Download the PHP package betterauth/laravel without Composer
On this page you can find all versions of the php package betterauth/laravel. It is possible to download/install these versions without Composer. Possible dependencies are resolved automatically.
Download betterauth/laravel
More information about betterauth/laravel
Files in betterauth/laravel
Package laravel
Short Description Modern authentication for Laravel with Paseto V4 tokens, OAuth, 2FA, and Magic Links
License MIT
Informations about the package laravel
BetterAuth for Laravel
Modern authentication for Laravel with Paseto V4 tokens, 2FA, and Magic Links
API Reference
Why BetterAuth?
| JWT | BetterAuth (Paseto V4) |
|---|---|
| Signed only | Encrypted + Authenticated |
| Algorithm confusion attacks | Single secure algorithm |
| Complex key management | Simple symmetric keys |
| Base64 encoded payload | Encrypted payload |
BetterAuth uses Paseto V4 (Platform-Agnostic Security Tokens) - a modern, secure alternative to JWT that eliminates entire classes of vulnerabilities by design.
Installation
That's it. The installer configures everything automatically.
Quick Start
Features
Core Authentication
- Paseto V4 Tokens - Encrypted, not just signed
- Argon2id Passwords - Memory-hard hashing (PHC winner)
- Refresh Token Rotation - One-time use with automatic rotation
- UUID v7 IDs - Time-ordered, database-friendly
Advanced Features
- Two-Factor Auth (TOTP) - With recovery codes
- Magic Links - Passwordless email authentication
- OAuth Providers - Google, GitHub, Facebook, and more
- Passkeys/WebAuthn - Biometric authentication (coming soon)
Laravel Native
- Works with
Auth::guard('betterauth') - Eloquent models and migrations
- Artisan commands
- Event dispatching
Requirements
| Requirement | Version |
|---|---|
| PHP | 8.2+ |
| Laravel | 10, 11, 12 |
| Database | PostgreSQL, MySQL, SQLite |
Configuration
After installation, configure via environment variables:
Or edit config/betterauth.php:
Generate a new secret key:
API Reference
Authentication Endpoints
| Method | Endpoint | Description |
|---|---|---|
POST |
/auth/register |
Create new account |
POST |
/auth/login |
Authenticate user |
GET |
/auth/me |
Get current user |
POST |
/auth/refresh |
Refresh access token |
POST |
/auth/logout |
Revoke refresh token |
POST |
/auth/revoke-all |
Revoke all tokens |
PUT |
/auth/password |
Update password |
Two-Factor Authentication
| Method | Endpoint | Description |
|---|---|---|
GET |
/auth/2fa/status |
Check 2FA status |
POST |
/auth/2fa/setup |
Get QR code |
POST |
/auth/2fa/enable |
Enable 2FA |
POST |
/auth/2fa/verify |
Verify TOTP code |
POST |
/auth/2fa/recovery |
Use recovery code |
DELETE |
/auth/2fa |
Disable 2FA |
Magic Links
| Method | Endpoint | Description |
|---|---|---|
POST |
/auth/magic-link |
Send magic link |
GET |
/auth/magic-link/verify |
Verify and login |
User Model
Add the HasBetterAuth trait to your User model:
The trait provides:
Two-Factor Authentication
Enable in configuration:
Using the service:
Magic Links
Enable in configuration:
Using the service:
Events
| Event | Trigger |
|---|---|
UserRegistered |
New user signs up |
UserLoggedIn |
Successful authentication |
UserLoggedOut |
User signs out |
TokenRefreshed |
Refresh token used |
PasswordChanged |
Password updated |
TwoFactorEnabled |
2FA activated |
TwoFactorDisabled |
2FA deactivated |
MagicLinkSent |
Magic link email sent |
Middleware
Security
Token Security (Paseto V4)
- XChaCha20-Poly1305 encryption
- Tokens are encrypted, not just signed
- No algorithm confusion attacks
- No key type confusion
Password Security (Argon2id)
- Winner of Password Hashing Competition
- Memory-hard to prevent GPU attacks
- Configurable memory/time/threads
Refresh Token Security
- Hashed before storage (SHA-256)
- One-time use - revoked after refresh
- Automatic rotation - new token on each refresh
Testing
License
MIT License. See LICENSE for details.
All versions of laravel with dependencies
illuminate/auth Version ^10.0|^11.0|^12.0
illuminate/contracts Version ^10.0|^11.0|^12.0
illuminate/database Version ^10.0|^11.0|^12.0
illuminate/http Version ^10.0|^11.0|^12.0
illuminate/routing Version ^10.0|^11.0|^12.0
illuminate/support Version ^10.0|^11.0|^12.0
paragonie/paseto Version ^3.1
ramsey/uuid Version ^4.7