PHPackages                             padosoft/laravel-rebel-admin - PHPackages - PHPackages  [Skip to content](#main-content)[PHPackages](/)[Directory](/)[Categories](/categories)[Trending](/trending)[Leaderboard](/leaderboard)[Changelog](/changelog)[Analyze](/analyze)[Collections](/collections)[Log in](/login)[Sign up](/register)

1. [Directory](/)
2. /
3. [Authentication &amp; Authorization](/categories/authentication)
4. /
5. padosoft/laravel-rebel-admin

ActiveLibrary[Authentication &amp; Authorization](/categories/authentication)

padosoft/laravel-rebel-admin
============================

Web Admin Panel (Blade + AJAX + vanilla JS) for Laravel Rebel: a security operations dashboard over the Rebel Admin API. Part of padosoft/laravel-rebel-\*.

v0.1.6(1mo ago)196↓90%[1 PRs](https://github.com/padosoft/laravel-rebel-admin/pulls)1MITJavaScriptPHP ^8.3CI passing

Since Jun 3Pushed 1mo agoCompare

[ Source](https://github.com/padosoft/laravel-rebel-admin)[ Packagist](https://packagist.org/packages/padosoft/laravel-rebel-admin)[ Docs](https://github.com/padosoft/laravel-rebel-admin)[ RSS](/packages/padosoft-laravel-rebel-admin/feed)WikiDiscussions main Synced 1w ago

READMEChangelog (7)Dependencies (10)Versions (17)Used By (1)

Laravel Rebel — Web Admin Panel
===============================

[](#laravel-rebel--web-admin-panel)

> Official documentation:

> **A security-operations dashboard for your auth stack.** A clean Blade + vanilla-JS panel that hydrates entirely from the [Rebel Admin API](https://github.com/padosoft/laravel-rebel-admin-api): security overview, OTP/step-up funnels, channels, providers, audit explorer, devices, risk rules, anomalies, AI copilot and compliance — light/dark, tenant-aware, no JS framework required. Part of the `padosoft/laravel-rebel-*` suite.

 [![Laravel Rebel](resources/screenshoots/Laravel-Rebel-banner.png)](resources/screenshoots/Laravel-Rebel-banner.png)

 [![Laravel 12|13](https://camo.githubusercontent.com/9e9b743bcbf97a29fe735334a4a8e906d05d60310969905af6607cef8da30138/68747470733a2f2f696d672e736869656c64732e696f2f62616467652f4c61726176656c2d313225323025374325323031332d4646324432303f7374796c653d666c61742d737175617265266c6f676f3d6c61726176656c266c6f676f436f6c6f723d7768697465)](https://camo.githubusercontent.com/9e9b743bcbf97a29fe735334a4a8e906d05d60310969905af6607cef8da30138/68747470733a2f2f696d672e736869656c64732e696f2f62616467652f4c61726176656c2d313225323025374325323031332d4646324432303f7374796c653d666c61742d737175617265266c6f676f3d6c61726176656c266c6f676f436f6c6f723d7768697465) [![PHP 8.3+](https://camo.githubusercontent.com/6aa777dd33ef43fbef727d8187b578003a61e5dc41bbc958b0938c996cdc92f2/68747470733a2f2f696d672e736869656c64732e696f2f62616467652f5048502d382e33253230253743253230382e34253230253743253230382e352d3737374242343f7374796c653d666c61742d737175617265266c6f676f3d706870266c6f676f436f6c6f723d7768697465)](https://camo.githubusercontent.com/6aa777dd33ef43fbef727d8187b578003a61e5dc41bbc958b0938c996cdc92f2/68747470733a2f2f696d672e736869656c64732e696f2f62616467652f5048502d382e33253230253743253230382e34253230253743253230382e352d3737374242343f7374796c653d666c61742d737175617265266c6f676f3d706870266c6f676f436f6c6f723d7768697465) [![PHPStan max](https://camo.githubusercontent.com/4b9a3c97d76534abb905e64bd9e5bb9f13fe68e962071e0ccbbe7b629112f11c/68747470733a2f2f696d672e736869656c64732e696f2f62616467652f5048505374616e2d6d61782d3241364644423f7374796c653d666c61742d737175617265)](https://camo.githubusercontent.com/4b9a3c97d76534abb905e64bd9e5bb9f13fe68e962071e0ccbbe7b629112f11c/68747470733a2f2f696d672e736869656c64732e696f2f62616467652f5048505374616e2d6d61782d3241364644423f7374796c653d666c61742d737175617265) [![Pest 4](https://camo.githubusercontent.com/9b9da1d7d243a7465ab338e9374e47300a7fe2e26b5c291e7e3c95b53153789a/68747470733a2f2f696d672e736869656c64732e696f2f62616467652f74657374732d50657374253230342d3232433535453f7374796c653d666c61742d737175617265)](https://camo.githubusercontent.com/9b9da1d7d243a7465ab338e9374e47300a7fe2e26b5c291e7e3c95b53153789a/68747470733a2f2f696d672e736869656c64732e696f2f62616467652f74657374732d50657374253230342d3232433535453f7374796c653d666c61742d737175617265) [![Blade + vanilla JS](https://camo.githubusercontent.com/35318675ca02d980c4e2a1932868fcfe0aec286fbe21a1fc391a068d567b5991/68747470733a2f2f696d672e736869656c64732e696f2f62616467652f55492d426c61646525323025324225323076616e696c6c612532304a532d3045413545393f7374796c653d666c61742d737175617265)](https://camo.githubusercontent.com/35318675ca02d980c4e2a1932868fcfe0aec286fbe21a1fc391a068d567b5991/68747470733a2f2f696d672e736869656c64732e696f2f62616467652f55492d426c61646525323025324225323076616e696c6c612532304a532d3045413545393f7374796c653d666c61742d737175617265) [![MIT](https://camo.githubusercontent.com/ac049ef4e7a0b7196b09add6ac2d4f180e544c0ac779c2b2ac2fd2723a209579/68747470733a2f2f696d672e736869656c64732e696f2f62616467652f6c6963656e73652d4d49542d626c75653f7374796c653d666c61742d737175617265)](https://camo.githubusercontent.com/ac049ef4e7a0b7196b09add6ac2d4f180e544c0ac779c2b2ac2fd2723a209579/68747470733a2f2f696d672e736869656c64732e696f2f62616467652f6c6963656e73652d4d49542d626c75653f7374796c653d666c61742d737175617265)

---

Table of contents
-----------------

[](#table-of-contents)

- [What it is](#what-it-is)
- [Screenshots](#screenshots)
- [Why this panel](#why-this-panel)
- [Rebel Admin Panel vs the alternatives](#rebel-admin-panel-vs-the-alternatives)
- [Installation](#installation)
- [Configuration](#configuration)
- [Sections](#sections)
- [Architecture](#architecture)
- [Security notes](#security-notes)
- [`.env.example`](#envexample)
- [Testing &amp; License](#testing--license)

---

What it is
----------

[](#what-it-is)

The **web UI** of the Rebel control plane. It does not query your database directly — it renders a skeleton and **hydrates each widget over the Admin API** (`AbortController` fetch, explicit loading/empty/error states). It's deliberately dependency-light: **Blade + a single vanilla-JS file + CSS variables**, no Alpine/Livewire/React/Vue required, Bootstrap-compatible.

Depends on [`padosoft/laravel-rebel-core`](https://github.com/padosoft/laravel-rebel-core)and [`padosoft/laravel-rebel-admin-api`](https://github.com/padosoft/laravel-rebel-admin-api)(the data source).

> **v0.1.0 status:** the full shell (10 sections, theming, tenant/period context, access gate) is in place; **Security Overview** and **Audit Explorer** hydrate from the live API, and the remaining sections render an "endpoint pending" state until their Admin API endpoints ship in upcoming releases.

---

Screenshots
-----------

[](#screenshots)

 [![Dashboard (dark)](resources/screenshoots/Laravel-Rebel-Web-Panel-dasboard-dark.png)](resources/screenshoots/Laravel-Rebel-Web-Panel-dasboard-dark.png)

[![Audit explorer](resources/screenshoots/Laravel-Rebel-Web-Panel-audit-explorer.png)](resources/screenshoots/Laravel-Rebel-Web-Panel-audit-explorer.png)[![Anomaly detection](resources/screenshoots/Laravel-Rebel-Web-Panel-anomaly-detection.png)](resources/screenshoots/Laravel-Rebel-Web-Panel-anomaly-detection.png)[![Channel performance](resources/screenshoots/Laravel-Rebel-Web-Panel-channel-performance.png)](resources/screenshoots/Laravel-Rebel-Web-Panel-channel-performance.png)[![Risk rules](resources/screenshoots/Laravel-Rebel-Web-Panel-risk-rules.png)](resources/screenshoots/Laravel-Rebel-Web-Panel-risk-rules.png)[![Providers](resources/screenshoots/Laravel-Rebel-Web-Panel-providers.png)](resources/screenshoots/Laravel-Rebel-Web-Panel-providers.png)[![Compliance center](resources/screenshoots/Laravel-Rebel-Web-Panel-compilance-center.png)](resources/screenshoots/Laravel-Rebel-Web-Panel-compilance-center.png)[![Device & session trust](resources/screenshoots/Laravel-Rebel-Web-Panel-device-e-session-trust.png)](resources/screenshoots/Laravel-Rebel-Web-Panel-device-e-session-trust.png)[![AI security copilot](resources/screenshoots/Laravel-Rebel-Web-Panel-AI-security-copilot.png)](resources/screenshoots/Laravel-Rebel-Web-Panel-AI-security-copilot.png)---

Why this panel
--------------

[](#why-this-panel)

★WhatIn short★★★**API-driven, no direct DB queries**The UI only talks to the Admin API — safe, cacheable, and decoupled from your schema.★★★**Dependency-light**Blade + one vanilla-JS file + CSS variables. No JS framework, no heavy build step.★★★**Fail-closed access**Anonymous → login; authenticated without the `rebel-admin` ability → 403.★★**Light/dark + tenant/period context**Theme toggle and global context that re-hydrates every widget.★★**Explicit widget states**Every widget draws loading (skeleton), empty, and error (with retry).★★**Accessible &amp; responsive**Focus-visible, `aria-live` regions, collapsible sidebar.---

Rebel Admin Panel vs the alternatives
-------------------------------------

[](#rebel-admin-panel-vs-the-alternatives)

Building an auth-ops dashboard, compared:

Capability**Rebel Admin Panel**ShopifyGeneric admin (Nova/Filament)Hand-rolled Blade dashboardsPurpose-built for the Rebel auth stack✅❌❌➖API-driven (no direct DB coupling)✅➖❌❌No JS framework / heavy build required✅❌❌✅Self-hosted in your app (not hosted SaaS)✅❌✅✅Themeable Blade over your own data✅❌➖✅Hosted admin dashboard for staff✅✅✅➖Built-in light/dark + tenant/period context✅➖➖❌Explicit loading/empty/error per widget✅➖➖❌Fail-closed access gate out of the box✅➖➖❌Feature-flagged by installed Rebel packages✅❌❌❌Ships with the security section designs✅➖❌❌> Legend: ✅ built-in · ➖ partial / DIY / hosted-only / not exposed to you · ❌ not available.
>
> Note: Shopify is a hosted, closed commerce platform — it ships its own admin dashboard but you can't self-host it, extend it, point it at your own data/tenants, or treat it as a library for your app.

---

Installation
------------

[](#installation)

```
composer require padosoft/laravel-rebel-admin
php artisan vendor:publish --tag="rebel-admin-config"
php artisan vendor:publish --tag="rebel-admin-assets"   # publishes CSS/JS to public/vendor/laravel-rebel-admin
```

Grant access by defining the `rebel-admin` Gate (fail-closed by default):

```
Gate::define('rebel-admin', fn ($user) => $user->is_admin === true);
```

Visit `/admin/rebel`.

---

Configuration
-------------

[](#configuration)

File `config/rebel-admin.php`:

KeyDefaultWhat it does`prefix``admin/rebel`Where the panel is mounted.`middleware``['web']`Base middleware (session); `EnsurePanelAccess` is appended.`guard``''`Auth guard to require (`''` = default).`ability``rebel-admin`Gate ability to require (fail-closed).`api_base``/rebel/admin/api/v1`The Admin API base the JS hydrates from.`login_redirect``/login`Where anonymous visitors are sent.---

Sections
--------

[](#sections)

Overview · OTP &amp; Step-up Funnels · Channel Performance · Provider Health · Audit Explorer · Device &amp; Session Trust · Risk Rules · Anomaly Detection · AI Security Copilot · Compliance Center. See [`docs/admin-panel-template-spec.md`](docs/admin-panel-template-spec.md) for the full per-section component + endpoint specification.

---

Architecture
------------

[](#architecture)

```
Browser ──GET /admin/rebel/{section}──► PanelController ──► Blade shell (skeleton + data-rebel-widget)
                                                                   │
   rebel-admin.js scans [data-rebel-widget], for each:            │
        AbortController fetch ──► {api_base}/ (Admin API) ──► render (cards/table) | empty | error

```

Each section is one Blade page that renders the skeleton and declares its widgets via `data-rebel-widget` + `data-endpoint`; `rebel-admin.js` hydrates them and re-fetches on tenant/period changes.

---

Security notes
--------------

[](#security-notes)

- **No direct DB access from the UI** — only the Admin API, which is itself permission-gated and tenant-scoped.
- **Fail-closed**: the panel requires the `rebel-admin` ability by default.
- **No plaintext PII**: the Admin API only exposes HMAC'd identifiers; the panel renders text via `textContent` (no `innerHTML` interpolation of data).
- **Same-origin, CSRF-aware** requests.

---

`.env.example`
--------------

[](#envexample)

```
REBEL_ADMIN_PREFIX=admin/rebel
REBEL_ADMIN_GUARD=
REBEL_ADMIN_ABILITY=rebel-admin
REBEL_ADMIN_API_BASE=/rebel/admin/api/v1
REBEL_ADMIN_LOGIN_REDIRECT=/login
```

---

🔋 Vibe coding with batteries included
-------------------------------------

[](#-vibe-coding-with-batteries-included)

This package ships **AI batteries** — so you (and your AI agent) can extend it correctly on the first try:

- **`CLAUDE.md`** — a concise AI working guide (purpose, conventions, architecture, how to extend, Definition of Done). Plain Markdown, so Claude Code, Cursor, Copilot and Codex all read it.
- **`AGENTS.md`** — the agent/workflow contract (branch → PR → CI → tag/release, the gates).
- **`.claude/skills/`** — invocable skills (at least `rebel-package-dev`) encoding the suite's TDD loop, the **PHPStan-level-max** recipes, the security/telemetry rules, and the release discipline.

Open the repo in your AI editor and just start — the rules, guardrails and extension recipes come with it. PRs that follow the shipped `CLAUDE.md` pass CI (PHPStan max + Pest + Pint) and review the first time around.

Testing &amp; License
---------------------

[](#testing--license)

```
composer test      # Pest (access gate, shell rendering, sections, fail-closed)
composer phpstan   # static analysis, level max
composer pint      # code style
```

**License:** MIT — see [LICENSE](LICENSE). Part of the [`padosoft/laravel-rebel`](https://github.com/padosoft) suite.

###  Health Score

42

—

FairBetter than 88% of packages

Maintenance91

Actively maintained with recent releases

Popularity13

Limited adoption so far

Community8

Small or concentrated contributor base

Maturity47

Maturing project, gaining track record

 Bus Factor1

Top contributor holds 100% of commits — single point of failure

How is this calculated?**Maintenance (25%)** — Last commit recency, latest release date, and issue-to-star ratio. Uses a 2-year decay window.

**Popularity (30%)** — Total and monthly downloads, GitHub stars, and forks. Logarithmic scaling prevents top-heavy scores.

**Community (15%)** — Contributors, dependents, forks, watchers, and maintainers. Measures real ecosystem engagement.

**Maturity (30%)** — Project age, version count, PHP version support, and release stability.

###  Release Activity

Cadence

Every ~0 days

Total

7

Last Release

51d ago

### Community

Maintainers

![](https://avatars.githubusercontent.com/u/10467699?v=4)[Lorenzo](/maintainers/lopadova)[@lopadova](https://github.com/lopadova)

---

Top Contributors

[![lopadova](https://avatars.githubusercontent.com/u/10467699?v=4)](https://github.com/lopadova "lopadova (12 commits)")

---

Tags

laravelsecurityAuthenticationpadosoftRebel

###  Code Quality

TestsPest

Static AnalysisPHPStan

Code StyleLaravel Pint

### Embed Badge

![Health badge](/badges/padosoft-laravel-rebel-admin/health.svg)

```
[![Health](https://phpackages.com/badges/padosoft-laravel-rebel-admin/health.svg)](https://phpackages.com/packages/padosoft-laravel-rebel-admin)
```

###  Alternatives

[spatie/laravel-permission

Permission handling for Laravel 12 and up

12.9k102.4M1.5k](/packages/spatie-laravel-permission)[defstudio/telegraph

A laravel facade to interact with Telegram Bots

813336.8k3](/packages/defstudio-telegraph)[harris21/laravel-fuse

Circuit breaker for Laravel queue jobs. Protect your workers from cascading failures.

45955.7k](/packages/harris21-laravel-fuse)[rawilk/profile-filament-plugin

Profile &amp; MFA starter kit for filament.

3914.8k](/packages/rawilk-profile-filament-plugin)[masterix21/laravel-licensing

Laravel licensing package with polymorphic assignment to any model, activation keys, expirations/renewals, and seat control via LicenseUsage. Supports offline verification with public-key–signed tokens, a CLI to generate/rotate/revoke keys, and an extensible architecture via config and contracts.

1613.3k4](/packages/masterix21-laravel-licensing)[simplestats-io/laravel-client

Server-side analytics for Laravel that follows the full funnel from visit to registration to payment, attributed to the channel that drove it. Revenue, MRR, churn and ad-spend profit (ROAS/CAC) per channel. GDPR compliant, ad-blocker proof.

5022.6k](/packages/simplestats-io-laravel-client)

PHPackages © 2026

[Directory](/)[Categories](/categories)[Trending](/trending)[Changelog](/changelog)[Analyze](/analyze)
