Libraries tagged by signed
nicrame/rc_smime
689 Downloads
Roundcube webmail plugin to verify S/MIME signed messages
nawasara/api
331 Downloads
Public REST API plumbing for the Nawasara superapp framework — API token management with hashed storage, scope registry, HMAC-signed stream URLs, and audit log infrastructure. Domain packages (cctv, wifi, ...) provide their own routes/controllers/transformers; this package owns auth + scope + token lifecycle.
montu/module-affiliate
231 Downloads
Montu Affiliate Tracking Extension for Magento 2 - Captures affiliate referral codes, attributes orders, sends signed order webhooks, and renders a white-label affiliate storefront.
mindtwo/laravel-monitoring
370 Downloads
Laravel plugin of the mindtwo monitoring suite: framework-specific collectors, a scheduled push job and a signed pull endpoint on top of mindtwo/base-monitoring.
mindtwo/base-monitoring
510 Downloads
Framework-agnostic core of the mindtwo monitoring suite. Safely collects infrastructure, package and security-audit data and ships it as a signed snapshot.
konfig/snaptrade-php-7-sdk
646 Downloads
Connect brokerage accounts to your app for live positions and trading. ## Rate limiting Two limits apply to requests signed with your `clientId`. The stricter one wins, and exceeding either returns `429 Too Many Requests`. - **Customer-level** — 250 requests/minute by default, scoped to your `clientId` and applied across all endpoints. Reported in `X-RateLimit-Limit`, `X-RateLimit-Remaining` and `X-RateLimit-Reset`. - **Account-level** — 10 requests/minute per account, scoped to (`clientId`, `accountId`). All covered operations for one account draw on the same bucket — reading balances and reading positions share it — and enforcement does not depend on the HTTP method, so updating an account consumes the same bucket as reading it. Only enforced for Personal users, and only for integrations it has been rolled out to — it is not yet in force for every Personal integration. It also does not apply on every operation that documents a 429 below. Where it applies it is reported in `X-RateLimit-Account-Limit`, `X-RateLimit-Account-Remaining` and `X-RateLimit-Account-Reset`. Do not read the absence of those headers as proof the limit is off — some configurations omit the rate limit headers while still enforcing the limit, so header absence tells you nothing about your allowance. On a 429, `X-RateLimit-Remaining: 0` means you hit the customer-level limit and `X-RateLimit-Account-Remaining: 0` means the account-level one. Wait for the corresponding `*-Reset` value (seconds) before retrying, or fall back to exponential backoff with jitter. Not every 429 is explained by those headers. A separate per-authenticated-user limit, reported in no `X-RateLimit-*` header, covers OAuth-authenticated requests and signed requests in configurations where the customer-level limit is not in effect — on the operations that use the default throttles. A few operations override those and are governed by the customer-level limit alone. The two do not stack: a signed request governed by the customer-level limit above is not additionally subject to the per-user one. If a 429 arrives with no header at zero — or with no `X-RateLimit-*` headers at all — honour `Retry-After` and back off. Treat the remaining counts as a hint, not a guarantee that the next request will succeed. Because the customer-level limit applies everywhere, any signed request can return 429. **OAuth-authenticated requests are an exception.** They are not subject to the customer-level limit and do not receive `X-RateLimit-Limit`, `X-RateLimit-Remaining` or `X-RateLimit-Reset` — do not wait on those headers or design around a customer-level allowance on this path. The account-level limit still applies to them on the account-data endpoints above, reported in the `X-RateLimit-Account-*` headers. On operations using the default throttles the per-user limit above applies to them as well, so an OAuth request can be rejected while the account headers still show capacity; on the few operations that override those throttles, OAuth callers have no per-user ceiling at all. Drive retries from `Retry-After` and exponential backoff with jitter rather than from the headers. See https://docs.snaptrade.com/docs/ratelimiting.
kirchdev/laravel-device-sessions
252 Downloads
Device-bound login sessions for Laravel: per-device remember-me tokens, a "where am I signed in" device list, and revoke/rename — privacy-respecting and Fortify-agnostic.
kinetis/auth-jwt
63 Downloads
Stateless JWT authentication middleware for Kinetis (HS256/RS256, optional per-token revocation), verifying signed tokens via firebase/php-jwt. See kinetis/auth instead for opaque Bearer-token validation against your own storage.
kennethormandy/craft-s3securedownloads
11787 Downloads
Return an AWS signed URL and proxy the download request.
jweiland/yellowpages2
5390 Downloads
Industry directory with frontend self-registration, moderation via signed mail links, EXT:maps2 integration and native FAL uploads for logo and images
juancarlo99/pdf-pades-signature-extractor
287 Downloads
PHP library to extract PAdES digital signature data from signed PDF files
josemodi97/yii2-ecitizen-gateway
40 Downloads
Beginner-friendly eCitizen payment gateway for Laravel, Yii2, and standalone PHP: build signed checkout payloads, render pay buttons, and verify callbacks with plain-English fields. Plain PHP, no required framework dependencies.
jeffersongoncalves/laravel-sso-client
48 Downloads
SSO client for Laravel: Authorization Code + PKCE login, RS256/JWKS or signed userinfo token validation, user sync and back-channel Single Logout.
goldnead/statamic-lead-magnets
208 Downloads
Confirm-first resource delivery: a visitor asks for a file, confirms the address, and the download link is signed, time-boxed and audited.
goldnead/statamic-booking
179 Downloads
Records Cal.com bookings in Statamic: signed webhooks, idempotent, with a seam for what happens next.