PHPackages                             padosoft/laravel-rebel-auth - PHPackages - PHPackages  [Skip to content](#main-content)[PHPackages](/)[Directory](/)[Categories](/categories)[Trending](/trending)[Leaderboard](/leaderboard)[Changelog](/changelog)[Analyze](/analyze)[Collections](/collections)[Log in](/login)[Sign up](/register)

1. [Directory](/)
2. /
3. [Authentication &amp; Authorization](/categories/authentication)
4. /
5. padosoft/laravel-rebel-auth

ActiveLibrary[Authentication &amp; Authorization](/categories/authentication)

padosoft/laravel-rebel-auth
===========================

Meta-package for the padosoft/laravel-rebel-\* enterprise authentication control plane: passwordless email-OTP, passkey-first, risk-based step-up with PSD2/SCA, channels, sessions, recovery, anomaly detection and a web admin panel — installs and ties the whole suite together.

v0.1.0(1mo ago)01↓90%[1 PRs](https://github.com/padosoft/laravel-rebel-auth/pulls)MITPHPPHP ^8.3CI passing

Since Jun 3Pushed 1mo agoCompare

[ Source](https://github.com/padosoft/laravel-rebel-auth)[ Packagist](https://packagist.org/packages/padosoft/laravel-rebel-auth)[ Docs](https://github.com/padosoft/laravel-rebel-auth)[ RSS](/packages/padosoft-laravel-rebel-auth/feed)WikiDiscussions main Synced 1w ago

READMEChangelog (1)Dependencies (18)Versions (7)Used By (0)

Laravel Rebel — Enterprise Authentication, the way Shopify wishes it did it
===========================================================================

[](#laravel-rebel--enterprise-authentication-the-way-shopify-wishes-it-did-it)

> Official documentation:

> **Passwordless, passkey-first, risk-based authentication for Laravel — a control plane over Fortify.** Email-OTP &amp; passkey login (web + mobile via Sanctum), risk-based step-up with **PSD2/SCA dynamic linking**, multi-channel verification with anti toll-fraud, refresh-token rotation with reuse detection, device trust, recovery codes, anomaly detection with an advisory AI, a web admin panel, and NIST/PSD2/GDPR-aware compliance — modular, multi-tenant, and PHPStan-max across the board.

 [![Laravel Rebel](resources/screenshoots/Laravel-Rebel-banner.png)](resources/screenshoots/Laravel-Rebel-banner.png)

 [![Laravel 12|13](https://camo.githubusercontent.com/9e9b743bcbf97a29fe735334a4a8e906d05d60310969905af6607cef8da30138/68747470733a2f2f696d672e736869656c64732e696f2f62616467652f4c61726176656c2d313225323025374325323031332d4646324432303f7374796c653d666c61742d737175617265266c6f676f3d6c61726176656c266c6f676f436f6c6f723d7768697465)](https://camo.githubusercontent.com/9e9b743bcbf97a29fe735334a4a8e906d05d60310969905af6607cef8da30138/68747470733a2f2f696d672e736869656c64732e696f2f62616467652f4c61726176656c2d313225323025374325323031332d4646324432303f7374796c653d666c61742d737175617265266c6f676f3d6c61726176656c266c6f676f436f6c6f723d7768697465) [![PHP 8.3+](https://camo.githubusercontent.com/6aa777dd33ef43fbef727d8187b578003a61e5dc41bbc958b0938c996cdc92f2/68747470733a2f2f696d672e736869656c64732e696f2f62616467652f5048502d382e33253230253743253230382e34253230253743253230382e352d3737374242343f7374796c653d666c61742d737175617265266c6f676f3d706870266c6f676f436f6c6f723d7768697465)](https://camo.githubusercontent.com/6aa777dd33ef43fbef727d8187b578003a61e5dc41bbc958b0938c996cdc92f2/68747470733a2f2f696d672e736869656c64732e696f2f62616467652f5048502d382e33253230253743253230382e34253230253743253230382e352d3737374242343f7374796c653d666c61742d737175617265266c6f676f3d706870266c6f676f436f6c6f723d7768697465) [![PHPStan max](https://camo.githubusercontent.com/4b9a3c97d76534abb905e64bd9e5bb9f13fe68e962071e0ccbbe7b629112f11c/68747470733a2f2f696d672e736869656c64732e696f2f62616467652f5048505374616e2d6d61782d3241364644423f7374796c653d666c61742d737175617265)](https://camo.githubusercontent.com/4b9a3c97d76534abb905e64bd9e5bb9f13fe68e962071e0ccbbe7b629112f11c/68747470733a2f2f696d672e736869656c64732e696f2f62616467652f5048505374616e2d6d61782d3241364644423f7374796c653d666c61742d737175617265) [![Pest 4](https://camo.githubusercontent.com/9b9da1d7d243a7465ab338e9374e47300a7fe2e26b5c291e7e3c95b53153789a/68747470733a2f2f696d672e736869656c64732e696f2f62616467652f74657374732d50657374253230342d3232433535453f7374796c653d666c61742d737175617265)](https://camo.githubusercontent.com/9b9da1d7d243a7465ab338e9374e47300a7fe2e26b5c291e7e3c95b53153789a/68747470733a2f2f696d672e736869656c64732e696f2f62616467652f74657374732d50657374253230342d3232433535453f7374796c653d666c61742d737175617265) [![PSD2 SCA](https://camo.githubusercontent.com/1351d882909769ee61f029d6a51094927801dc6bb29c2cd1d12c62055275a290/68747470733a2f2f696d672e736869656c64732e696f2f62616467652f505344322532465343412d64796e616d69632532306c696e6b696e672d3842354346363f7374796c653d666c61742d737175617265)](https://camo.githubusercontent.com/1351d882909769ee61f029d6a51094927801dc6bb29c2cd1d12c62055275a290/68747470733a2f2f696d672e736869656c64732e696f2f62616467652f505344322532465343412d64796e616d69632532306c696e6b696e672d3842354346363f7374796c653d666c61742d737175617265) [![passwordless](https://camo.githubusercontent.com/3b9b9348549d27b6b985b8172958e6a4c6f23ffe64d8cee6384fdbf9e8f5a5b6/68747470733a2f2f696d672e736869656c64732e696f2f62616467652f70617373776f72646c6573732d706173736b65792d2d66697273742d3045413545393f7374796c653d666c61742d737175617265)](https://camo.githubusercontent.com/3b9b9348549d27b6b985b8172958e6a4c6f23ffe64d8cee6384fdbf9e8f5a5b6/68747470733a2f2f696d672e736869656c64732e696f2f62616467652f70617373776f72646c6573732d706173736b65792d2d66697273742d3045413545393f7374796c653d666c61742d737175617265) [![MIT](https://camo.githubusercontent.com/ac049ef4e7a0b7196b09add6ac2d4f180e544c0ac779c2b2ac2fd2723a209579/68747470733a2f2f696d672e736869656c64732e696f2f62616467652f6c6963656e73652d4d49542d626c75653f7374796c653d666c61742d737175617265)](https://camo.githubusercontent.com/ac049ef4e7a0b7196b09add6ac2d4f180e544c0ac779c2b2ac2fd2723a209579/68747470733a2f2f696d672e736869656c64732e696f2f62616467652f6c6963656e73652d4d49542d626c75653f7374796c653d666c61742d737175617265)

---

Table of contents
-----------------

[](#table-of-contents)

- [What Laravel Rebel is](#what-laravel-rebel-is)
- [Rebel vs Shopify vs the rest — the card-battle](#rebel-vs-shopify-vs-the-rest--the-card-battle)
- [The package map](#the-package-map)
- [Dependency DAG](#dependency-dag)
- [What you can do, end to end](#what-you-can-do-end-to-end)
- [Narrated flows](#narrated-flows)
- [Web Admin Panel](#web-admin-panel)
- [Install](#install)
- [Compliance](#compliance)
- [Quality bar](#quality-bar)
- [License](#license)

---

What Laravel Rebel is
---------------------

[](#what-laravel-rebel-is)

**Rebel is the control plane for authentication.** Laravel Fortify gives you the plumbing (login, 2FA enrolment, passkeys); Rebel adds the *policy, intelligence and operations* on top:

- **Passwordless &amp; passkey-first** login — email-OTP and WebAuthn, for web **and** mobile (Laravel Sanctum access + refresh tokens).
- **Risk-based step-up** — require the *right strength* (NIST AAL/AMR) per action, with **PSD2/SCA dynamic linking** for payments.
- **Multi-channel verification** — SMS/WhatsApp/voice through pluggable providers (Twilio…), with **anti toll-fraud/IRSF** defences and provider fallback.
- **Session security** — refresh-token rotation with **reuse detection**, logout-everywhere, device trust.
- **Recovery** — single-use, HMAC-hashed backup codes.
- **Intelligence** — deterministic anomaly detection + an AI that **explains, never decides**.
- **Operations** — a permission-gated, tenant-aware admin API + a web panel.

Every piece is its own composer package: take only what you need, or the whole suite via this meta-package.

---

Rebel vs Shopify vs the rest — the card-battle
----------------------------------------------

[](#rebel-vs-shopify-vs-the-rest--the-card-battle)

How Rebel's auth stacks up against **Shopify**'s customer auth, Laravel **Fortify** alone, and **Sanctum/Passport** tokens:

Capability**Laravel Rebel**Shopify (customer auth)Fortify onlySanctum / PassportPasswordless email-OTP login✅✅❌❌Passkey-first (WebAuthn) login✅➖✅❌Mobile tokens (access + **refresh**)✅➖❌➖ (Sanctum: no refresh)Refresh-token **rotation + reuse detection**✅❌❌❌**Risk-based step-up** (per-action AAL/AMR)✅❌❌❌**PSD2/SCA dynamic linking** (amount+payee)✅❌❌❌SMS/WhatsApp/voice with provider **fallback**✅➖❌❌**Anti toll-fraud / IRSF** defences✅➖❌❌Device trust (remembered devices)✅✅❌❌Single-use, hashed **recovery codes**✅✅➖❌**Anomaly detection** + advisory AI✅➖ (opaque)❌❌Unified, HMAC'd **audit trail**✅➖❌❌**Web admin panel** for security ops✅✅ (Shopify-hosted)❌❌NIST AAL / PSD2 / GDPR aware✅➖❌❌**Multi-tenant**✅❌❌❌**Self-hosted, you own the data**✅❌✅✅PHPStan **max**, Pest-tested, modular✅n/a➖➖> Legend: ✅ built-in · ➖ partial / hosted-only / DIY · ❌ not available · n/a closed-source. Shopify is a great hosted product — but it's a black box you don't control or extend. Rebel gives you the same capabilities (and several Shopify doesn't have, like PSD2/SCA dynamic linking and refresh-token reuse detection) **in your own Laravel app, self-hosted, auditable, and multi-tenant.**

---

The package map
---------------

[](#the-package-map)

PackageWhat it does[`laravel-rebel-core`](https://github.com/padosoft/laravel-rebel-core)The shared language: assurance (AAL/AMR), security context, contracts, keyed hashing, audit log, tenancy.[`laravel-rebel-email-otp`](https://github.com/padosoft/laravel-rebel-email-otp)Passwordless email-OTP login (anti-enumeration, rate limit, atomic verify, Sanctum tokens).[`laravel-rebel-bridge-fortify`](https://github.com/padosoft/laravel-rebel-bridge-fortify)Exposes Fortify password/TOTP/passkey as step-up drivers + maps Fortify events to the audit.[`laravel-rebel-step-up`](https://github.com/padosoft/laravel-rebel-step-up)Per-action step-up with AAL/AMR enforcement and **PSD2/SCA dynamic linking**.[`laravel-rebel-channels`](https://github.com/padosoft/laravel-rebel-channels)Verification routing (SMS/WhatsApp/voice): bot gate, anti-IRSF, rate limit, provider fallback.[`laravel-rebel-channel-twilio`](https://github.com/padosoft/laravel-rebel-channel-twilio)Twilio Verify provider for the channels layer (live-tested).[`laravel-rebel-sessions`](https://github.com/padosoft/laravel-rebel-sessions)Session/refresh-token registry: rotation + **reuse detection**, logout-everywhere, device trust.[`laravel-rebel-recovery`](https://github.com/padosoft/laravel-rebel-recovery)Single-use, HMAC-hashed recovery (backup) codes.[`laravel-rebel-ai-guard`](https://github.com/padosoft/laravel-rebel-ai-guard)Deterministic anomaly detection + an AI that **explains, never decides**.[`laravel-rebel-admin-api`](https://github.com/padosoft/laravel-rebel-admin-api)Permission-gated, tenant-aware control-plane read API (metrics, funnels, audit explorer).[`laravel-rebel-admin`](https://github.com/padosoft/laravel-rebel-admin)The web admin panel (Blade + vanilla JS) over the admin API.[`laravel-rebel-auth`](https://github.com/padosoft/laravel-rebel-auth)**This meta-package** — installs and ties the suite together.*Optional providers/bridges*`channel-vonage`, `channel-bird`, `channel-telegram`, `channel-discord`, `bridge-passkeys`, `bridge-spatie-otp`, `bridge-laragear-2fa`, `bridge-otpz`, `bot-protection`.---

Dependency DAG
--------------

[](#dependency-dag)

```
                         laravel-rebel-core
                                 |  (assurance, contracts, audit, tenancy, keyed hashing)
       +--------------+----------+---------------+---------------+-------------+
       v              v          v               v               v             v
  email-otp        channels   sessions        recovery       ai-guard      admin-api
       |              |                                                        |
       v              v                                                        v
  step-up   channel-twilio --> channels      (providers/bridges plug in)

```

Install order follows the arrows: **core first**, then the leaves; `channel-twilio` after `channels`; `admin` after `admin-api`.

---

What you can do, end to end
---------------------------

[](#what-you-can-do-end-to-end)

- **Log a customer in without a password** — email -&gt; OTP -&gt; access + refresh token (mobile) or session (web); or **passkey-first** with email-OTP fallback.
- **Force a strong re-auth before a risky action** — "this checkout needs a phishing-resistant passkey", bound to the exact amount + payee (PSD2/SCA).
- **Send verifications safely** — across SMS/WhatsApp/voice with provider fallback, geo allowlist and per-prefix circuit breaker so toll-fraud can't drain your budget.
- **Detect token theft** — a replayed refresh token burns the whole session.
- **Recover lost access** — single-use backup codes behind a high-assurance step-up.
- **See and explain what's happening** — a tenant-aware admin panel with metrics, funnels and an audit explorer, plus deterministic anomaly cases an AI can narrate.

---

Narrated flows
--------------

[](#narrated-flows)

**1) Customer passwordless login (mobile)**

```
POST /login {email}  -> email-otp: send code (anti-enumeration, rate-limited)
POST /verify {code}  -> atomic single-use verify -> LoginResult -> Sanctum access + refresh tokens
                        (refresh tokens tracked by laravel-rebel-sessions, rotated on use)

```

**2) Checkout of a credit order (PSD2/SCA)**

```
POST /checkout  -> middleware rebel.stepup:checkout-credit-order
                   policy: AAL2 + phishing-resistant -> only a passkey qualifies
                   step-up bound to (amount, currency, payee, orderRef) via HMAC dynamic linking
user confirms with passkey (bridge-fortify driver) -> binding matches -> order proceeds
                   if the amount changes -> binding_mismatch -> re-authenticate

```

**3) Account recovery**

```
user lost device -> submits a recovery code (laravel-rebel-recovery, single-use, hashed)
                    gated behind a high-assurance step-up purpose -> access restored
                    every step audited; anomalies (e.g. many failures) raise an ai-guard case

```

---

Web Admin Panel
---------------

[](#web-admin-panel)

A security-operations dashboard ([`laravel-rebel-admin`](https://github.com/padosoft/laravel-rebel-admin)) sits on top of the admin API: security overview, OTP/step-up funnels, channel performance, provider health, audit explorer, device &amp; session trust, risk rules, anomaly cases, an AI copilot, and a compliance center — light/dark, tenant-aware, fail-closed.

 [![Laravel Rebel Web Admin Panel](resources/screenshoots/Laravel-Rebel-Web-Panel-dasboard-dark.png)](resources/screenshoots/Laravel-Rebel-Web-Panel-dasboard-dark.png)

---

Install
-------

[](#install)

Install the whole suite via this meta-package:

```
composer require padosoft/laravel-rebel-auth
```

…or cherry-pick the packages you need (each has its own quick-start README). Optional channel providers and bridges are listed under `suggest` — e.g. add Twilio:

```
composer require padosoft/laravel-rebel-channel-twilio
```

Then publish migrations/config from the packages you use and run `php artisan migrate`. Each package's README has a junior-proof, copy-paste quick start.

---

Compliance
----------

[](#compliance)

- **NIST 800-63B**: explicit AAL/AMR on every factor; passkeys are phishing-resistant; step-up enforces the required assurance and decays it on policy change.
- **PSD2/SCA**: dynamic linking binds a strong confirmation to amount + payee; the binding is a keyed HMAC with key rotation.
- **GDPR**: identifiers and IPs are stored as keyed HMACs (never plaintext); audit metadata is sanitized; AI prompts are scrubbed of PII/secrets.

---

Quality bar
-----------

[](#quality-bar)

Every package in the suite ships with: **PHPStan level max**, **Pest** tests, **Pint** code style, a CI matrix across **PHP 8.3 / 8.4 / 8.5 × Laravel 12 / 13**, a didactic README with a competitor comparison, and a full local + dual-bot (Codex + Copilot) review on every release.

---

🔋 Vibe coding with batteries included
-------------------------------------

[](#-vibe-coding-with-batteries-included)

Every package in the suite ships **AI batteries** — so you (and your AI agent) extend it correctly on the first try:

- **`CLAUDE.md`** — a concise AI working guide (purpose, conventions, architecture, how to extend, Definition of Done). Plain Markdown, so Claude Code, Cursor, Copilot and Codex all read it.
- **`AGENTS.md`** — the agent/workflow contract (branch → PR → CI → tag/release, the gates).
- **`.claude/skills/rebel-package-dev`** — an invocable skill encoding the suite's TDD loop, the **PHPStan-level-max** recipes, the security/telemetry rules, and the release discipline.

Open any repo in your AI editor and just start — the rules, guardrails and extension recipes come with it. The source-of-truth templates + the rollout plan live in [`docs/ai-batteries/`](docs/ai-batteries/).

---

License
-------

[](#license)

MIT — see [LICENSE](LICENSE). Built by [Padosoft](https://www.padosoft.com).

###  Health Score

37

—

LowBetter than 81% of packages

Maintenance91

Actively maintained with recent releases

Popularity1

Limited adoption so far

Community6

Small or concentrated contributor base

Maturity43

Maturing project, gaining track record

 Bus Factor1

Top contributor holds 100% of commits — single point of failure

How is this calculated?**Maintenance (25%)** — Last commit recency, latest release date, and issue-to-star ratio. Uses a 2-year decay window.

**Popularity (30%)** — Total and monthly downloads, GitHub stars, and forks. Logarithmic scaling prevents top-heavy scores.

**Community (15%)** — Contributors, dependents, forks, watchers, and maintainers. Measures real ecosystem engagement.

**Maturity (30%)** — Project age, version count, PHP version support, and release stability.

###  Release Activity

Cadence

Unknown

Total

1

Last Release

51d ago

### Community

Maintainers

![](https://avatars.githubusercontent.com/u/10467699?v=4)[Lorenzo](/maintainers/lopadova)[@lopadova](https://github.com/lopadova)

---

Top Contributors

[![lopadova](https://avatars.githubusercontent.com/u/10467699?v=4)](https://github.com/lopadova "lopadova (32 commits)")

---

Tags

laravelsecurityAuthenticationpadosoftRebel

###  Code Quality

TestsPest

Static AnalysisPHPStan

Code StyleLaravel Pint

### Embed Badge

![Health badge](/badges/padosoft-laravel-rebel-auth/health.svg)

```
[![Health](https://phpackages.com/badges/padosoft-laravel-rebel-auth/health.svg)](https://phpackages.com/packages/padosoft-laravel-rebel-auth)
```

###  Alternatives

[spatie/laravel-permission

Permission handling for Laravel 12 and up

12.9k102.4M1.5k](/packages/spatie-laravel-permission)[defstudio/telegraph

A laravel facade to interact with Telegram Bots

813336.8k3](/packages/defstudio-telegraph)[harris21/laravel-fuse

Circuit breaker for Laravel queue jobs. Protect your workers from cascading failures.

45955.7k](/packages/harris21-laravel-fuse)[rawilk/profile-filament-plugin

Profile &amp; MFA starter kit for filament.

3914.8k](/packages/rawilk-profile-filament-plugin)[masterix21/laravel-licensing

Laravel licensing package with polymorphic assignment to any model, activation keys, expirations/renewals, and seat control via LicenseUsage. Supports offline verification with public-key–signed tokens, a CLI to generate/rotate/revoke keys, and an extensible architecture via config and contracts.

1613.3k4](/packages/masterix21-laravel-licensing)[simplestats-io/laravel-client

Server-side analytics for Laravel that follows the full funnel from visit to registration to payment, attributed to the channel that drove it. Revenue, MRR, churn and ad-spend profit (ROAS/CAC) per channel. GDPR compliant, ad-blocker proof.

5022.6k](/packages/simplestats-io-laravel-client)

PHPackages © 2026

[Directory](/)[Categories](/categories)[Trending](/trending)[Changelog](/changelog)[Analyze](/analyze)
