passwordless-login - PHPackages - PHPackages  [Skip to content](#main-content)[PHPackages](/)[Directory](/)[Categories](/categories)[Trending](/trending)[Leaderboard](/leaderboard)[Changelog](/changelog)[Analyze](/analyze)[Collections](/collections)[Log in](/login)[Sign up](/register)

1. [Directory](/)
2. /
3. [Authentication &amp; Authorization](/categories/authentication)
4. /
5. grosv/laravel-passwordless-login

ActiveLibrary[Authentication &amp; Authorization](/categories/authentication)

grosv/laravel-passwordless-login
================================

Passwordless login using temporary signed URL

v2.2.1(3w ago)872587.6k↓24.5%71MITPHPPHP ^8.3CI passing

Since Feb 28Pushed 3w ago15 watchersCompare

[ Source](https://github.com/edalzell/laravel-passwordless-login)[ Packagist](https://packagist.org/packages/grosv/laravel-passwordless-login)[ RSS](/packages/grosv-laravel-passwordless-login/feed)WikiDiscussions main Synced 2w ago

READMEChangelog (10)Dependencies (10)Versions (37)Used By (0)

Laravel Passwordless Login
==========================

[](#laravel-passwordless-login)

[![build status](https://github.com/grosv/laravel-passwordless-login/actions/workflows/test.yml/badge.svg)](https://github.com/grosv/laravel-passwordless-login/actions/workflows/test.yml)

### A simple, safe magic login link generator for Laravel

[](#a-simple-safe-magic-login-link-generator-for-laravel)

This package provides a temporary signed route that logs in a user. What it does not provide is a way of actually sending the link to the route to the user. This is because I don't want to make any assumptions about how you communicate with your users.

### Installation

[](#installation)

```
composer require grosv/laravel-passwordless-login
```

### Simple Usage

[](#simple-usage)

```
use App\User;
use Grosv\LaravelPasswordlessLogin\LoginUrl;

function sendLoginLink()
{
    $user = User::find(1);

    $generator = new LoginUrl($user);
    $generator->setRedirectUrl('/somewhere/else'); // Override the default url to redirect to after login
    $url = $generator->generate();

    //OR Use a Facade
    $url = PasswordlessLogin::forUser($user)->generate();

    // Send $url in an email or text message to your user
}
```

### Using A Trait

[](#using-a-trait)

Because some sites have more than one user-type model (users, admins, etc.), you can use a trait to set up the default configurations for each user type. The methods below are provided by the trait, so you only need to include the ones for which you want to use a different value.

```
use Grosv\LaravelPasswordlessLogin\Traits\PasswordlessLogin;
use Illuminate\Foundation\Auth\User as Authenticatable;

class User extends Authenticatable
{
    use PasswordlessLogin;

    public function getGuardNameAttribute(): string
    {
        return config('laravel-passwordless-login.user_guard');
    }

    public function getShouldRememberLoginAttribute(): bool
    {
        return config('laravel-passwordless-login.remember_login');
    }

    public function getLoginRouteExpiresInAttribute(): int
    {
        return config('laravel-passwordless-login.login_route_expires');
    }

    public function getRedirectUrlAttribute(): string
    {
        return config('laravel-passwordless-login.redirect_on_success');
    }
}
```

If you are using the PasswordlessLogin Trait, you can generate a link using the defaults defined in the trait by simply calling `createPasswordlessLoginLink()` on the user you want to log in.

The biggest mistake I could see someone making with this package is creating a login link for one user and sending it to another. Please be careful and test your code. I don't want anyone getting mad at me for someone else's silliness.

### Multiple Guards

[](#multiple-guards)

If you have more than one user-type model authenticated on different guards (e.g. `User` on `web` and `Admin` on `admin`), override `getGuardNameAttribute()` on each model to return its own guard instead of the globally configured one:

```
class Admin extends Authenticatable
{
    use PasswordlessLogin;

    public function getGuardNameAttribute(): string
    {
        return 'admin';
    }
}
```

The package uses this to both retrieve and log in the user with the correct guard, so a link generated for an `Admin` is authenticated against the `admin` guard rather than `LPL_USER_GUARD`.

### Configuration

[](#configuration)

You can publish the config file or just set the values you want to use in your .env file:

```
LPL_REMEMBER_LOGIN=false
LPL_LOGIN_ROUTE=/magic-login
LPL_LOGIN_ROUTE_ACTION=get
LPL_LOGIN_ROUTE_NAME=magic-login
LPL_LOGIN_ROUTE_EXPIRES=30
LPL_REDIRECT_ON_LOGIN=/
LPL_USER_GUARD=web
LPL_USE_ONCE=false
LPL_REQUIRE_CACHE_MARKER=false
LPL_CACHE_STORE=
LPL_INVALID_SIGNATURE_MESSAGE="Expired or Invalid Link"
```

`LPL_REMEMBER_LOGIN` is whether you want to remember the login (like the user checking Remember Me)

`LPL_LOGIN_ROUTE` is the route that points to the login function this package provides. Make sure you don't collide with one of your other routes.

`LPL_LOGIN_ROUTE_ACTION` is the HTTP verb the login route responds to, e.g. `get` or `post`. Defaults to `get`. If you use `post`, you'll need to exclude the route from CSRF verification — see [Laravel's CSRF documentation](https://laravel.com/docs/13.x/csrf#csrf-excluding-uris).

`LPL_LOGIN_ROUTE_NAME` is the name of the LPL\_LOGIN\_ROUTE. Again, make sure it doesn't collide with any of your existing route names.

`LPL_LOGIN_ROUTE_EXPIRES` is the number of minutes you want the link to be good for. I recommend you set the shortest value that makes sense for your use case.

`LPL_REDIRECT_ON_LOGIN` is where you want to send the user after they've logged in by clicking their magic link.

`LPL_USE_ONCE` is whether you want a link to expire after first use. When enabled, the link is consumed on first use and cannot be used again.

`LPL_REQUIRE_CACHE_MARKER` is whether a link must have a matching entry in the cache to be considered valid, which is what powers [invalidating links](#invalidating-links) before they expire. It defaults to `false` so that links generated before you adopted this feature (or before you upgraded across a version that introduced it) keep working based on their own signature and expiry alone. Turn it on if you need `invalidateForUser()` to actually revoke outstanding multi-use links — note that doing so also means a cleared or evicted cache will invalidate every outstanding link, so make sure your cache store is durable enough for your link lifetimes before enabling it. `LPL_USE_ONCE` links always check the cache marker regardless of this setting.

`LPL_CACHE_STORE` is the name of the cache store (as defined in your `config/cache.php`) that link markers are read from and written to. Leave it blank to use your app's default (`cache.default`). Set it to point markers at a specific store when you need them to survive things that don't affect link validity — a `cache:clear` on deploy, a Redis restart, or `maxmemory` eviction on your general-purpose cache — which matters most once `LPL_REQUIRE_CACHE_MARKER=true`, since that's when marker survival determines whether a link still works.

`LPL_INVALID_SIGNATURE_MESSAGE` is a custom message sent when we abort with a 401 status on an invalid or expired link. You can also add some custom logic on how to deal with invalid or expired links by handling `InvalidSignatureException` and `ExpiredSignatureException` in your `Handler.php` file.

### Invalidating Links

[](#invalidating-links)

Links can be explicitly revoked before they expire — for example, after a user sets a password or changes their email.

```
use Grosv\LaravelPasswordlessLogin\PasswordlessLogin;

// Revoke any outstanding magic link for a user
PasswordlessLogin::invalidateForUser($user);
```

Generating a new link for a user automatically clears any prior invalidation, so calling `generate()` is all you need to issue a fresh link.

> **Note:** `invalidateForUser()` only takes effect on multi-use links when `LPL_REQUIRE_CACHE_MARKER=true` (see [Configuration](#configuration)) — otherwise a link's own signature and expiry are all that's checked, and revocation is a no-op. With the marker required, magic links are tracked in the cache, so a cleared or evicted cache also invalidates every outstanding link — intentional, since a cleared cache is safer than silently reactivating a revoked link, but it means your cache store needs to be durable enough to outlive your longest-lived links. Use `LPL_CACHE_STORE` to point markers at a store dedicated to that purpose, separate from whatever your app flushes on deploy. `LPL_USE_ONCE` links check the cache marker regardless of this setting, since consuming a link has always relied on it.

### Events

[](#events)

The package dispatches events during the login flow that you can listen for, e.g. for auditing or alerting on suspicious activity:

EventDispatched when`$user``Grosv\LaravelPasswordlessLogin\Events\LoginLinkSuccessful`A valid, unexpired link successfully logs the user in.Always present.`Grosv\LaravelPasswordlessLogin\Events\LoginLinkExpired`A correctly signed link is used after it has expired.Always present.`Grosv\LaravelPasswordlessLogin\Events\LoginLinkInvalid`A request has an invalid or missing signature (e.g. tampered URL, or a URL missing its signed query parameters entirely).May be `null` if the user couldn't be identified from the request.```
use Grosv\LaravelPasswordlessLogin\Events\LoginLinkInvalid;

class LogSuspiciousLoginAttempt
{
    public function handle(LoginLinkInvalid $event): void
    {
        // $event->user may be null
        logger()->warning('Invalid passwordless login attempt', [
            'user_id' => $event->user?->id,
        ]);
    }
}
```

### Reporting Issues

[](#reporting-issues)

For security issues, please email me directly at `security@silentz.co`. For any other problems, use the issue tracker here.

### Contributing

[](#contributing)

I welcome the community's help with improving and maintaining all my packages. Just be nice to each other. Remember we're all just trying to do our best.

###  Health Score

71

—

ExcellentBetter than 100% of packages

Maintenance95

Actively maintained with recent releases

Popularity60

Solid adoption and visibility

Community30

Small or concentrated contributor base

Maturity84

Battle-tested with a long release history

 Bus Factor3

3 contributors hold 50%+ of commits

How is this calculated?**Maintenance (25%)** — Last commit recency, latest release date, and issue-to-star ratio. Uses a 2-year decay window.

**Popularity (30%)** — Total and monthly downloads, GitHub stars, and forks. Logarithmic scaling prevents top-heavy scores.

**Community (15%)** — Contributors, dependents, forks, watchers, and maintainers. Measures real ecosystem engagement.

**Maturity (30%)** — Project age, version count, PHP version support, and release stability.

###  Release Activity

Cadence

Every ~90 days

Recently: every ~37 days

Total

27

Last Release

24d ago

Major Versions

0.2.0 → 1.0.02020-03-11

1.11.0 → v2.0.02026-02-26

PHP version history (3 changes)0.1.0PHP ^7.3

1.4.1PHP ^7.3|^8.0

v2.0.0PHP ^8.3

### Community

Maintainers

![](https://www.gravatar.com/avatar/85ea2872499207e557751841b622e1c655c1ea9b56c6bced58686926f0e0fd17?d=identicon)[edalzell](/maintainers/edalzell)

![](https://avatars.githubusercontent.com/u/1053395?v=4)[Ed Grosvenor](/maintainers/edgrosvenor)[@edgrosvenor](https://github.com/edgrosvenor)

---

Top Contributors

[![kamiben](https://avatars.githubusercontent.com/u/389495?v=4)](https://github.com/kamiben "kamiben (41 commits)")[![edalzell](https://avatars.githubusercontent.com/u/6069653?v=4)](https://github.com/edalzell "edalzell (39 commits)")[![edgrosvenor](https://avatars.githubusercontent.com/u/1053395?v=4)](https://github.com/edgrosvenor "edgrosvenor (37 commits)")[![innoflash](https://avatars.githubusercontent.com/u/12772919?v=4)](https://github.com/innoflash "innoflash (35 commits)")[![JhumanJ](https://avatars.githubusercontent.com/u/11312432?v=4)](https://github.com/JhumanJ "JhumanJ (6 commits)")[![laravel-shift](https://avatars.githubusercontent.com/u/15991828?v=4)](https://github.com/laravel-shift "laravel-shift (5 commits)")[![szepeviktor](https://avatars.githubusercontent.com/u/952007?v=4)](https://github.com/szepeviktor "szepeviktor (4 commits)")[![ashleighsims](https://avatars.githubusercontent.com/u/1674351?v=4)](https://github.com/ashleighsims "ashleighsims (4 commits)")[![afzafri](https://avatars.githubusercontent.com/u/14824387?v=4)](https://github.com/afzafri "afzafri (2 commits)")[![felixdorn](https://avatars.githubusercontent.com/u/55788595?v=4)](https://github.com/felixdorn "felixdorn (1 commits)")[![dependabot[bot]](https://avatars.githubusercontent.com/in/29110?v=4)](https://github.com/dependabot[bot] "dependabot[bot] (1 commits)")[![joe-pritchard](https://avatars.githubusercontent.com/u/25373032?v=4)](https://github.com/joe-pritchard "joe-pritchard (1 commits)")[![DavidGoodwin](https://avatars.githubusercontent.com/u/203929?v=4)](https://github.com/DavidGoodwin "DavidGoodwin (1 commits)")[![benrolfe](https://avatars.githubusercontent.com/u/474175?v=4)](https://github.com/benrolfe "benrolfe (1 commits)")[![iman-ragab](https://avatars.githubusercontent.com/u/79089798?v=4)](https://github.com/iman-ragab "iman-ragab (1 commits)")[![pktharindu](https://avatars.githubusercontent.com/u/23132672?v=4)](https://github.com/pktharindu "pktharindu (1 commits)")[![ReinisL](https://avatars.githubusercontent.com/u/18574406?v=4)](https://github.com/ReinisL "ReinisL (1 commits)")[![rico](https://avatars.githubusercontent.com/u/92818?v=4)](https://github.com/rico "rico (1 commits)")[![spekulatius](https://avatars.githubusercontent.com/u/8433587?v=4)](https://github.com/spekulatius "spekulatius (1 commits)")[![likeadeckofcards](https://avatars.githubusercontent.com/u/6399755?v=4)](https://github.com/likeadeckofcards "likeadeckofcards (1 commits)")

###  Code Quality

TestsPest

### Embed Badge

![Health badge](/badges/grosv-laravel-passwordless-login/health.svg)

```
[![Health](https://phpackages.com/badges/grosv-laravel-passwordless-login/health.svg)](https://phpackages.com/packages/grosv-laravel-passwordless-login)
```

###  Alternatives

[illuminate/auth

The Illuminate Auth package.

9328.5M1.4k](/packages/illuminate-auth)[directorytree/ldaprecord-laravel

LDAP Authentication &amp; Management for Laravel.

5732.5M23](/packages/directorytree-ldaprecord-laravel)[masterix21/laravel-licensing

Laravel licensing package with polymorphic assignment to any model, activation keys, expirations/renewals, and seat control via LicenseUsage. Supports offline verification with public-key–signed tokens, a CLI to generate/rotate/revoke keys, and an extensible architecture via config and contracts.

1614.1k4](/packages/masterix21-laravel-licensing)

PHPackages © 2026

[Directory](/)[Categories](/categories)[Trending](/trending)[Changelog](/changelog)[Analyze](/analyze)
