Introduction 🖖

This is a simple package to generate and validate OTPs (One Time Passwords). This can be implemented mostly in Authentication. This is a fork from ichtrojan/laravel-otp. In this version the default $identifier type is App\User instead of string type.

Installation 💽

Install via composer

composer require kenkioko/laravel-otp

Add service provider to the config/app.php file

    'providers' => [

Add alias to the config/app.php file


    'aliases' => [
        'OTP' => Kenkioko\OTP\OTP::class,

Publish files with:

php artisan vendor:publish --provider="Kenkioko\OTP\OTPServiceProvider"

Run Migrations

php artisan migrate

Usage 🧨

Response are returned as objects. You can access its attributes with the arrow operator (->)

Generate OTP


OTP::generate(App\User $identifier, int $digits = 4, int $validity = 5)
  • $identifier: The identity that will be tied to the OTP of type \App\User::class.
  • $digit (optional | default = 4): The amount of digits to be generated, can be any of 4, 5 and 6.
  • $validity (optional | default = 5): The validity period of the OTP in minutes.



$user = App\User::find(1);
$otp = OTP::generate($user, 6, 15);

This will generate a six digit OTP that will be valid for 15 minutes and the success response will be:

  "status": true,
  "token": "282581",
  "message": "OTP generated"

Validate OTP


OTP::validate(App\User $identifier, string $token)
  • $identifier: The identity that is tied to the OTP of type \App\User::class.
  • $token: The token tied to the identity.



$user = App\User::find(1);
$otp = OTP::generate($user, '282581');

Extend Expiry of OTP


OTP::extend(App\User $identifier, string $token, int $validity = 1)
  • $identifier: The identity that is tied to the OTP of type \App\User::class.
  • $token: The token tied to the identity.
  • $validity (optional | default = 1): The validity period of the OTP in minutes.



$user = App\User::find(1);
$otp = OTP::extend($user, '282581', 5);


Uses Laravel's localization features to show the messages. The translations are found in translations\en\messages.php file. Please use the file as a template for other languages.

On Success

  "status": true,
  'message' => __("laravel-otp::messages.otp_message", ['password' => '12345']),
  // "otp_message" => "Your one-time password (OTP) to enter the system is: :password"


  "status": false,
  'message' => __("laravel-otp::messages.otp_valid"),
  // "otp_valid" => "The one-time password (OTP) token is valid."

Not Valid

  "status": false,
  'message' => __("laravel-otp::messages.otp_invalid"),
  // "otp_invalid" => "The one-time password (OTP) token is  not valid".


  "status": false,
  'message' => __("laravel-otp::messages.otp_expired"),
  // "otp_expired" => "token seems to be expired. Please request a new OTP code."

Missing field

  "status": false,
  'message' => __("laravel-otp::messages.otp_missing"),
  // "otp_missing" => "The one-time password (OTP) token does not exist.",


  "status": false,
  'message' => __("laravel-otp::messages.otp_mismatch"),
  // "otp_mismatch" => "The one-time password (OTP) token doesn't match any token in database."

Expiry extended

  "status": false,
  'message' => __("laravel-otp::messages.otp_extended", ['minutes' => 5 ]),
  // "otp_extended" => "Your one-time password (OTP) token expiry was extended by :minutes minutes."


This is a fork from ichtrojan/laravel-otp.

If you find an issue with this package or you have any suggestion please help out. I am not perfect.