PHPackages                             padosoft/laravel-rebel-sessions - PHPackages - PHPackages  [Skip to content](#main-content)[PHPackages](/)[Directory](/)[Categories](/categories)[Trending](/trending)[Leaderboard](/leaderboard)[Changelog](/changelog)[Analyze](/analyze)[Collections](/collections)[Log in](/login)[Sign up](/register)

1. [Directory](/)
2. /
3. [Authentication &amp; Authorization](/categories/authentication)
4. /
5. padosoft/laravel-rebel-sessions

ActiveLibrary[Authentication &amp; Authorization](/categories/authentication)

padosoft/laravel-rebel-sessions
===============================

Device/session registry for Laravel Rebel: session/device tracking, logout-everywhere, refresh-token rotation with reuse detection, and device trust. Part of padosoft/laravel-rebel-\*.

v0.1.0(1mo ago)0198↓90%[1 PRs](https://github.com/padosoft/laravel-rebel-sessions/pulls)2MITPHPPHP ^8.3CI passing

Since Jun 3Pushed 1mo agoCompare

[ Source](https://github.com/padosoft/laravel-rebel-sessions)[ Packagist](https://packagist.org/packages/padosoft/laravel-rebel-sessions)[ Docs](https://github.com/padosoft/laravel-rebel-sessions)[ RSS](/packages/padosoft-laravel-rebel-sessions/feed)WikiDiscussions main Synced 1w ago

READMEChangelog (1)Dependencies (9)Versions (5)Used By (2)

Laravel Rebel — Sessions
========================

[](#laravel-rebel--sessions)

> Official documentation:

> **Refresh-token rotation with reuse detection, logout-everywhere, and device trust.** When a stolen refresh token is replayed, Rebel detects the reuse and **burns the whole session — every token of that user** — instead of silently handing the attacker a fresh one. Plus remembered-device trust to cut step-up friction. Part of the `padosoft/laravel-rebel-*` suite.

 [![Laravel Rebel](resources/screenshoots/Laravel-Rebel-banner.png)](resources/screenshoots/Laravel-Rebel-banner.png)

 [![Laravel 12|13](https://camo.githubusercontent.com/9e9b743bcbf97a29fe735334a4a8e906d05d60310969905af6607cef8da30138/68747470733a2f2f696d672e736869656c64732e696f2f62616467652f4c61726176656c2d313225323025374325323031332d4646324432303f7374796c653d666c61742d737175617265266c6f676f3d6c61726176656c266c6f676f436f6c6f723d7768697465)](https://camo.githubusercontent.com/9e9b743bcbf97a29fe735334a4a8e906d05d60310969905af6607cef8da30138/68747470733a2f2f696d672e736869656c64732e696f2f62616467652f4c61726176656c2d313225323025374325323031332d4646324432303f7374796c653d666c61742d737175617265266c6f676f3d6c61726176656c266c6f676f436f6c6f723d7768697465) [![PHP 8.3+](https://camo.githubusercontent.com/6aa777dd33ef43fbef727d8187b578003a61e5dc41bbc958b0938c996cdc92f2/68747470733a2f2f696d672e736869656c64732e696f2f62616467652f5048502d382e33253230253743253230382e34253230253743253230382e352d3737374242343f7374796c653d666c61742d737175617265266c6f676f3d706870266c6f676f436f6c6f723d7768697465)](https://camo.githubusercontent.com/6aa777dd33ef43fbef727d8187b578003a61e5dc41bbc958b0938c996cdc92f2/68747470733a2f2f696d672e736869656c64732e696f2f62616467652f5048502d382e33253230253743253230382e34253230253743253230382e352d3737374242343f7374796c653d666c61742d737175617265266c6f676f3d706870266c6f676f436f6c6f723d7768697465) [![PHPStan max](https://camo.githubusercontent.com/4b9a3c97d76534abb905e64bd9e5bb9f13fe68e962071e0ccbbe7b629112f11c/68747470733a2f2f696d672e736869656c64732e696f2f62616467652f5048505374616e2d6d61782d3241364644423f7374796c653d666c61742d737175617265)](https://camo.githubusercontent.com/4b9a3c97d76534abb905e64bd9e5bb9f13fe68e962071e0ccbbe7b629112f11c/68747470733a2f2f696d672e736869656c64732e696f2f62616467652f5048505374616e2d6d61782d3241364644423f7374796c653d666c61742d737175617265) [![Pest 4](https://camo.githubusercontent.com/9b9da1d7d243a7465ab338e9374e47300a7fe2e26b5c291e7e3c95b53153789a/68747470733a2f2f696d672e736869656c64732e696f2f62616467652f74657374732d50657374253230342d3232433535453f7374796c653d666c61742d737175617265)](https://camo.githubusercontent.com/9b9da1d7d243a7465ab338e9374e47300a7fe2e26b5c291e7e3c95b53153789a/68747470733a2f2f696d672e736869656c64732e696f2f62616467652f74657374732d50657374253230342d3232433535453f7374796c653d666c61742d737175617265) [![reuse detection](https://camo.githubusercontent.com/3a3ee9e2a40eb7ad8750291b4429a49338c682b28d6a5df23cf7be25a290e244/68747470733a2f2f696d672e736869656c64732e696f2f62616467652f726566726573682d72657573652d2d646574656374696f6e2d3842354346363f7374796c653d666c61742d737175617265)](https://camo.githubusercontent.com/3a3ee9e2a40eb7ad8750291b4429a49338c682b28d6a5df23cf7be25a290e244/68747470733a2f2f696d672e736869656c64732e696f2f62616467652f726566726573682d72657573652d2d646574656374696f6e2d3842354346363f7374796c653d666c61742d737175617265) [![MIT](https://camo.githubusercontent.com/ac049ef4e7a0b7196b09add6ac2d4f180e544c0ac779c2b2ac2fd2723a209579/68747470733a2f2f696d672e736869656c64732e696f2f62616467652f6c6963656e73652d4d49542d626c75653f7374796c653d666c61742d737175617265)](https://camo.githubusercontent.com/ac049ef4e7a0b7196b09add6ac2d4f180e544c0ac779c2b2ac2fd2723a209579/68747470733a2f2f696d672e736869656c64732e696f2f62616467652f6c6963656e73652d4d49542d626c75653f7374796c653d666c61742d737175617265)

---

Table of contents
-----------------

[](#table-of-contents)

- [What it is](#what-it-is)
- [Quick glossary](#quick-glossary)
- [Why this package](#why-this-package)
- [Rebel Sessions vs the alternatives](#rebel-sessions-vs-the-alternatives)
- [How rotation + reuse detection works](#how-rotation--reuse-detection-works)
- [Installation](#installation)
- [Usage](#usage)
- [Security notes](#security-notes)
- [Testing &amp; License](#testing--license)

---

What it is
----------

[](#what-it-is)

The device/session **registry** for Rebel. It provides the default implementations of two core contracts — `SessionRegistry` (used by OTP/step-up for logout-everywhere and reuse checks) and `DeviceTrust` (remembered devices) — plus a `SessionManager` that does the real work: tracking sessions/refresh tokens and rotating them safely.

Depends on [`padosoft/laravel-rebel-core`](https://github.com/padosoft/laravel-rebel-core).

---

Quick glossary
--------------

[](#quick-glossary)

TermIn plain words**Refresh token**A long-lived token exchanged for a fresh access token (e.g. on mobile).**Rotation**Each use of a refresh token **consumes** it and issues a brand-new one.**Reuse detection**If an already-used refresh token shows up again, it was probably stolen → react.**Chain**All the refresh tokens descended from one original login, sharing a `root_id`.**Device trust**"Remember this device" so it can skip step-up for a while.---

Why this package
----------------

[](#why-this-package)

★WhatIn short★★★**Reuse detection that burns the chain**A replayed refresh token doesn't just fail — it revokes **all** the user's tokens (the correct theft response).★★★**Ownership + expiry enforced**A refresh token can only be rotated by its owner, and never after it expires.★★★**Race-safe rotation**Every rotation locks the chain root, so concurrent requests serialize and no sibling escapes a burn.★★**Logout-everywhere**One call revokes every active session/token of a subject.★★**Device trust**Remembered devices (by fingerprint hash) expire after N days; atomic, tenant-scoped.★★**Drop-in contracts**Implements the core `SessionRegistry` + `DeviceTrust` — OTP/step-up use them automatically.---

Rebel Sessions vs the alternatives
----------------------------------

[](#rebel-sessions-vs-the-alternatives)

Capability**Rebel Sessions**ShopifySanctum / Passport (native)Hand-rolledRefresh-token rotation you control✅❌➖ (Passport rotates, Sanctum has no refresh)❌**Reuse detection** (theft signal)✅❌❌❌Burns the **whole chain/user** on reuse✅❌❌❌Owner + expiry enforced on rotate✅➖➖❌Race-safe (chain-root locking)✅❌❌❌Programmatic logout-everywhere API✅➖➖➖Customer-facing login activity / logout✅✅❌❌Remembered-device trust API✅➖❌❌Multi-tenant + audit-friendly (your app)✅❌❌❌> Legend: ✅ built-in · ➖ partial / hosted-only / not exposed to you · ❌ not available.
>
> Note: Shopify is a hosted, closed commerce platform — it manages its own customer sessions and shows shoppers a "logged-in devices" view, but never exposes refresh-token rotation, reuse detection, or a device-trust API you can self-host or build on.

---

How rotation + reuse detection works
------------------------------------

[](#how-rotation--reuse-detection-works)

```
login → issue refresh R0 (root of the chain)
   │
client exchanges R0 ──► rotateRefresh(R0): consume R0, issue R1 (parent=R0, root=R0)
   │
client exchanges R1 ──► consume R1, issue R2 ...
   │
ATTACKER replays a stolen R0 ──► rotateRefresh(R0):
        R0 is already 'consumed' ⇒ REUSE ⇒ burn EVERY live token of the user
        (sessions + the whole refresh chain) and return null

```

A rotation can only proceed if the token is **active**, **owned by the caller**, and **not expired** — otherwise it returns null (and, for reuse, burns the user's tokens).

---

Installation
------------

[](#installation)

```
composer require padosoft/laravel-rebel-sessions
php artisan vendor:publish --tag="rebel-sessions-migrations"
php artisan migrate
```

The package binds the core `SessionRegistry` and `DeviceTrust` contracts automatically.

---

Usage
-----

[](#usage)

```
use Padosoft\Rebel\Sessions\Enums\SessionType;
use Padosoft\Rebel\Sessions\SessionManager;

$sessions = app(SessionManager::class);

// On login: open a session and issue a refresh token
$session = $sessions->start($user, SessionType::Session, ttlSeconds: 3600);
$refresh = $sessions->start($user, SessionType::Refresh, ttlSeconds: 60 * 60 * 24 * 30);

// On token refresh: rotate (null = reject; a stolen-token replay burns the chain)
$next = $sessions->rotateRefresh($refresh->id, $user);
if ($next === null) {
    // token unknown / expired / reused → force a fresh login
}

// Logout everywhere
$sessions->revokeAll($user);
```

Device trust:

```
use Padosoft\Rebel\Core\Context\DeviceContext;
use Padosoft\Rebel\Core\Contracts\DeviceTrust;

$trust = app(DeviceTrust::class);
$device = new DeviceContext(fingerprintHash: $hashOfThisDevice);

$trust->trust($user, $device, days: 30);   // "remember this device"
$trust->isTrusted($user, $device);          // true until it expires
$trust->untrust($user, $device);
```

---

Security notes
--------------

[](#security-notes)

- **Reuse = theft**: a replayed refresh token revokes every live token of the subject.
- **Ownership &amp; expiry**: rotation checks the token belongs to the caller and isn't expired.
- **Race-safe**: rotations lock the chain root row, so concurrent rotations serialize.
- **UUID** ids; **tenant-scoped** queries; device fingerprints stored as hashes (never raw).

---

🔋 Vibe coding with batteries included
-------------------------------------

[](#-vibe-coding-with-batteries-included)

This package ships **AI batteries** — so you (and your AI agent) can extend it correctly on the first try:

- **`CLAUDE.md`** — a concise AI working guide (purpose, conventions, architecture, how to extend, Definition of Done). Plain Markdown, so Claude Code, Cursor, Copilot and Codex all read it.
- **`AGENTS.md`** — the agent/workflow contract (branch → PR → CI → tag/release, the gates).
- **`.claude/skills/`** — invocable skills (at least `rebel-package-dev`) encoding the suite's TDD loop, the **PHPStan-level-max** recipes, the security/telemetry rules, and the release discipline.

Open the repo in your AI editor and just start — the rules, guardrails and extension recipes come with it. PRs that follow the shipped `CLAUDE.md` pass CI (PHPStan max + Pest + Pint) and review the first time around.

---

Testing &amp; License
---------------------

[](#testing--license)

```
composer test      # Pest (rotation, reuse-burn, ownership, expiry, logout-everywhere, device trust)
composer phpstan   # static analysis, level max
composer pint      # code style
```

**License:** MIT — see [LICENSE](LICENSE). Part of the [`padosoft/laravel-rebel`](https://github.com/padosoft) suite.

###  Health Score

41

—

FairBetter than 87% of packages

Maintenance91

Actively maintained with recent releases

Popularity13

Limited adoption so far

Community10

Small or concentrated contributor base

Maturity42

Maturing project, gaining track record

 Bus Factor1

Top contributor holds 100% of commits — single point of failure

How is this calculated?**Maintenance (25%)** — Last commit recency, latest release date, and issue-to-star ratio. Uses a 2-year decay window.

**Popularity (30%)** — Total and monthly downloads, GitHub stars, and forks. Logarithmic scaling prevents top-heavy scores.

**Community (15%)** — Contributors, dependents, forks, watchers, and maintainers. Measures real ecosystem engagement.

**Maturity (30%)** — Project age, version count, PHP version support, and release stability.

###  Release Activity

Cadence

Unknown

Total

1

Last Release

51d ago

### Community

Maintainers

![](https://avatars.githubusercontent.com/u/10467699?v=4)[Lorenzo](/maintainers/lopadova)[@lopadova](https://github.com/lopadova)

---

Top Contributors

[![lopadova](https://avatars.githubusercontent.com/u/10467699?v=4)](https://github.com/lopadova "lopadova (6 commits)")

---

Tags

laravelsecurityAuthenticationpadosoftRebel

###  Code Quality

TestsPest

Static AnalysisPHPStan

Code StyleLaravel Pint

### Embed Badge

![Health badge](/badges/padosoft-laravel-rebel-sessions/health.svg)

```
[![Health](https://phpackages.com/badges/padosoft-laravel-rebel-sessions/health.svg)](https://phpackages.com/packages/padosoft-laravel-rebel-sessions)
```

###  Alternatives

[spatie/laravel-permission

Permission handling for Laravel 12 and up

12.9k102.4M1.5k](/packages/spatie-laravel-permission)[defstudio/telegraph

A laravel facade to interact with Telegram Bots

813336.8k3](/packages/defstudio-telegraph)[harris21/laravel-fuse

Circuit breaker for Laravel queue jobs. Protect your workers from cascading failures.

45955.7k](/packages/harris21-laravel-fuse)[rawilk/profile-filament-plugin

Profile &amp; MFA starter kit for filament.

3914.8k](/packages/rawilk-profile-filament-plugin)[masterix21/laravel-licensing

Laravel licensing package with polymorphic assignment to any model, activation keys, expirations/renewals, and seat control via LicenseUsage. Supports offline verification with public-key–signed tokens, a CLI to generate/rotate/revoke keys, and an extensible architecture via config and contracts.

1613.3k4](/packages/masterix21-laravel-licensing)[simplestats-io/laravel-client

Server-side analytics for Laravel that follows the full funnel from visit to registration to payment, attributed to the channel that drove it. Revenue, MRR, churn and ad-spend profit (ROAS/CAC) per channel. GDPR compliant, ad-blocker proof.

5022.6k](/packages/simplestats-io-laravel-client)

PHPackages © 2026

[Directory](/)[Categories](/categories)[Trending](/trending)[Changelog](/changelog)[Analyze](/analyze)
