Download the PHP package novvor/central-sdk-php without Composer

On this page you can find all versions of the php package novvor/central-sdk-php. It is possible to download/install these versions without Composer. Possible dependencies are resolved automatically.

FAQ

After the download, you have to make one include require_once('vendor/autoload.php');. After that you have to import the classes with use statements.

Example:
If you use only one package a project is not needed. But if you use more then one package, without a project it is not possible to import the classes with use statements.

In general, it is recommended to use always a project to download your libraries. In an application normally there is more than one library needed.
Some PHP packages are not free to download and because of that hosted in private repositories. In this case some credentials are needed to access such packages. Please use the auth.json textarea to insert credentials, if a package is coming from a private repository. You can look here for more information.

  • Some hosting areas are not accessible by a terminal or SSH. Then it is not possible to use Composer.
  • To use Composer is sometimes complicated. Especially for beginners.
  • Composer needs much resources. Sometimes they are not available on a simple webspace.
  • If you are using private repositories you don't need to share your credentials. You can set up everything on our site and then you provide a simple download link to your team member.
  • Simplify your Composer build process. Use our own command line tool to download the vendor folder as binary. This makes your build process faster and you don't need to expose your credentials for private repositories.
Please rate this library. Is it a good library?

Informations about the package central-sdk-php

Novvor Central SDK for PHP

CI

Official server-side SDK for integrating PHP applications with the Novvor Central control plane.

It provides three deliberately small, tenant-bound capabilities:

The SDK does not create local users, roles, workspaces, or business records. Those decisions remain inside each consuming application.

Requirements

Installation

The package uses PSR-18 and PSR-17. You may inject your existing HTTP client and request factory or use the secure Guzzle factory.

Never commit the application or snapshot verification key. They are separate, product-scoped secrets and must come from a secret manager.

Installation contract

For repeatable onboarding, generate or construct the three public values once from the registered application. The SDK deliberately never creates, prints, or writes credentials into .env.

Store ENIX_CENTRAL_API_KEY, ENIX_CENTRAL_WEBHOOK_SECRET, and ENIX_CENTRAL_ENTITLEMENT_SNAPSHOT_VERIFICATION_KEY through the deployment secret manager as three distinct, product-scoped values. They must never be derived from each other, an application key, or an identity client secret.

CentralEnvironmentTemplate::deploymentContract() returns a machine-readable checklist of these names and purposes without ever accepting or rendering their values. Deployment automation can use it to prepare an application's contract without turning the SDK into a credential distribution channel.

The package also exposes this as a Composer binary after installation:

It emits public configuration plus required secret names only. The Central control plane must still register the application and grant least-privilege scopes (for example entitlements.read and heartbeat.write) before the application can connect.

Tenant entitlements

The SDK rejects responses whose application or tenant boundary differs from the request. Consumers should persist a short-lived projection only for resilience and must never turn a stale or missing projection into access.

Signed entitlement snapshots (contract v2)

Use the immutable snapshot only when an application needs to reconcile its local modules, capabilities or limits. The SDK requires a distinct product-scoped snapshot verification key and rejects missing contract headers, bad signatures, cross-boundary payloads and tampered snapshot hashes.

Do not use a v2 snapshot to make an unauthenticated browser authorization decision. It is a server-to-server synchronisation projection. A snapshot that cannot be retrieved or verified must not grant new access.

One-time application launch

Central sends an opaque, single-use code to the application's /sso/consume endpoint. The application exchanges it server-to-server:

The SDK validates:

Only after validation should the application map the Central identity to a local user and create its own session. Permission mapping must remain least-privilege and application-specific.

Authentication and request integrity

Authenticated requests include:

Central enforces credential scope, application status, optional IP allowlists, timestamp tolerance, nonce replay protection, and audit logging.

Request signing is enabled by default. Disabling it is intended only for a controlled migration with a first-party registration that does not require HMAC.

Error handling

Exception Meaning
CentralAuthenticationException Missing, invalid, or revoked credential
CentralAuthorizationException Scope, application status, or policy denied
CentralRateLimitException Central throttled the caller
CentralUnavailableException Network or Central 5xx failure
CentralProtocolException Invalid JSON, unsafe JWKS, bad JWT, or boundary mismatch

Exceptions expose only HTTP status and correlation ID. Response bodies and credentials are intentionally not copied into exception messages.

Retry behavior

Only idempotent GET requests are retried, and only for transient network errors, 429, 502, 503, or 504. The one-time launch-code exchange is never retried by the SDK because replay semantics must remain explicit.

Operational guidance

See the integration contract and the release policy. See integration evidence for the authenticated runtime contract that Central uses to evaluate an external application's SDK readiness.

^2.5 is available through immutable release tags. Consumers must still use a reviewed lockfile update and validate their own tenant-bound integration; an SDK tag alone is not proof of a live Central connection.


All versions of central-sdk-php with dependencies

PHP Build Version
Package Version
Requires php Version ^8.2
firebase/php-jwt Version ^7.0
guzzlehttp/guzzle Version ^7.0
guzzlehttp/psr7 Version ^2.7
psr/http-client Version ^1.0
psr/http-factory Version ^1.0
Composer command for our command line client (download client) This client runs in each environment. You don't need a specific PHP version etc. The first 20 API calls are free. Standard composer command

The package novvor/central-sdk-php contains the following files

Loading the files please wait ...