Download the PHP package kilogram/auth without Composer
On this page you can find all versions of the php package kilogram/auth. It is possible to download/install these versions without Composer. Possible dependencies are resolved automatically.
Download kilogram/auth
More information about kilogram/auth
Files in kilogram/auth
Package auth
Short Description Secure and simple validation library for Telegram Login Widget and Web App data (including Third-Party validation support).
License MIT
Informations about the package auth
Telegram Auth 🔑
Secure and simple validation library for Telegram Login Widget and Web App (including Third-Party validation support).
Features
- ✅ Telegram Login Widget – validate payloads from the login widget (hash verification, timestamp check).
- ✅ Telegram Web App – authenticate users inside mini‑apps by verifying
initData. - ✅ Third‑Party Use – validate Telegram data for external services (without a bot token, using bot ID).
- ✅ Simple API – ready‑to‑use methods like
isValidLoginWidget(),validateWebApp(), plus exceptions for error handling. - ✅ Secure by design – uses cryptographically strong hashing (
hash_hmac,sodium) to prevent data tampering. - ✅ PHP 8.2+ – modern, strictly typed code.
Requirements
- PHP:
^8.2 - ext-hash:
* - ext-sodium:
*
Installation
Quick start
[!NOTE] Usage examples are also available in the examples directory.
Login Widget (simple)
Basic validation of the data received from the Telegram Login Widget. Checks the hash and timestamp, returns a boolean result.
Login Widget (with exceptions)
A more robust approach that throws specific exceptions for invalid input (missing parameters) and validation failures (tampered data).
Web App (simple)
Verifies the initData string from a Telegram Web App. Returns true if the signature is valid and the data is fresh.
Web App (with exceptions)
Same as above, but throws exceptions for malformed input or invalid signatures, giving you finer control over error handling.
Web App Third-Party (simple)
Validates data for third‑party services without using a bot token. Only the bot ID is required.
Web App Third-Party (with exceptions)
The same third‑party validation, but with exception-based error reporting.
[!TIP] When to use simple vs exceptions?
Use the simple methods (isValid*) when you only need a boolean result (e.g., in controllers, middleware, or conditional logic).
Use the exception methods (validate*) when you need granular error handling – they distinguish between malformed input (developer errors, e.g., missing parameters) and invalid signatures (security issues, e.g., tampered data).
License
MIT
All versions of auth with dependencies
ext-hash Version *
ext-sodium Version *