Download the PHP package mikebronner/laravel-sign-in-with-apple without Composer

On this page you can find all versions of the php package mikebronner/laravel-sign-in-with-apple. It is possible to download/install these versions without Composer. Possible dependencies are resolved automatically.

FAQ

After the download, you have to make one include require_once('vendor/autoload.php');. After that you have to import the classes with use statements.

Example:
If you use only one package a project is not needed. But if you use more then one package, without a project it is not possible to import the classes with use statements.

In general, it is recommended to use always a project to download your libraries. In an application normally there is more than one library needed.
Some PHP packages are not free to download and because of that hosted in private repositories. In this case some credentials are needed to access such packages. Please use the auth.json textarea to insert credentials, if a package is coming from a private repository. You can look here for more information.

  • Some hosting areas are not accessible by a terminal or SSH. Then it is not possible to use Composer.
  • To use Composer is sometimes complicated. Especially for beginners.
  • Composer needs much resources. Sometimes they are not available on a simple webspace.
  • If you are using private repositories you don't need to share your credentials. You can set up everything on our site and then you provide a simple download link to your team member.
  • Simplify your Composer build process. Use our own command line tool to download the vendor folder as binary. This makes your build process faster and you don't need to expose your credentials for private repositories.
Please rate this library. Is it a good library?

Informations about the package laravel-sign-in-with-apple

Sign In With Apple for Laravel

repository-open-graph-template

Supporting This Package

This is an MIT-licensed open source project with its ongoing development made possible by the support of the community. If you'd like to support this, and our other packages, please consider sponsoring us via the button above.

We thank the following sponsors for their generosity, please take a moment to check them out:

Table of Contents

Requirements

Version Support

Laravel PHP Package
10.x 8.2+ 5.x
11.x 8.2+ 5.x
12.x 8.2+ 5.x
13.x 8.3+ 5.x

Installation

siwa-video-cover

  1. Install the composer package:

    We also recommend using geneaLabs/laravel-socialiter to automatically manage user resolution and persistence:

Configuration

  1. Create an App ID for your website (https://developer.apple.com/account/resources/identifiers/list/bundleId) with the following details:
    • Platform: iOS, tvOS, watchOS (I'm unsure if either choice has an effect for web apps)
    • Description: (something like "example.com app id")
    • Bundle ID (Explicit): com.example.id (or something similar)
    • Check "Sign In With Apple"
  2. Create a Service ID for your website (https://developer.apple.com/account/resources/identifiers/list/serviceId) with the following details:
    • Description: (something like "example.com service id")
    • Identifier: com.example.service (or something similar)
    • Check "Sign In With Apple"
    • Configure "Sign In With Apple":
      • Primary App Id: (select the primary app id created in step 1)
      • Web Domain: example.com (the domain of your web site)
      • Return URLs: https://example.com/apple-signin (the route pointing to the callback method in your controller)
      • Click "Save".
      • Click the "Edit" button to edit the details of the "Sign In With Apple" configuration we just created.
      • If you haven't verified the domain yet, download the verification file, upload it to https://example.com/.well-known/apple-developer-domain-association.txt, and then click the "Verify" button.
  3. Create a Private Key for your website (https://developer.apple.com/account/resources/authkeys/list) with the following details:
    • Key Name:
    • Check "Sign In With Apple"
    • Configure "Sign In With Apple":
      • Primary App ID: (select the primary app id created in step 1)
      • Click "Save"
    • Click "Continue"
    • Click "Register"
    • Click "Download"
    • Rename the downloaded file to key.txt
  4. Create your app's client secret:

    • Install the JWT Gem:

    • Create a file called client_secret.rb to process the private key:

    • Fill in the following fields:
      • team_id: This can be found on the top-right corner when logged into your Apple Developer account, right under your name.
      • client_id: This is the identifier from the Service Id created in step 2 above, for example com.example.service
      • key_id: This is the identifier of the private key created in step 3 above.
    • Save the file and run it from the terminal. It will spit out a JWT which is your client secret, which you will need to add to your .env file in the next step.

Alternative: Generate client_secret in PHP

Instead of using the Ruby script above, you can generate the client secret JWT directly in PHP using this package's built-in helper:

You can use an Artisan command or scheduled task to auto-rotate the secret before it expires:

Required env vars for fromConfig():

  1. Set the necessary environment variables in your .env file:

    Note: The APPLE_LOGIN environment variable has been removed (previously SIGN_IN_WITH_APPLE_LOGIN). Login routes should be defined in your application's route files instead. See the Migration Guide below if upgrading from an older version.

Redirect URL Requirements

Apple has strict requirements for the redirect (callback) URL:

The package validates your redirect URL at auth initiation and throws an InvalidRedirectUrlException with a clear error message if it doesn't meet these requirements.

Common mistakes:

Implementation

Button

Add the following blade directive to your login page:

Parameter Definition
$color String, either "black" or "white.
$hasBorder Boolean, either true or false.
$type String, either "sign-in" or "continue".
$borderRadius Integer, greater or equal to 0.

CSRF Exclusion

Apple sends the authorization response as a POST request to your callback URL. This would normally trigger a 419 | Page Expired (CSRF token mismatch) error. This package automatically excludes the configured callback route from CSRF verification, so no additional configuration is required.

This is safe because Apple callbacks are validated via the OAuth state parameter, not CSRF tokens. If you need to manually exclude the route for any reason, you can use one of these approaches:

Option A: Exclude the route in your VerifyCsrfToken middleware (Laravel 10 and earlier):

Option B: Use withoutMiddleware on the route (Laravel 11+):

Controller

This implementation uses Socialite to get the login credentials. The following is an example implementation of the controller:

Note that when processing the returned $user object, it is critical to know that the sub element is the unique identifier for the user, NOT the email address. For more details, visit https://developer.apple.com/documentation/signinwithapplerestapi/authenticating_users_with_sign_in_with_apple.

Missing Authorization Code

If you receive an error about a missing authorization code in the callback, check:

  1. Your callback route must accept POST requests — Apple uses response_mode=form_post, which means the authorization code is sent as a POST form parameter, not a URL query parameter. Use Route::post(), not Route::get().

  2. CSRF protection must be disabled for the callback — Since Apple's POST doesn't include a CSRF token, Laravel will return a 419 error and the code will never reach your controller. See the CSRF Exclusion section above.

  3. The redirect URL must exactly match — The URL in your .env (APPLE_REDIRECT) must exactly match the Return URL configured in your Apple Developer account, including the protocol, domain, and path.

Handling Revoked Access

When a user revokes your app's access via Apple ID settings, Apple sends a server-to-server notification. This package provides an AppleNotificationController and AppleAccessRevoked event to handle this.

1. Register the notification route:

2. Listen for the revocation event:

3. Configure the endpoint in Apple Developer:

Add your notification URL (https://example.com/apple/notifications) in the Apple Developer portal under your Services ID configuration.

Important: Apple only provides the user's name and email on the first authorization. If a user revokes access and re-authenticates, Apple treats it as a new sign-in but may not provide the name again. Always store the user's name on first sign-in.

Handling re-authentication after revocation:

When a user revokes and re-authenticates, Apple may assign a new sub value. The Socialite user object includes an is_returning_user flag to help you detect this:

Security: The notification endpoint verifies Apple's JWT signatures against Apple's public keys (fetched from https://appleid.apple.com/auth/keys). Keys are cached for 1 hour. Unsigned or forged notifications are rejected.

Testing

This package includes unit, feature, and browser tests. Unit and feature tests run without any additional dependencies:

Browser Tests

Browser tests use Laravel Dusk via orchestra/testbench-dusk and require a Chrome-based browser installed on your machine.

Install Chrome or Chromium:

Install Chromedriver:

The package uses orchestra/dusk-updater (included as a dev dependency) to manage the Chromedriver binary. Run this to auto-detect your Chrome version and install the matching Chromedriver:

Run browser tests:

Run all tests:

Migration Guide

Upgrading from versions prior to the config update

The configuration has been simplified. The following changes were made:

Old Key New Behavior
SIGN_IN_WITH_APPLE_LOGIN Removed. Define your login route in your application's route files instead of the config.
SIGN_IN_WITH_APPLE_REDIRECT Renamed to APPLE_REDIRECT. Old name still works as fallback.
SIGN_IN_WITH_APPLE_CLIENT_ID Renamed to APPLE_CLIENT_ID. Old name still works as fallback.
SIGN_IN_WITH_APPLE_CLIENT_SECRET Renamed to APPLE_CLIENT_SECRET. Old name still works as fallback.

Steps to upgrade:

  1. Remove SIGN_IN_WITH_APPLE_LOGIN from your .env file.
  2. Rename env vars: SIGN_IN_WITH_APPLE_REDIRECTAPPLE_REDIRECT, SIGN_IN_WITH_APPLE_CLIENT_IDAPPLE_CLIENT_ID, SIGN_IN_WITH_APPLE_CLIENT_SECRETAPPLE_CLIENT_SECRET. The old names continue to work as fallbacks.
  3. If you relied on the login config key for the @signInWithApple Blade directive button URL, define the route in your application's routes file and update the directive or link accordingly.
  4. The package will emit a E_USER_DEPRECATED notice if the old login key is still present, giving you time to migrate before it is fully removed.

Credits

  1. https://developer.okta.com/blog/2019/06/04/what-the-heck-is-sign-in-with-apple
  2. https://developer.apple.com/sign-in-with-apple/get-started

Commitment to Quality

During package development I try as best as possible to embrace good design and development practices, to help ensure that this package is as good as it can be. My checklist for package development includes:

Troubleshooting

invalid_client Error

This means Apple rejected your credentials. Common causes:

invalid_grant Error

This means the authorization code was rejected. Common causes:

Missing Configuration

If you see Sign In With Apple is missing required config, ensure you have set the following in your .env:

Contributing

Please observe and respect all aspects of the included Code of Conduct.

Reporting Issues

When reporting issues, please fill out the included template as completely as possible. Incomplete issues may be ignored or closed if there is not enough information included to be actionable.

Submitting Pull Requests

Please review the Contribution Guidelines. Only PRs that meet all criterium will be accepted.

If you ❤️ open-source software, give the repos you use a ⭐️.

We have included the awesome symfony/thanks composer package as a dev dependency. Let your OS package maintainers know you appreciate them by starring the packages you use. Simply run composer thanks after installing this package. (And not to worry, since it's a dev-dependency it won't be installed in your live environment.)


All versions of laravel-sign-in-with-apple with dependencies

PHP Build Version
Package Version
Requires php Version ^8.2
firebase/php-jwt Version ^7.0
illuminate/support Version ^11.0|^12.0|^13.0
laravel/socialite Version ^5.6
Composer command for our command line client (download client) This client runs in each environment. You don't need a specific PHP version etc. The first 20 API calls are free. Standard composer command

The package mikebronner/laravel-sign-in-with-apple contains the following files

Loading the files please wait ...