Download the PHP package smithingdev/laravel-vault without Composer

On this page you can find all versions of the php package smithingdev/laravel-vault. It is possible to download/install these versions without Composer. Possible dependencies are resolved automatically.

FAQ

After the download, you have to make one include require_once('vendor/autoload.php');. After that you have to import the classes with use statements.

Example:
If you use only one package a project is not needed. But if you use more then one package, without a project it is not possible to import the classes with use statements.

In general, it is recommended to use always a project to download your libraries. In an application normally there is more than one library needed.
Some PHP packages are not free to download and because of that hosted in private repositories. In this case some credentials are needed to access such packages. Please use the auth.json textarea to insert credentials, if a package is coming from a private repository. You can look here for more information.

  • Some hosting areas are not accessible by a terminal or SSH. Then it is not possible to use Composer.
  • To use Composer is sometimes complicated. Especially for beginners.
  • Composer needs much resources. Sometimes they are not available on a simple webspace.
  • If you are using private repositories you don't need to share your credentials. You can set up everything on our site and then you provide a simple download link to your team member.
  • Simplify your Composer build process. Use our own command line tool to download the vendor folder as binary. This makes your build process faster and you don't need to expose your credentials for private repositories.
Please rate this library. Is it a good library?

Informations about the package laravel-vault

smithingdev/laravel-vault

Latest Version on Packagist Tests Total Downloads PHP Version

A small, focused Laravel client for HashiCorp Vault: AppRole/token authentication and KV2 secret CRUD. No domain assumptions — just the transport.

Requirements

Install

The service provider and Vault facade are auto-discovered.

Configure

Set these in .env:

TLS verification

VAULT_VERIFY controls how the Vault server's certificate is checked:

Logging

VAULT_LOG_CHANNEL is optional and disabled by default. When set to a configured log channel, the package logs a line on successful authentication and logs the raw Vault response body (at error level) whenever a request fails — the body is logged rather than thrown, so it never leaks into exception messages (see Errors).

Namespace modes

Vault supports two equivalent ways to address an Enterprise namespace, and this package lets you pick via VAULT_NAMESPACE_MODE:

Upgrading from a version without VAULT_NAMESPACE_MODE: the default is now header. If you previously relied on VAULT_KV_NAMESPACE, set VAULT_NAMESPACE_MODE=path (and keep VAULT_KV_NAMESPACE) to retain the old behavior.

Usage

Use the facade, or inject VaultService anywhere the container resolves dependencies:

KV2 operations

Return values and not-found behavior:

Method Returns When the path is missing (404)
read($path, $version = null) array<string, mixed>\|null null (also null if a 200 response carries no data.data)
write($path, array $data) void — (creates the path)
list($path) array<int, string> (keys directly under the path) []
delete($path) void no-op
destroy($path) void no-op

delete() soft-deletes the latest version — KV2 keeps it recoverable via Vault's undelete endpoint until it's destroyed. destroy() permanently removes all versions and metadata and cannot be undone. Any other failure throws (see Errors).

Authentication

authenticate() runs automatically on the first call and the token is cached for the process lifetime. With AppRole the client re-authenticates once on a 401/403 and retries the failed request, so an expired token is transparently refreshed. The token auth method uses a pre-issued token and cannot self-refresh.

Errors

Every failure surfaces as a single exception type, Smithingdev\Vault\Exceptions\VaultException (a RuntimeException), so you only have to catch one thing:

A VaultException is thrown when:

Exception messages are intentionally generic (e.g. Vault read 'foo' failed (HTTP 500).). The raw Vault response body is not included in the message — it is sent to the configured log channel instead (see Logging), so secrets and internal details don't leak into stack traces or error reporting.

Multiple namespaces

To promote secrets between environments with a single login, derive a clone bound to a sibling namespace. The clone shares the already-acquired token, so no second login happens.

In header mode, swap the Enterprise namespace with withNamespace():

In path mode, swap the full KV namespace path with withKvNamespace():

Each setter has a matching getter for reading what the instance is currently bound to — useful for deriving a sibling target from the current one:

What this package is not

It deliberately ships only auth + KV2 CRUD. Application-specific concepts belong in your app, not here.

Testing


All versions of laravel-vault with dependencies

PHP Build Version
Package Version
Requires php Version ^8.2
illuminate/http Version ^11.0|^12.0|^13.0
illuminate/support Version ^11.0|^12.0|^13.0
Composer command for our command line client (download client) This client runs in each environment. You don't need a specific PHP version etc. The first 20 API calls are free. Standard composer command

The package smithingdev/laravel-vault contains the following files

Loading the files please wait ...