Download the PHP package sanjay-np/laravel-authenticator without Composer
On this page you can find all versions of the php package sanjay-np/laravel-authenticator. It is possible to download/install these versions without Composer. Possible dependencies are resolved automatically.
Download sanjay-np/laravel-authenticator
More information about sanjay-np/laravel-authenticator
Files in sanjay-np/laravel-authenticator
Package laravel-authenticator
Short Description A Laravel package for TOTP authentication with QR code scanning capabilities
License MIT
Homepage https://github.com/sanjay-np/laravel-authenticator
Informations about the package laravel-authenticator
Laravel Authenticator
A Laravel package for Time-based One-Time Password (TOTP) authentication with Blade shortcode support and optional QR code display.
Features
- TOTP generation and verification using
spomky-labs/otphp. - Encrypted secrets stored via Laravel Crypt.
- Per-client secrets with active scope and last-used tracking.
- Blade directive
@totp([...])to render current code with timer. - Configurable period, digits, algorithm, window, QR settings.
- Tested with Pest + Orchestra Testbench.
Requirements
- PHP: ^8.3
- Laravel: ^10 || ^11 || ^12
Installation
-
Install via Composer:
- Publish only what you need (config or migration):
-
Publish config only:
- Publish migration only:
This will place:
- Config at
config/authenticator.php - Migration (timestamped) under
database/migrations
- Run migrations:
Configuration
Update config/authenticator.php as needed:
- totp.period: default 60 seconds
- totp.digits: default 6
- totp.algorithm:
sha1|sha256|sha512 - totp.window: allowed drift windows for verification
Usage
Service API
Facade
Blade Directive (Shortcode)
Render a live-updating code with a progress timer (auto-refresh via page reload each period):
- secret_id: the
authenticator_secrets.idvalue - display:
code|qr|both|minimal(currentlycodeis implemented) - show_timer:
true|false
Database
Table: authenticator_secrets
- client_id: bigint (application user id or similar)
- secret: encrypted string via
Crypt - label, issuer, algorithm, digits, period, is_active, last_used_at
A migration is provided and can be published using the commands above. Ensure APP_KEY is set.
Testing
This package ships with Pest tests.
-
Run all tests:
- With coverage:
Security Considerations
- Secrets are encrypted at rest using Laravel Crypt.
- Ensure APP_KEY is configured in production.
- Consider rotating secrets if compromised and track
last_used_at. - Limit exposure of raw secrets;
getClientTotpDisplayDatahides secrets by default.
Versioning & Release
- Follow SemVer:
MAJOR.MINOR.PATCH. - Add changes to a
CHANGELOG.md. - Tag releases in Git:
git tag vX.Y.Z && git push --tags. - Configure GitHub Actions (optional) to run tests and build on PRs.
Suggested GitHub Actions Workflow (optional)
Create .github/workflows/tests.yml:
License
MIT
All versions of laravel-authenticator with dependencies
spatie/laravel-package-tools Version ^1.16
illuminate/contracts Version ^10.0||^11.0||^12.0
spomky-labs/otphp Version ^11.0
endroid/qr-code Version ^5.0
bacon/bacon-qr-code Version ^3.0