Download the PHP package yatilabs/laravel-api-access without Composer
On this page you can find all versions of the php package yatilabs/laravel-api-access. It is possible to download/install these versions without Composer. Possible dependencies are resolved automatically.
Download yatilabs/laravel-api-access
More information about yatilabs/laravel-api-access
Files in yatilabs/laravel-api-access
Package laravel-api-access
Short Description Laravel package for comprehensive API key management with domain restrictions, usage tracking, and secure authentication
License MIT
Informations about the package laravel-api-access
Laravel API Access Package
A comprehensive Laravel package for managing API keys with domain restrictions, secret authentication and middleware protection with logging for enabling secure API access for partner applications.
✨ Features
- Complete API Key Management: Create, update, delete, and manage API keys with full metadata
- Model Owner Support: Link API keys to specific model instances (Users, Organizations, etc.)
- Domain Restrictions: Restrict API keys to specific domains with wildcard pattern support
- Secure Authentication: Multiple authentication methods with bcrypt secret hashing
- Test/Live Modes: Separate environments with different validation rules
- Beautiful UI: Modern responsive interface with copy buttons and modals
- Built-in Controllers & Routes: No need to create controllers in your app
- Usage Tracking: Track API key usage and last used timestamps
- API Request Logging: Log all API requests with filtering and export options
- Middleware for Protection: Easy-to-use middleware to protect your API routes
- Copy-to-Clipboard: Easy copying of API keys and secrets
- Soft Deletes: API keys are soft deleted for data integrity
🚀 Quick Installation
1. Install via Composer
2. Publish and Run Migrations
3. Publish Assets (CSS)
4. Publish Configuration (Optional)
📋 Usage
Built-in Routes
The package automatically registers routes for you! No need to create controllers.
By default, the management interface is available at: /api-access
Configuration
Publish and edit the config file:
php 'layout' => 'layouts.app', // Your app's main layout blade
<!DOCTYPE html>
bash php artisan api-access:publish-config --force
Available Routes
The package provides these routes automatically:
GET /api-access- Main management interfacePOST /api-access/api-keys- Create API keyPOST /api-access/api-keys/{id}/update- Update API keyPOST /api-access/api-keys/{id}/delete- Delete API keyPOST /api-access/api-keys/{id}/regenerate-secret- Regenerate secretPOST /api-access/api-keys/{id}/toggle-status- Toggle active statusPOST /api-access/domains- Create domain restrictionPOST /api-access/domains/{id}/update- Update domain restrictionPOST /api-access/domains/{id}/delete- Delete domain restriction
Navigation
Simply visit /api-access in your application (after authenticating) to access the management interface.
🛡️ API Authentication
Using the Middleware
Add the middleware to protect your API routes:
Authentication Methods
The package supports multiple authentication methods:
-
Bearer Token (Recommended)
-
Custom Header
-
Query Parameters
- Request Body
🔧 Advanced Usage
Custom Middleware
You can create custom middleware that uses the API key verification:
Using the Service Directly
If you want to manage API keys programmatically:
Test Mode Domain Configuration
In test mode, API keys automatically allow domains specified in the localhost_domains configuration array. This makes development easier by allowing local development domains without manually adding domain restrictions.
Default allowed domains in test mode:
localhost127.0.0.1::1(IPv6 localhost)0.0.0.0*.test(any .test domain)*.local(any .local domain)*.dev(any .dev domain)
You can customize these in your config file:
Note: Wildcard patterns are supported in the localhost_domains configuration.
🏢 Model Owner Support
The package supports linking API keys to specific model instances (e.g., Users, Organizations, Projects, etc.). This feature allows you to track which entity owns each API key.
Configuration
Configure model ownership in your configuration file:
Usage
When model owner support is enabled:
- Creating API Keys: You can optionally (or require) selecting an owner when creating API keys
- Management Interface: The owner information is displayed in API key lists and details
- Logs: API key owner information is included in request logs
- Programmatic Access: You can access owner relationships in your code
Programmatic Usage
Customization Examples
For Organizations:
For Projects:
🤝 Contributing
Contributions are welcome! Please feel free to submit a Pull Request.
📄 License
This package is open-sourced software licensed under the MIT license.
🆘 Support
If you encounter any issues or have questions, please open an issue on GitHub.
All versions of laravel-api-access with dependencies
illuminate/support Version ^8.0|^9.0|^10.0|^11.0
illuminate/http Version ^8.0|^9.0|^10.0|^11.0
guzzlehttp/guzzle Version ^7.0