PHPackages                             redeyed/sentinel-laravel - PHPackages - PHPackages  [Skip to content](#main-content)[PHPackages](/)[Directory](/)[Categories](/categories)[Trending](/trending)[Leaderboard](/leaderboard)[Changelog](/changelog)[Analyze](/analyze)[Collections](/collections)[Log in](/login)[Sign up](/register)

1. [Directory](/)
2. /
3. [Security](/categories/security)
4. /
5. redeyed/sentinel-laravel

ActiveLibrary[Security](/categories/security)

redeyed/sentinel-laravel
========================

Redeyed Sentinel CAPTCHA + IP-reputation integration for Laravel. Free to install, inert until keys are set.

v1.0.2(1mo ago)111MITPHPPHP &gt;=8.1

Since Jun 30Pushed 4w agoCompare

[ Source](https://github.com/Bruted/sentinel-laravel)[ Packagist](https://packagist.org/packages/redeyed/sentinel-laravel)[ Docs](https://redeyed.com)[ RSS](/packages/redeyed-sentinel-laravel/feed)WikiDiscussions main Synced 2w ago

READMEChangelog (3)Dependencies (2)Versions (4)Used By (0)

Redeyed Sentinel for Laravel
============================

[](#redeyed-sentinel-for-laravel)

Add **Redeyed Sentinel** — a self-hosted CAPTCHA + IP-reputation service — to any Laravel app in a couple of minutes.

Sentinel is **free to install** and completely **inert until you set your keys**. Before keys are configured the package fails *open* (verification passes and a warning is logged) so your forms never break. Once your keys are in place, every protected form is verified server-side.

Requirements
------------

[](#requirements)

- PHP &gt;= 8.1
- Laravel 10, 11, 12, or 13

Installation
------------

[](#installation)

```
composer require redeyed/sentinel-laravel
```

The service provider is auto-discovered — there is nothing to register manually.

Optionally publish the config:

```
php artisan vendor:publish --tag=sentinel-config
```

Configuration
-------------

[](#configuration)

Grab both keys from the **Redeyed Lab → Sentinel → Sites** (each site has both):

- **Site key** (public): renders the widget — safe in page markup.
- **Secret key** (private): verifies tokens server-side — shown once when you create the site.

Add them to your `.env`:

```
SENTINEL_SITE_KEY=st_pub_your-public-site-key
SENTINEL_SECRET_KEY=st_sec_your-secret-key

# Optional — only change if you self-host Sentinel elsewhere
# SENTINEL_BASE_URL=https://redeyed.com
```

The `SENTINEL_SECRET_KEY` is **secret** and stays server-side — it is only ever sent to the verification endpoint and is never exposed to the browser. **No developer API key is required.**

Usage
-----

[](#usage)

### 1. Render the widget in your form

[](#1-render-the-widget-in-your-form)

Drop the component anywhere inside your ``:

```

    @csrf

    {{-- ...your fields... --}}

    Submit

```

Prefer a directive? `@sentinel` does exactly the same thing:

```

    @csrf
    @sentinel
    Submit

```

The widget loads the Sentinel script once per page and injects a hidden input named `sentinel-token` into your form.

#### Customising the widget (optional)

[](#customising-the-widget-optional)

The widget accepts four **optional** settings. Leave them unset and nothing changes — the widget renders exactly as before (just `data-sitekey`). Each one is rendered as a `data-*` attribute only when non-empty.

Option`data-*`Values`widget``data-widget``behavioral` | `checkbox` | `press_hold` | `image_pick``theme``data-theme``auto` | `light` | `dark``scheme``data-scheme`colour scheme name`difficulty``data-difficulty``easy` | `medium` | `hard` | `max`, or `1`–`6``width``data-width`fixed widget width, e.g. `full`, `100%` or `340px`> **Note:** `difficulty` only **raises** the challenge strength above the adaptive baseline. A risky visitor is always challenged hard regardless of this value.

Set them **per instance** via component props (these override the config defaults):

```

```

…or set **project-wide defaults** in the published `config/sentinel.php`(or via `.env`):

```
SENTINEL_WIDGET=checkbox
SENTINEL_THEME=auto
SENTINEL_SCHEME=midnight
SENTINEL_DIFFICULTY=medium
SENTINEL_WIDTH=full
```

### 2. Verify on the server

[](#2-verify-on-the-server)

Add the rule to your validation. Either use the rule class:

```
use Redeyed\LaravelSentinel\Rules\Sentinel;

$request->validate([
    // ...your other rules...
    'sentinel-token' => ['required', new Sentinel],
]);
```

…or the string alias:

```
$request->validate([
    'sentinel-token' => ['required', 'sentinel'],
]);
```

If verification fails the user sees:

> Human verification failed — please try again.

How verification works
----------------------

[](#how-verification-works)

On submit, the package POSTs to `{BASE_URL}/sentinel/siteverify` with a JSON body of `{"secret": "...", "response": ""}` — reCAPTCHA-style. The site secret authenticates the call, so **no developer API key is involved**. The submission passes only when the response reports `success === true`.

If the secret is not configured, verification fails **open** and logs a warning so forms keep working until you finish setup.

License
-------

[](#license)

MIT © 2026 Redeyed Corporation

###  Health Score

40

—

FairBetter than 86% of packages

Maintenance93

Actively maintained with recent releases

Popularity9

Limited adoption so far

Community6

Small or concentrated contributor base

Maturity44

Maturing project, gaining track record

 Bus Factor1

Top contributor holds 100% of commits — single point of failure

How is this calculated?**Maintenance (25%)** — Last commit recency, latest release date, and issue-to-star ratio. Uses a 2-year decay window.

**Popularity (30%)** — Total and monthly downloads, GitHub stars, and forks. Logarithmic scaling prevents top-heavy scores.

**Community (15%)** — Contributors, dependents, forks, watchers, and maintainers. Measures real ecosystem engagement.

**Maturity (30%)** — Project age, version count, PHP version support, and release stability.

###  Release Activity

Cadence

Every ~1 days

Total

3

Last Release

42d ago

### Community

Maintainers

![](https://www.gravatar.com/avatar/5244208523531156be8603e3bb5a526fdc7857cf27610cbbfddcd9cf8fe51d68?d=identicon)[Bruted](/maintainers/Bruted)

---

Top Contributors

[![Bruted](https://avatars.githubusercontent.com/u/73144421?v=4)](https://github.com/Bruted "Bruted (6 commits)")

---

Tags

laravelcaptchasentinelbot-protectionip reputationredeyed

### Embed Badge

![Health badge](/badges/redeyed-sentinel-laravel/health.svg)

```
[![Health](https://phpackages.com/badges/redeyed-sentinel-laravel/health.svg)](https://phpackages.com/packages/redeyed-sentinel-laravel)
```

###  Alternatives

[psalm/plugin-laravel

Psalm plugin for Laravel

3345.4M354](/packages/psalm-plugin-laravel)[api-platform/laravel

API Platform support for Laravel

58190.1k21](/packages/api-platform-laravel)

PHPackages © 2026

[Directory](/)[Categories](/categories)[Trending](/trending)[Changelog](/changelog)[Analyze](/analyze)
