PHPackages                             phalcon/rest-api - PHPackages - PHPackages  [Skip to content](#main-content)[PHPackages](/)[Directory](/)[Categories](/categories)[Trending](/trending)[Leaderboard](/leaderboard)[Changelog](/changelog)[Analyze](/analyze)[Collections](/collections)[Log in](/login)[Sign up](/register)

1. [Directory](/)
2. /
3. [Framework](/categories/framework)
4. /
5. phalcon/rest-api

ActiveProject[Framework](/categories/framework)

phalcon/rest-api
================

This is a sample REST API application for the Phalcon PHP Framework

v5.1.0(1mo ago)93234[3 issues](https://github.com/phalcon/rest-api/issues)BSD-3-ClausePHPPHP &gt;=8.1CI passing

Since Jul 9Pushed 2w ago21 watchersCompare

[ Source](https://github.com/phalcon/rest-api)[ Packagist](https://packagist.org/packages/phalcon/rest-api)[ Docs](https://phalcon.io)[ GitHub Sponsors](https://github.com/phalcon)[ Fund](https://opencollective.com/phalcon)[ RSS](/packages/phalcon-rest-api/feed)WikiDiscussions master Synced 1w ago

READMEChangelog (6)Dependencies (27)Versions (9)Used By (0)

Phalcon REST API
================

[](#phalcon-rest-api)

[![Latest Version](https://camo.githubusercontent.com/b3dfc0f6350d04354e80dc16b7cafdfd2a1e469b66a9c3664488d3aa38938e52/68747470733a2f2f696d672e736869656c64732e696f2f7061636b61676973742f762f7068616c636f6e2f726573742d6170693f696e636c7564655f70726572656c6561736573267374796c653d666c61742d737175617265266c6f676f3d7061636b6167697374266c6f676f436f6c6f723d7768697465)](https://packagist.org/packages/phalcon/rest-api)[![PHP Version](https://camo.githubusercontent.com/dc31c63a2c00c7111150a8ad3a0aa60c68f5ddbb723274a7017d9e0117eb4e02/68747470733a2f2f696d672e736869656c64732e696f2f7061636b61676973742f7068702d762f7068616c636f6e2f726573742d6170693f7374796c653d666c61742d737175617265266c6f676f3d706870266c6f676f436f6c6f723d7768697465)](https://packagist.org/packages/phalcon/rest-api)[![Total Downloads](https://camo.githubusercontent.com/ee2b06c8e00d95ab1ca0a8e30df3e3e1d0d66b6db73bae44bc407029e87a5cc1/68747470733a2f2f696d672e736869656c64732e696f2f7061636b61676973742f64742f7068616c636f6e2f726573742d6170693f7374796c653d666c61742d737175617265266c6f676f3d7061636b6167697374266c6f676f436f6c6f723d7768697465)](https://packagist.org/packages/phalcon/rest-api/stats)[![License](https://camo.githubusercontent.com/d7e063c16d2b8e48abd08a4538b7f077fef0f493ba33481ef1ad268004c5afb8/68747470733a2f2f696d672e736869656c64732e696f2f6769746875622f6c6963656e73652f7068616c636f6e2f726573742d6170693f7374796c653d666c61742d737175617265266c6f676f3d6f70656e736f75726365696e6974696174697665266c6f676f436f6c6f723d7768697465)](https://github.com/phalcon/rest-api/blob/master/LICENSE)

[![REST API CI](https://github.com/phalcon/rest-api/actions/workflows/main.yml/badge.svg?branch=master)](https://github.com/phalcon/rest-api/actions/workflows/main.yml)[![Quality Gate Status](https://camo.githubusercontent.com/e40b55bc2751977df2445e440e179aa159933bd3dadeacaeee1f8ed13ac28e0f/68747470733a2f2f736f6e6172636c6f75642e696f2f6170692f70726f6a6563745f6261646765732f6d6561737572653f70726f6a6563743d7068616c636f6e5f726573742d617069266d65747269633d616c6572745f737461747573)](https://sonarcloud.io/summary/new_code?id=phalcon_rest-api)[![Coverage](https://camo.githubusercontent.com/dfd263a41350cc26ca07e95c6c548eec37f0be86d6331260ad63c292a215c487/68747470733a2f2f736f6e6172636c6f75642e696f2f6170692f70726f6a6563745f6261646765732f6d6561737572653f70726f6a6563743d7068616c636f6e5f726573742d617069266d65747269633d636f766572616765)](https://sonarcloud.io/summary/new_code?id=phalcon_rest-api)[![PDS Skeleton](https://camo.githubusercontent.com/50d01a5094afcc3a827c3cadaec43d23b2a256cb249f5fdd6e5ffdb53ea7971c/68747470733a2f2f696d672e736869656c64732e696f2f62616467652f7064732d736b656c65746f6e2d626c75652e7376673f7374796c653d666c61742d737175617265)](https://github.com/php-pds/skeleton)

[![Discord](https://camo.githubusercontent.com/94fc3d9eff10556bb8115023b0f05a2b7465d01e863e0d7bb030e8fc51cfcf56/68747470733a2f2f696d672e736869656c64732e696f2f646973636f72642f3331303931303438383135323337353239373f6c6162656c3d446973636f7264266c6f676f3d646973636f7264267374796c653d666c61742d737175617265)](https://phalcon.io/discord)[![Contributors](https://camo.githubusercontent.com/602b47c8930e8e1b1505faf3ef75010f4d213abf38ae940b40a6a189f0f7e038/68747470733a2f2f696d672e736869656c64732e696f2f6769746875622f636f6e7472696275746f72732f7068616c636f6e2f726573742d6170693f7374796c653d666c61742d737175617265266c6f676f3d676974687562266c6f676f436f6c6f723d7768697465)](https://github.com/phalcon/rest-api/graphs/contributors)[![OpenCollective Backers](https://camo.githubusercontent.com/b0e7e54861423843ca8c0b82b3cbdbd7e43557493dee35be2c721a9cc21107a1/68747470733a2f2f696d672e736869656c64732e696f2f6f70656e636f6c6c6563746976652f6261636b6572732f7068616c636f6e3f7374796c653d666c61742d737175617265266c6f676f3d6f70656e636f6c6c656374697665266c6f676f436f6c6f723d7768697465)](https://opencollective.com/phalcon)[![OpenCollective Sponsors](https://camo.githubusercontent.com/09f0801da6213d104e2283e28a70b5b5c9aa25076b9211442e403187c64ca12b/68747470733a2f2f696d672e736869656c64732e696f2f6f70656e636f6c6c6563746976652f73706f6e736f72732f7068616c636f6e3f7374796c653d666c61742d737175617265266c6f676f3d6f70656e636f6c6c656374697665266c6f676f436f6c6f723d7768697465)](https://opencollective.com/phalcon)

A sample REST API for the [Phalcon Framework](https://github.com/phalcon/cphalcon). It showcases JWT authentication, a [JSON:API](https://jsonapi.org) response layer (sparse fieldsets, includes, sorting), a lazy middleware chain, and the model / repository / transformer split behind it.

It runs on **Phalcon v5** (the C extension, default) and on **Phalcon v6**(the `phalcon/phalcon` package) from the same source.

Requirements
------------

[](#requirements)

- PHP 8.1 or newer
- MySQL 8.0 and Redis (both provided by the Docker stack)
- Docker + Docker Compose (recommended), or a local PHP with the Phalcon extension (see [docs/installation.md](docs/installation.md))

Quick start (Docker)
--------------------

[](#quick-start-docker)

```
cp resources/.env.example .env
docker compose up -d --build

# Create the database schema (migrations are not run on boot)
docker compose exec app composer install
docker compose exec app composer migrate
```

The API is then served at . There are no bundled fixtures, so every collection starts empty; see [docs/usage.md](docs/usage.md) for the request and response format and how authentication works.

> **Note:** `app` is the Compose *service* name, used as-is by `docker compose exec`. The running container is named `${PROJECT_PREFIX}-app` (`rest-api-app` by default, set via `PROJECT_PREFIX` in `.env`). If you address it with plain `docker exec`, use the container name, e.g. `docker exec rest-api-app composer migrate`.

### Choosing the Phalcon and PHP versions

[](#choosing-the-phalcon-and-php-versions)

```
docker compose up -d --build                      # v5 (C extension, default)
PHALCON_VARIANT=v6 docker compose up -d --build   # v6 (phalcon/phalcon)

PHP_VERSION=8.1 docker compose up -d --build       # pick a PHP version (8.1+)
```

The two Phalcon variants are mutually exclusive: the v5 image installs the C extension, the v6 image installs the pure-PHP package instead. `APP_PORT` in `.env` changes the host port, so this app can run alongside the other Phalcon sample applications. [docs/installation.md](docs/installation.md) covers running several versions side by side.

Quick start (Composer)
----------------------

[](#quick-start-composer)

Prefer a local PHP over Docker? Bootstrap a fresh copy straight from Packagist:

```
composer create-project phalcon/rest-api rest-api
cd rest-api
```

The post-create hook copies `resources/.env.example` to `.env` and prints the next steps. [docs/installation.md](docs/installation.md) has the full local walkthrough (installing the Phalcon extension with [PIE](https://github.com/php/pie), the database, and serving).

Composer scripts
----------------

[](#composer-scripts)

Run them inside the container, e.g. `docker compose exec app composer cs`:

ScriptDescription`composer cs`PHP\_CodeSniffer (PSR-12)`composer cs-fix`Auto-fix coding standard issues (phpcbf)`composer cs-fixer`PHP CS Fixer (dry-run)`composer cs-fixer-fix`Apply PHP CS Fixer`composer analyze`PHPStan static analysis (level 8)`composer test`The default (unit) PHPUnit suite via `vendor/bin/talon``composer test-coverage`PHPUnit + Clover coverage (`tests/_output/coverage.xml`)`composer test-mutation`Infection mutation testing (see below)`composer migrate`Run database migrations (Phinx)> `composer analyze` resolves Phalcon classes from the `phalcon/phalcon` (v6) source, so run it where the v5 C extension is **not** loaded (the CI `quality` job, or a plain host). The coding-standard and test scripts are unaffected.

Features
--------

[](#features)

- **JWT authentication** - [JSON Web Tokens](https://jwt.io) let a client authenticate once at `/login` and then carry a bearer token; the token lifetime is configurable in `.env`.
- **JSON:API responses** - every response follows the [JSON:API](https://jsonapi.org)standard: a uniform envelope, compound documents, includes (related data), sparse fieldsets, and sorting.
- **A lazy middleware chain** - `NotFound`, `Authentication`, and `Response`, each attached to the Micro application and resolved only when a request reaches it.
- **Public fields are opt-in per model** - a model declares exactly which columns the API may publish, so adding a column never exposes it by accident (`Users`, for instance, never returns its password or token secrets).

See [docs/usage.md](docs/usage.md) for the endpoints, query parameters, and response format.

Running the tests
-----------------

[](#running-the-tests)

The suite is split into four PHPUnit testsuites - `unit`, `integration`, `api`, and `cli` - orchestrated by [`phalcon/talon`](https://github.com/phalcon/talon). The `api` suite drives the running application over real HTTP, so it needs the web server up (nginx in the Docker stack, reached via `TALON_REST_URL` in `tests/.env.test`).

```
docker compose exec app composer migrate    # once - create the schema
docker compose exec app composer test       # the default (unit) suite
docker compose exec app vendor/bin/talon run all   # every suite, one process each
```

### Mutation testing

[](#mutation-testing)

`composer test-mutation` runs [Infection](https://infection.github.io/). The dependency is **not** shipped - it pulls `thecodingmachine/safe` at `dev-master`, which deprecation-warns on newer PHP - so install it on demand:

```
docker compose exec app composer require --dev infection/infection
docker compose exec app composer test-mutation
docker compose exec app composer remove --dev infection/infection
```

The configuration in `resources/infection.json5` stays in the repository. Runs are single-threaded on purpose: the suite shares one MySQL database, so parallel mutants would corrupt each other's data.

Project layout
--------------

[](#project-layout)

Follows the [PDS skeleton](https://github.com/php-pds/skeleton):

```
bin/        command-line entry point (bin/cli)
public/     web server root (index.php)
resources/  tooling configs, docker, phinx, migrations
src/        application source
tests/      PHPUnit suites (unit, integration, api, cli)
storage/    runtime cache and logs

```

Documentation
-------------

[](#documentation)

- [docs/installation.md](docs/installation.md) - Docker and local (non-Docker) setup
- [docs/usage.md](docs/usage.md) - endpoints, includes, sparse fields, sorting, and the response format

License
-------

[](#license)

Phalcon REST API is open-sourced software licensed under the New BSD License. See [LICENSE](LICENSE).

###  Health Score

56

—

FairBetter than 97% of packages

Maintenance93

Actively maintained with recent releases

Popularity20

Limited adoption so far

Community23

Small or concentrated contributor base

Maturity77

Established project with proven stability

 Bus Factor1

Top contributor holds 87.9% of commits — single point of failure

How is this calculated?**Maintenance (25%)** — Last commit recency, latest release date, and issue-to-star ratio. Uses a 2-year decay window.

**Popularity (30%)** — Total and monthly downloads, GitHub stars, and forks. Logarithmic scaling prevents top-heavy scores.

**Community (15%)** — Contributors, dependents, forks, watchers, and maintainers. Measures real ecosystem engagement.

**Maturity (30%)** — Project age, version count, PHP version support, and release stability.

###  Release Activity

Cadence

Every ~586 days

Recently: every ~726 days

Total

6

Last Release

45d ago

Major Versions

v1.1.1 → v2.0.02019-12-26

v2.0.0 → v5.0.02022-09-25

PHP version history (4 changes)v1.0.0PHP &gt;= 7.1

v2.0.0PHP &gt;=7.2

v5.0.0PHP &gt;=8.0

v5.1.0PHP &gt;=8.1

### Community

Maintainers

![](https://avatars.githubusercontent.com/u/1221505?v=4)[The Phalcon PHP Framework](/maintainers/phalcon)[@phalcon](https://github.com/phalcon)

---

Top Contributors

[![niden](https://avatars.githubusercontent.com/u/1073784?v=4)](https://github.com/niden "niden (415 commits)")[![Jeckerson](https://avatars.githubusercontent.com/u/3289702?v=4)](https://github.com/Jeckerson "Jeckerson (43 commits)")[![dependabot[bot]](https://avatars.githubusercontent.com/in/29110?v=4)](https://github.com/dependabot[bot] "dependabot[bot] (10 commits)")[![sergeyklay](https://avatars.githubusercontent.com/u/1256298?v=4)](https://github.com/sergeyklay "sergeyklay (2 commits)")[![Arhell](https://avatars.githubusercontent.com/u/26163841?v=4)](https://github.com/Arhell "Arhell (1 commits)")[![ruudboon](https://avatars.githubusercontent.com/u/7444246?v=4)](https://github.com/ruudboon "ruudboon (1 commits)")

---

Tags

apijson-apijsonapijwtphalconphalcon-phprestrest-apirestful-apitutorialapiframeworkrestphalconREST APIsample app

###  Code Quality

TestsPHPUnit

Static AnalysisPHPStan, Psalm

Code StylePHP CS Fixer

Type Coverage Yes

### Embed Badge

![Health badge](/badges/phalcon-rest-api/health.svg)

```
[![Health](https://phpackages.com/badges/phalcon-rest-api/health.svg)](https://phpackages.com/packages/phalcon-rest-api)
```

###  Alternatives

[laravel/framework

The Laravel Framework.

35.4k569.8M21.9k](/packages/laravel-framework)[zemit-cms/core

Build Phalcon REST APIs faster with database-first scaffolding, model relationships, eager loading, identity, permissions, CLI, and WebSocket support.

148.5k1](/packages/zemit-cms-core)[tempest/framework

The PHP framework that gets out of your way.

2.3k42.4k21](/packages/tempest-framework)[bullhorn/fast-rest

FastREST generates REST-ready models and controllers dynamically from a MySQL database schema, including foreign keys, table and column comments, and indexes.

258.0k](/packages/bullhorn-fast-rest)

PHPackages © 2026

[Directory](/)[Categories](/categories)[Trending](/trending)[Changelog](/changelog)[Analyze](/analyze)
