PHPackages                             php-opcua/opcua-client-ext-transport-https - PHPackages - PHPackages  [Skip to content](#main-content)[PHPackages](/)[Directory](/)[Categories](/categories)[Trending](/trending)[Leaderboard](/leaderboard)[Changelog](/changelog)[Analyze](/analyze)[Collections](/collections)[Log in](/login)[Sign up](/register)

1. [Directory](/)
2. /
3. [Parsing &amp; Serialization](/categories/parsing)
4. /
5. php-opcua/opcua-client-ext-transport-https

ActiveLibrary[Parsing &amp; Serialization](/categories/parsing)

php-opcua/opcua-client-ext-transport-https
==========================================

OPC UA HTTPS transport (Part 6 §7.4) for PHP — Binary / JSON / XML-SOAP encodings over opc.https://, extends opcua-client

v4.4.0(1mo ago)00MITPHPPHP ^8.2

Since Jun 4Pushed 1mo agoCompare

[ Source](https://github.com/php-opcua/opcua-client-ext-transport-https)[ Packagist](https://packagist.org/packages/php-opcua/opcua-client-ext-transport-https)[ Docs](https://github.com/php-opcua/opcua-client-ext-transport-https)[ RSS](/packages/php-opcua-opcua-client-ext-transport-https/feed)WikiDiscussions master Synced 1w ago

READMEChangelog (1)Dependencies (5)Versions (2)Used By (0)

**OPC UA HTTPS Transport — PHP**
================================

[](#opc-ua-https-transport--php)

    ![OPC UA HTTPS Transport — PHP](assets/logo-light.svg)

 [![Tests](https://camo.githubusercontent.com/e105fc22d3583f749352313de66d0b58ac7b2bae990881046989fa9a9dd37e45/68747470733a2f2f696d672e736869656c64732e696f2f6769746875622f616374696f6e732f776f726b666c6f772f7374617475732f7068702d6f706375612f6f706375612d636c69656e742d6578742d7472616e73706f72742d68747470732f74657374732e796d6c3f6272616e63683d6d6173746572266c6162656c3d7465737473267374796c653d666c61742d737175617265)](https://github.com/php-opcua/opcua-client-ext-transport-https/actions/workflows/tests.yml) [![Coverage](https://camo.githubusercontent.com/209ad125de81ade07b74ee5998d6982e8d8301d3e2e16c96eef1f424211eb7fd/68747470733a2f2f696d672e736869656c64732e696f2f636f6465636f762f632f6769746875622f7068702d6f706375612f6f706375612d636c69656e742d6578742d7472616e73706f72742d68747470733f7374796c653d666c61742d737175617265266c6f676f3d636f6465636f76)](https://codecov.io/gh/php-opcua/opcua-client-ext-transport-https) [![Latest Version](https://camo.githubusercontent.com/d6296e22acb6dfafbead213751a6fedbaf0f68ac5a9e2b1327a8aa9e2cdec68b/68747470733a2f2f696d672e736869656c64732e696f2f7061636b61676973742f762f7068702d6f706375612f6f706375612d636c69656e742d6578742d7472616e73706f72742d68747470733f7374796c653d666c61742d737175617265266c6162656c3d7061636b6167697374)](https://packagist.org/packages/php-opcua/opcua-client-ext-transport-https) [![PHP Version](https://camo.githubusercontent.com/b964c931d2cadc273630c81620ce1f9d116323dc59b3f43bea8f6fa749146704/68747470733a2f2f696d672e736869656c64732e696f2f7061636b61676973742f7068702d762f7068702d6f706375612f6f706375612d636c69656e742d6578742d7472616e73706f72742d68747470733f7374796c653d666c61742d737175617265)](https://packagist.org/packages/php-opcua/opcua-client-ext-transport-https) [![License](https://camo.githubusercontent.com/47497b6b588bb44d225a0dbb7ef1196ce03e7511a56d84e826288a51abec9aad/68747470733a2f2f696d672e736869656c64732e696f2f6769746875622f6c6963656e73652f7068702d6f706375612f6f706375612d636c69656e742d6578742d7472616e73706f72742d68747470733f7374796c653d666c61742d737175617265)](LICENSE)

 [![Linux](https://camo.githubusercontent.com/88a96af546255df6414fb878e65861f03abd9cd7c69fe0c652b32d10e1dc2b84/68747470733a2f2f637573746f6d2d69636f6e2d6261646765732e64656d6f6c61622e636f6d2f62616467652f4c696e75782de29c932d3265613434663f7374796c653d666c61742d737175617265266c6f676f3d6c696e7578266c6f676f436f6c6f723d7768697465)](https://camo.githubusercontent.com/88a96af546255df6414fb878e65861f03abd9cd7c69fe0c652b32d10e1dc2b84/68747470733a2f2f637573746f6d2d69636f6e2d6261646765732e64656d6f6c61622e636f6d2f62616467652f4c696e75782de29c932d3265613434663f7374796c653d666c61742d737175617265266c6f676f3d6c696e7578266c6f676f436f6c6f723d7768697465) [![macOS](https://camo.githubusercontent.com/9abd62edee5c8e38df116839daa54deb7e5b2054d4bcb856529f5cd92ada8b74/68747470733a2f2f637573746f6d2d69636f6e2d6261646765732e64656d6f6c61622e636f6d2f62616467652f6d61634f532de29c932d3265613434663f7374796c653d666c61742d737175617265266c6f676f3d6170706c65266c6f676f436f6c6f723d7768697465)](https://camo.githubusercontent.com/9abd62edee5c8e38df116839daa54deb7e5b2054d4bcb856529f5cd92ada8b74/68747470733a2f2f637573746f6d2d69636f6e2d6261646765732e64656d6f6c61622e636f6d2f62616467652f6d61634f532de29c932d3265613434663f7374796c653d666c61742d737175617265266c6f676f3d6170706c65266c6f676f436f6c6f723d7768697465) [![Windows](https://camo.githubusercontent.com/67b9f3090b3bbef27712496e616a0a0f0ead78d1a3a092a80b74df716dda8a6b/68747470733a2f2f637573746f6d2d69636f6e2d6261646765732e64656d6f6c61622e636f6d2f62616467652f57696e646f77732de29c932d3265613434663f7374796c653d666c61742d737175617265266c6f676f3d77696e646f77733131266c6f676f436f6c6f723d7768697465)](https://camo.githubusercontent.com/67b9f3090b3bbef27712496e616a0a0f0ead78d1a3a092a80b74df716dda8a6b/68747470733a2f2f637573746f6d2d69636f6e2d6261646765732e64656d6f6c61622e636f6d2f62616467652f57696e646f77732de29c932d3265613434663f7374796c653d666c61742d737175617265266c6f676f3d77696e646f77733131266c6f676f436f6c6f723d7768697465)

---

`opc.https://` transport for [`php-opcua/opcua-client`](https://github.com/php-opcua/opcua-client). Implements the HTTPS mappings of [OPC UA Part 6 §7.4](https://reference.opcfoundation.org/Core/Part6/v105/docs/7.4): each service request is a single HTTPS POST, TLS is the secure channel, the response body is the service response. Use it when the network forbids inbound `opc.tcp` but allows outbound `https`.

**What you get with v4.4.0:**

- **`HttpsTransport`** that drops straight into `ClientBuilder::setTransport()` — every OPC UA service call (`read`, `write`, `browse`, `subscribe`, `call`, `history*`) becomes one POST under the hood
- **`BinaryHttpsEncoding`** (Part 6 §7.4.4) — strips the UA-TCP framing into bare service requests, re-wraps responses for the core's decoder, fakes the HEL/ACK locally because `opc.https://` doesn't carry it on the wire
- **`CurlHttpClient`** with first-class TLS support — system CA store or pinned bundle, mutual TLS via PEM cert/key, HTTP keep-alive and TLS session resumption out of the box, full `extraCurlOptions` passthrough for proxies and corporate networks
- **Three PSR-14 events** (`HttpsRequestSent`, `HttpsResponseReceived`, `HttpsRequestFailed`) for tracing, metrics, audit
- **Five typed exceptions** rooted in `HttpsTransportException` (`HttpsRequestException`, `HttpsStatusException`, `EncodingException`, `UnsupportedEncodingException`) — route on the cause that matters
- **29 unit tests** running cross-platform (no Unix-only APIs), zero external dependency
- **Plug-and-play core integration** — the `opcua-client` v4.4 `ClientTransportInterface::createProbe()` and `isSecureChannelExternal()` seams mean the discovery probe runs through HTTPS too, and the OPC UA `OpenSecureChannel` exchange is short-circuited because TLS already wraps the channel

> **HTTPS auth note:** UA-.NETStandard filters Anonymous out of HTTPS endpoint policies when mTLS is off, so the integration suite connects with Username / Password (the channel itself stays `SecurityPolicy::None` — TLS provides confidentiality). For Anonymous over HTTPS, the server must be configured with mTLS and the client must supply `clientCertPath` + `clientKeyPath` on `CurlHttpClient`.

---

Quick Start
-----------

[](#quick-start)

```
composer require php-opcua/opcua-client-ext-transport-https
```

```
use PhpOpcua\Client\ClientBuilder;
use PhpOpcua\Client\ExtTransportHttps\Encoding\BinaryHttpsEncoding;
use PhpOpcua\Client\ExtTransportHttps\Http\CurlHttpClient;
use PhpOpcua\Client\ExtTransportHttps\HttpsTransport;
use PhpOpcua\Client\Security\SecurityMode;
use PhpOpcua\Client\Security\SecurityPolicy;

$transport = new HttpsTransport(
    httpClient: new CurlHttpClient(verifyTls: true, caBundle: '/etc/ssl/certs/ca-bundle.crt'),
    encoding: new BinaryHttpsEncoding(),
    endpointUrl: 'opc.https://server.example:443/UA/',
);

$client = (new ClientBuilder())
    ->setSecurityPolicy(SecurityPolicy::None)
    ->setSecurityMode(SecurityMode::None)
    ->setTransport($transport)
    ->setUserCredentials('admin', 'admin123')
    ->connect('opc.https://server.example:443/UA/');

$value = $client->read('i=2259');
echo $value->getValue();

$client->disconnect();
```

See It in Action
----------------

[](#see-it-in-action)

### Mutual TLS

[](#mutual-tls)

```
$transport = new HttpsTransport(
    httpClient: new CurlHttpClient(
        verifyTls: true,
        caBundle: '/etc/ssl/certs/server-ca-bundle.crt',
        clientCertPath: '/var/lib/myapp/client.pem',
        clientKeyPath: '/var/lib/myapp/client.key',
        clientKeyPassword: getenv('CLIENT_KEY_PASS') ?: null,
    ),
    encoding: new BinaryHttpsEncoding(),
    endpointUrl: 'opc.https://server.example:443/UA/',
);
```

### Behind a corporate proxy

[](#behind-a-corporate-proxy)

```
$http = new CurlHttpClient(
    verifyTls: true,
    extraCurlOptions: [
        CURLOPT_PROXY => 'http://proxy.corp.example:8080',
        CURLOPT_PROXYUSERPWD => 'user:secret',
    ],
);
```

`HTTPS_PROXY` / `NO_PROXY` from the environment are honoured automatically when no `CURLOPT_PROXY` is supplied.

### Observability via PSR-14

[](#observability-via-psr-14)

```
use PhpOpcua\Client\ExtTransportHttps\Event\HttpsRequestSent;
use PhpOpcua\Client\ExtTransportHttps\Event\HttpsResponseReceived;
use PhpOpcua\Client\ExtTransportHttps\Event\HttpsRequestFailed;

$transport = new HttpsTransport(
    httpClient: $http,
    encoding: new BinaryHttpsEncoding(),
    endpointUrl: 'opc.https://server.example:443/UA/',
    dispatcher: $yourPsr14Dispatcher,
);

class TraceListener {
    public function onSent(HttpsRequestSent $e): void { /* ... */ }
    public function onReceived(HttpsResponseReceived $e): void { /* ... */ }
    public function onFailed(HttpsRequestFailed $e): void {
        Log::warning("HTTPS {$e->statusCode} for {$e->url}: {$e->cause->getMessage()}");
    }
}
```

Zero overhead when no dispatcher is supplied — events are not constructed at all.

### Bring your own HTTP backend

[](#bring-your-own-http-backend)

```
final class GuzzleHttpClient implements HttpClientInterface {
    public function __construct(private readonly \GuzzleHttp\Client $http) {}

    public function post(HttpRequest $r, float $timeout): HttpResponse {
        try {
            $resp = $this->http->post($r->url, [
                'body' => $r->body,
                'headers' => ['Content-Type' => $r->contentType, 'Accept' => $r->acceptHeader] + $r->extraHeaders,
                'timeout' => $timeout,
                'http_errors' => false,
            ]);
            return new HttpResponse($resp->getStatusCode(), (string) $resp->getBody());
        } catch (\Throwable $e) {
            throw new HttpsRequestException($e->getMessage(), 0, $e);
        }
    }

    public function close(): void {}
}
```

Why This Package?
-----------------

[](#why-this-package)

- **Drops into the existing `Client`** — no new API surface for the application layer; the same `read`, `write`, `browse`, `call`, `subscribe`, `history*` methods you already use
- **`opcua-client` stays lean** — the core only adds two contract methods (`createProbe`, `isSecureChannelExternal`); HTTPS-specific logic lives here
- **PSR everywhere** — PSR-3 logger and PSR-14 dispatcher both optional; no global state
- **Cross-platform** — pure PHP + `ext-curl`; tested on Linux, macOS, Windows across PHP 8.2–8.5
- **No HTTP framework baked in** — `HttpClientInterface` is two methods; supply Guzzle, Symfony, PSR-18, or anything else
- **Three encodings, one transport** — Binary in v4.4, JSON / XML-SOAP in the roadmap, all sharing transport mechanics

Documentation
-------------

[](#documentation)

The published site lives at . The Markdown sources ship under [`docs/`](docs/index.md):

SectionCovers**Getting started** — [Overview](docs/overview.md) · [Installation](docs/getting-started/installation.md) · [Quick start](docs/getting-started/quick-start.md)What it is, how to install, first connection**Concepts** — [How it works](docs/concepts/how-it-works.md) · [Encodings](docs/concepts/encodings.md)Wire format, fake HEL/ACK, OPN skip, the three encodings of Part 6 §7.4**API** — [Transport](docs/api/transport.md) · [Encoding strategies](docs/api/encoding-strategies.md) · [HTTP client](docs/api/http-client.md) · [Events](docs/api/events.md)Public surface**Recipes** — [TLS and cert trust](docs/recipes/tls-and-cert-trust.md) · [Corporate proxy](docs/recipes/corporate-proxy.md) · [Connection pooling](docs/recipes/connection-pooling.md)Operational patterns**Reference** — [Exceptions](docs/reference/exceptions.md)Every exception, cause, catch strategyTesting
-------

[](#testing)

```
./vendor/bin/pest                                          # everything (29 unit + 1 integration)
./vendor/bin/pest tests/Unit/                              # 29 tests, no external deps
./vendor/bin/pest tests/Integration/ --group=integration   # E2E (requires uanetstandard-test-suite v1.5.0+)
```

Ecosystem
---------

[](#ecosystem)

PackageDescription[opcua-client](https://github.com/php-opcua/opcua-client)Pure PHP OPC UA client (the core this extension hooks into)[opcua-client-ext-reverse-connect](https://github.com/php-opcua/opcua-client-ext-reverse-connect)Listener for OPC UA Reverse Connect (Part 6 §7.1.2.3)[opcua-client-ext-pubsub](https://github.com/php-opcua/opcua-client-ext-pubsub)OPC UA PubSub Subscriber — UDP + UADP + JSON[opcua-cli](https://github.com/php-opcua/opcua-cli)CLI tool — browse, read, write, watch, discover endpoints[opcua-client-nodeset](https://github.com/php-opcua/opcua-client-nodeset)Pre-generated PHP types from 51 OPC Foundation companion specifications[uanetstandard-test-suite](https://github.com/php-opcua/uanetstandard-test-suite)Docker-based OPC UA test servers (UA-.NETStandard) — v1.5.0+ ships the `opcua-https-binary` serviceCommunity
---------

[](#community)

Have questions, ideas, or want to share what you've built? Join the [GitHub Discussions](https://github.com/php-opcua/opcua-client/discussions).

Contributing
------------

[](#contributing)

Contributions welcome — see [CONTRIBUTING.md](CONTRIBUTING.md).

Changelog
---------

[](#changelog)

See [CHANGELOG.md](CHANGELOG.md).

Roadmap
-------

[](#roadmap)

See [ROADMAP.md](ROADMAP.md). All non-Binary encodings (JSON §7.4.5, XML SOAP §7.4.3, legacy SOAP/HTTP with WS-SecureConversation §7.3 + §6.6) are **community-driven** — no production server stack ships them end-to-end today, so they wait for a concrete use case before being scheduled.

License
-------

[](#license)

[MIT](LICENSE)

###  Health Score

37

—

LowBetter than 81% of packages

Maintenance90

Actively maintained with recent releases

Popularity0

Limited adoption so far

Community6

Small or concentrated contributor base

Maturity46

Maturing project, gaining track record

 Bus Factor1

Top contributor holds 100% of commits — single point of failure

How is this calculated?**Maintenance (25%)** — Last commit recency, latest release date, and issue-to-star ratio. Uses a 2-year decay window.

**Popularity (30%)** — Total and monthly downloads, GitHub stars, and forks. Logarithmic scaling prevents top-heavy scores.

**Community (15%)** — Contributors, dependents, forks, watchers, and maintainers. Measures real ecosystem engagement.

**Maturity (30%)** — Project age, version count, PHP version support, and release stability.

###  Release Activity

Cadence

Unknown

Total

1

Last Release

50d ago

### Community

Maintainers

![](https://www.gravatar.com/avatar/fb72ba5d2c05eec08d9556c0007f17a7d657d5187de1025a4a0525ace4ac8000?d=identicon)[GianfriAur](/maintainers/GianfriAur)

---

Top Contributors

[![GianfriAur](https://avatars.githubusercontent.com/u/16904504?v=4)](https://github.com/GianfriAur "GianfriAur (6 commits)")

---

Tags

binary-protocolhttpsiiotindustrial-automationindustry-4-0opc-httpsopc-uaopcuaopcua-clientphptlstransporthttpsjsontransportbinarysoapopcuaopc-uaindustrialIIoTindustry-4.0

###  Code Quality

TestsPest

Code StylePHP CS Fixer

### Embed Badge

![Health badge](/badges/php-opcua-opcua-client-ext-transport-https/health.svg)

```
[![Health](https://phpackages.com/badges/php-opcua-opcua-client-ext-transport-https/health.svg)](https://phpackages.com/packages/php-opcua-opcua-client-ext-transport-https)
```

###  Alternatives

[symfony/symfony

The Symfony PHP framework

31.4k87.2M2.2k](/packages/symfony-symfony)[symfony/mailer

Helps sending emails

1.6k409.1M1.5k](/packages/symfony-mailer)[phpro/soap-client

A general purpose SoapClient library

8896.1M54](/packages/phpro-soap-client)[php-opcua/opcua-client

Pure PHP OPC UA client — binary protocol over TCP, 6 security policies, browse/read/write/subscribe/history, zero external dependencies

131.4k23](/packages/php-opcua-opcua-client)[drupal/core-recommended

Locked core dependencies; require this project INSTEAD OF drupal/core.

6942.5M425](/packages/drupal-core-recommended)[web-auth/webauthn-lib

FIDO2/Webauthn Support For PHP

12510.5M141](/packages/web-auth-webauthn-lib)

PHPackages © 2026

[Directory](/)[Categories](/categories)[Trending](/trending)[Changelog](/changelog)[Analyze](/analyze)
