A lightweight and powerful OAuth 2.0 authorization and resource server library with support for all the core specification grants. This library will allow you to secure your API with OAuth and allow your applications users to approve apps that want to access their data from your API.

Installs: 414 169

Dependents: 31

Stars: 1 831

Watchers: 164

Forks: 424

Open Issues: 31


Latest Version Software License Build Status Coverage Status Quality Score Total Downloads Gitter

A standards compliant OAuth 2.0 authorization server and resource server written in PHP which makes working with OAuth 2.0 trivial. You can easily configure an OAuth 2.0 server to protect your API with access tokens, or allow clients to request new access tokens and refresh them.

It supports out of the box the following grants:

  • Authorization code grant
  • Client credentials grant
  • Resource owner password credentials grant
  • Refresh grant

You can also define your own grants.

In addition it supports the following token types:

  • Bearer tokens
  • MAC tokens
  • JSON web tokens (coming soon)

You can also create you own tokens.


The following versions of PHP are supported:

  • PHP 5.4
  • PHP 5.5
  • PHP 5.6
  • HHVM


This library has full documentation, powered by Jekyll.

Contribute to this documentation in the gh-pages branch.


See the project releases page


Please see CONTRIBUTING for details.



Bugs and feature request are tracked on GitHub


If you discover any security related issues, please email hello@alexbilbie.com instead of using the issue tracker.


This package is released under the MIT License. See the bundled LICENSE file for details.


This code is principally developed and maintained by Alex Bilbie.

Special thanks to:

The initial code was developed as part of the Linkey project which was funded by JISC under the Access and Identity Management programme.