adeshsuryan / laravel-otp-login
Adds a one-time password step after Laravel login, with pluggable SMS, mail, log, and array channels.
Requires
- php: ^8.2
- illuminate/auth: ^12.0
- illuminate/contracts: ^12.0
- illuminate/database: ^12.0
- illuminate/http: ^12.0
- illuminate/mail: ^12.0
- illuminate/routing: ^12.0
- illuminate/session: ^12.0
- illuminate/support: ^12.0
Requires (Dev)
- orchestra/testbench: ^6.40|^7.40|^8.0|^9.0|^10.0
- phpunit/phpunit: ^9.6|^10.5|^11.0
Suggests
None
Provides
None
Conflicts
None
Replaces
None
This package is auto-updated.
Last update: 2026-10-03 19:09:59 UTC
README
Adds a one-time password step after a successful Laravel login. Delivery is pluggable: local log / array channels for development and CI, mail for Mailpit or real SMTP, and optional SMS adapters (Twilio, Nexmo/Vonage, Msg91, BioTekno).
Packagist: adeshsuryan/laravel-otp-login
GitHub: adeshsuryan/laravel-otp-login
Choose the right version
Pin the package major to your Laravel major. Legacy tags stay frozen for existing installs.
| Laravel | Package constraint | PHP | Status |
|---|---|---|---|
| 12.x | adeshsuryan/laravel-otp-login:^12.0 |
^8.2 | active |
| 11.x | adeshsuryan/laravel-otp-login:^11.0 |
^8.2 | active |
| 10.x | adeshsuryan/laravel-otp-login:^10.0 |
^8.1 | active |
| 9.x | adeshsuryan/laravel-otp-login:^9.0 |
^8.0 | active |
| 8.x | adeshsuryan/laravel-otp-login:^8.0 |
^8.0 | active |
| 5.x | adeshsuryan/laravel-otp-login:5.13 (or 5.8, …) |
historical | frozen |
# Modern composer require adeshsuryan/laravel-otp-login:^12.0 # Legacy Laravel 5 app — do not jump to ^12 composer require adeshsuryan/laravel-otp-login:5.13
Tags 0.1–5.13 are immutable historical releases for older Laravel 5-era apps.
Install (Laravel 8–12)
composer require adeshsuryan/laravel-otp-login:^12.0 php artisan vendor:publish --tag=otp-config php artisan migrate
Package discovery registers OTPServiceProvider automatically.
Environment
OTP_SERVICE_ENABLED=true OTP_SERVICE=log OTP_TIMEOUT=600 OTP_DIGIT_LENGTH=6 OTP_USER_PHONE_FIELD=phone OTP_AFTER_LOGIN_REDIRECT=/home
For CI and automated browsers use OTP_SERVICE=array or OTP_SERVICE=mail with Mailpit. Do not put Twilio/Nexmo keys in the test matrix.
After password login
Create a waiting OTP and send it:
use adeshsuryan\LaravelOTPLogin\OneTimePassword; $otp = OneTimePassword::create([ 'user_id' => $user->id, 'status' => 'waiting', ]); $otp->send($user); // redirect to route('otp.view')
Routes (middleware web + auth):
GET /login/verify→otp.viewPOST /login/check→otp.verify
Optional middleware alias: otp.verified.
Channels
| Key | Use |
|---|---|
log |
Default. Writes OTP to the Laravel log (and caches last OTP for tests). |
array |
Cache only. Best for PHPUnit. |
mail |
Laravel Mail (pair with Mailpit in Docker). |
twilio / nexmo / msg91 / biotekno |
Optional production SMS. |
Custom channel: implement adeshsuryan\LaravelOTPLogin\ServiceInterface and register the class under config/otp.php → services.
Tests
composer install
composer test
License
MIT. See LICENSE.md. Maintained by Adesh Kumar.
