Download the PHP package binuka200/apple-sign-in without Composer

On this page you can find all versions of the php package binuka200/apple-sign-in. It is possible to download/install these versions without Composer. Possible dependencies are resolved automatically.

FAQ

After the download, you have to make one include require_once('vendor/autoload.php');. After that you have to import the classes with use statements.

Example:
If you use only one package a project is not needed. But if you use more then one package, without a project it is not possible to import the classes with use statements.

In general, it is recommended to use always a project to download your libraries. In an application normally there is more than one library needed.
Some PHP packages are not free to download and because of that hosted in private repositories. In this case some credentials are needed to access such packages. Please use the auth.json textarea to insert credentials, if a package is coming from a private repository. You can look here for more information.

  • Some hosting areas are not accessible by a terminal or SSH. Then it is not possible to use Composer.
  • To use Composer is sometimes complicated. Especially for beginners.
  • Composer needs much resources. Sometimes they are not available on a simple webspace.
  • If you are using private repositories you don't need to share your credentials. You can set up everything on our site and then you provide a simple download link to your team member.
  • Simplify your Composer build process. Use our own command line tool to download the vendor folder as binary. This makes your build process faster and you don't need to expose your credentials for private repositories.
Please rate this library. Is it a good library?

Informations about the package apple-sign-in

Safe Apple Sign In for PHP

CI Latest Stable Version PHP Version

A framework-neutral, defensive implementation of the complete Sign in with Apple server lifecycle for PHP 8.1+.

It replaces abandoned packages that vendor old JWT code or fetch Apple's keys on every login request. It does not create application sessions, users, routes, or database records; those decisions remain in your application.

This is an independent community project and is not affiliated with or endorsed by Apple Inc.

Included

Install

Configuration

You need the following values from Apple Developer:

Use a shared PSR-16 cache such as Redis in production. ArrayCache is only for tests and one-process examples.

The default client secret lasts five minutes and is generated for each API operation. Apple permits a maximum lifetime of 15,777,000 seconds.

Start authorization

Generate a challenge, store both values in the user's server-side session, then redirect to Apple:

Handle the callback

Consume the stored challenge once. Parsing the callback first validates state. Then verify that the callback ID token is bound to the single-use code, exchange the code, and verify the resulting identity token with the original nonce.

For native applications that send a SHA-256 nonce to Apple, verify against $challenge->hashedNonce() instead of the raw nonce.

Refresh and revoke

Authorization-code requests are not automatically retried because the code is single-use. A successful Apple response lost in transit cannot safely be replayed.

Server-to-server notifications

Configure the endpoint in Apple Developer. Verification deliberately has no side effects:

Apple describes each event as expected to be delivered once. Duplicate events may occur, but they are not a redelivery guarantee. Commit durable intake before returning a success status, retry account mutations from your own queue, and use monitoring plus reconciliation where possible. If verification or durable intake fails, return a non-success status and alert; do not rely on Apple to send the event again. See Apple's DTS guidance on notification delivery.

PSR-16 cannot express an atomic insert-if-absent operation. Use a database or durable queue with a unique key on jwtId for inbox idempotency.

Resilience and telemetry

JWKS responses are fresh for one hour and retained as a stale fallback for 24 hours. Successful and failed refresh attempts enter the forced-refresh cooldown, so repeated unknown key IDs cannot cause sequential network requests every time. Configure FlockRefreshLock to make this protection atomic between PHP-FPM workers on the same filesystem. Distributed deployments can implement RefreshLock using their existing Redis or database lock.

Implement Observer to forward safe events such as jwks.cache_hit, jwks.stale_fallback, oauth.token_succeeded, and oauth.token_rejected to your logger or metrics system. Context never includes codes, tokens, client secrets, or private keys.

Framework examples

Failure behavior

Failures while communicating with Apple or verifying Apple data extend AppleSignInException. Important subclasses are:

Invalid credential and endpoint configuration uses InvalidConfiguration. Other invalid method or constructor arguments use PHP's InvalidArgumentException. Infrastructure failures from an injected cache or refresh-lock implementation may retain the exception type supplied by that implementation.

Map detailed failures to a generic login error at the public boundary. Never return raw Apple errors, tokens, codes, or claims to an unauthenticated client.

Development

CI covers PHP 8.1 through 8.5, including the lowest supported dependency set. The codebase is checked at PHPStan level 8 and dependencies are audited for published security advisories. Use a PHP branch that still receives upstream security fixes in production.

A separate job measures line coverage of src and fails when it drops below the committed floor:

Versioning and support

Releases follow Semantic Versioning. From 1.0 onward, breaking changes to the public API happen only in a major release. Only the latest release receives security fixes.

The public API is every type under the SafeApple\SignIn namespace except those marked @internal, which are implementation details shared between components and may change in any release. Because PHP supports named arguments, constructor and method parameter names are part of the public API as well as their order and types; new optional parameters are only ever appended.

Adding a property to a returned value object (AppleIdentity, AppleAccountEvent, TokenResponse) is treated as a compatible change, so match on the properties you use rather than destructuring every field.

Each GitHub release ships a source archive with a SHA-256 checksum and a Sigstore build-provenance attestation produced by the release workflow. To confirm an archive was built from this repository:

Release tags are protected against deletion and rewriting, so a published version always points at the same commit.

License

MIT


All versions of apple-sign-in with dependencies

PHP Build Version
Package Version
Requires php Version ^8.1
ext-json Version *
ext-openssl Version *
firebase/php-jwt Version ^7.0.5
psr/simple-cache Version ^3.0
symfony/http-client Version ^6.4 || ^7.0 || ^8.0
symfony/http-client-contracts Version ^3.4
Composer command for our command line client (download client) This client runs in each environment. You don't need a specific PHP version etc. The first 20 API calls are free. Standard composer command

The package binuka200/apple-sign-in contains the following files

Loading the files please wait ...