Download the PHP package birdcar/authkit-laravel without Composer

On this page you can find all versions of the php package birdcar/authkit-laravel. It is possible to download/install these versions without Composer. Possible dependencies are resolved automatically.

FAQ

After the download, you have to make one include require_once('vendor/autoload.php');. After that you have to import the classes with use statements.

Example:
If you use only one package a project is not needed. But if you use more then one package, without a project it is not possible to import the classes with use statements.

In general, it is recommended to use always a project to download your libraries. In an application normally there is more than one library needed.
Some PHP packages are not free to download and because of that hosted in private repositories. In this case some credentials are needed to access such packages. Please use the auth.json textarea to insert credentials, if a package is coming from a private repository. You can look here for more information.

  • Some hosting areas are not accessible by a terminal or SSH. Then it is not possible to use Composer.
  • To use Composer is sometimes complicated. Especially for beginners.
  • Composer needs much resources. Sometimes they are not available on a simple webspace.
  • If you are using private repositories you don't need to share your credentials. You can set up everything on our site and then you provide a simple download link to your team member.
  • Simplify your Composer build process. Use our own command line tool to download the vendor folder as binary. This makes your build process faster and you don't need to expose your credentials for private repositories.
Please rate this library. Is it a good library?

Informations about the package authkit-laravel

Authkit Laravel

Packagist PHP from Packagist Laravel versions GitHub Workflow Status (main) Total Downloads

A "batteries included" implementation of AuthKit and the entire WorkOS suite for Laravel — one package, headless plumbing only, no UI opinions.

Where laravel/workos wires AuthKit login into a starter kit, this package wraps the whole WorkOS platform behind Laravel-native mechanisms: a workos session guard over the AuthKit sealed cookie, organizations and memberships as local Eloquent projections kept fresh by an events pipeline, RBAC answered from JWT claims with zero HTTP per check, FGA via the Check API, a first-party Pennant driver, audit logs on model lifecycle hooks, Vault as an Eloquent cast + filesystem driver + KV facade, an API-key auth guard, Connect application management, MCP bearer auth, and Pipes connected accounts.

WorkOS stays canonical everywhere: local rows are declared projections linked by workos_id/external_id, refreshed by the events pipeline — never a second source of truth.

Quickstart

Five steps from composer require to a working login with organizations and role-based authorization live: docs/quickstart.md.

Testing Your App

Authkit::actingAs($user, [...]) fakes a full WorkOS session (guard, claims, Gate, current org, feature flags) and Authkit::fake() swaps every manager for an in-memory fake with Laravel-style assertions — no network, no API key, no emulator. The guide with a worked example per fake: docs/testing.md.

What's Included

Area Surface
AuthKit hosted auth authkit.login / authkit.callback / authkit.logout routes (thin wrappers over public form requests), PKCE + state handled for you
Sessions & tokens workos guard over the sealed session cookie, iss/aud hardening, refresh middleware (authkit.session), 4KB cookie-ceiling guardrails
User management HasWorkosUser trait: local user projection, workos_id ↔ external_id linking on first login, impersonation surfaced as an event
Organizations HasWorkosOrganization + BelongsToWorkosOrganizations traits, domains + memberships projections, claims-resolved current org (Authkit::currentOrganization(), $request->organization()), org-switch route, authkit.org tenant middleware
Events pipeline php artisan authkit:work poller (cursor-persisted, single-flight), typed events for projection-feeding types + GenericWorkosEvent for everything else, make:workos-listener generator
Webhooks Route::workosWebhooks() macro — signature verification and CSRF exclusion built in, same event objects as the poller
Authorization (RBAC) Role/permission claims into Gate::before — $user->can('posts.manage') costs zero HTTP
Authorization (FGA) Authkit::check() against the WorkOS Check API, HasWorkosResource trait for resource sync, resource-graph helpers, opt-in check cache with events-driven invalidation
Audit Logs HasAuditLogs model trait (create/update/archive/delete/restore), AuditLog::log() facade, schema/export/retention passthroughs
Admin Portal Authkit::portalLink($org, PortalIntent::Sso) across all seven intents
Feature Flags First-party Pennant driver (Feature::store('workos')): claim-first in HTTP, WorkOS API fallback in queues/console
API Keys authkit-key guard, key permissions into Gate, issue/revoke/list on user + org models (raw value shown once, structurally)
Vault Vaulted Eloquent cast, vault filesystem driver wrapping any disk, Vault KV facade — BYOK envelope encryption throughout
Connect & MCP Authkit::connect() application registry, authkit.mcp bearer middleware (RFC 6750), /.well-known/oauth-protected-resource (RFC 9728)
Pipes $user->connectedAccounts() / $user->pipe('slug') with WorkOS-managed token refresh, org provider-config passthrough
Depth extensions Invitations, JWT template + CORS origin passthroughs, Groups API
Testing Authkit::actingAs() synthetic sessions + Authkit::fake() manager fakes with recorded-call assertions — fast, offline feature tests for every surface above

Directory Sync ships no dedicated module by design — WorkOS-managed provisioning plus events-pipeline listeners cover it. Widgets are excluded from v1 entirely: UI belongs to your app, this package is plumbing.

Installation

The installer publishes the config and migrations, appends the WORKOS_* keys to your .env and .env.example, and generates a session cookie password. It is safe to re-run: existing keys are left untouched. Follow the quickstart for the two wiring steps that remain.

You may instead publish resources individually:

Or everything at once with --tag="authkit-laravel".

Local Development Against the Emulator

Every package HTTP call — the SDK client, the guard's JWKS verification, logout URLs — honors one switch:

Run @workos/emulate locally (npx @workos/emulate) and the whole login → claims → RBAC loop works offline. The package's own acceptance suite runs this exact journey.

Usage Notes

JWT Templates

Authkit::jwtTemplate() wraps the environment's JWT template:

[!WARNING] Editing the JWT template changes every access token your environment mints from that moment on — and the AuthKit sealed session cookie that carries those tokens has a hard 4KB browser ceiling.

A template that grows the claim set (for example by embedding large role/permission arrays) can push the sealed cookie past 4KB, at which point browsers silently truncate or drop it: the workos guard can no longer unseal the session and users are locked out of login entirely. Claims are also what back this package's zero-HTTP RBAC checks and the Pennant feature_flags claim, so template edits shift authorization behavior, not just token cosmetics.

Every update() call logs a warning and dispatches the Authkit\Authkit\Events\JwtTemplateUpdated event (carrying the before/after content) — listen for it to wire your own alerting. Always verify a real login end-to-end in staging after a template change before deploying it. If you need bulky data available at runtime, keep it out of the template and use the runtime APIs instead of growing the token.

MCP Servers Behind laravel/mcp

When protecting a laravel/mcp server with the authkit.mcp middleware, note that laravel/mcp's own AddWwwAuthenticateHeader middleware rewrites 401 challenges on Mcp::web routes and drops the resource_metadata pointer this package emits per RFC 9728. Clients that discover the protected-resource document from the challenge header should read it from /.well-known/oauth-protected-resource directly.

Release Process

Maintainers: see docs/release-checklist.md — including the required human quickstart trial log.

Changelog

Please see CHANGELOG for more information on what has changed recently.

Contributing

Thank you for considering contributing to Authkit Laravel! Please review our contributing guide to get started.

Security Vulnerabilities

Please review our security policy on how to report security vulnerabilities.

Credits

License

Authkit Laravel is open-sourced software licensed under the MIT license.


All versions of authkit-laravel with dependencies

PHP Build Version
Package Version
Requires php Version ^8.3
guzzlehttp/guzzle Version ^7.0||^8.0
illuminate/contracts Version ^12.0||^13.0
illuminate/support Version ^12.0||^13.0
laravel/framework Version ^12.0||^13.0
laravel/pennant Version ^1.22
workos/workos-php Version ^9.1
Composer command for our command line client (download client) This client runs in each environment. You don't need a specific PHP version etc. The first 20 API calls are free. Standard composer command

The package birdcar/authkit-laravel contains the following files

Loading the files please wait ...