A lightweight and powerful OAuth 2.0 authorization and resource server library with support for all the core specification grants. This library will allow you to secure your API with OAuth and allow your applications users to approve apps that want to access their data from your API.

Fund package maintenance!

Installs: 86 833 667

Dependents: 262

Suggesters: 4

Security: 1

Stars: 6 489

Watchers: 209

Forks: 1 115

Open Issues: 94

9.0.0 2024-05-13 21:35 UTC


Latest Version Software License Build Status Coverage Status Quality Score Total Downloads

league/oauth2-server is a standards compliant implementation of an OAuth 2.0 authorization server written in PHP which makes working with OAuth 2.0 trivial. You can easily configure an OAuth 2.0 server to protect your API with access tokens, or allow clients to request new access tokens and refresh them.

Out of the box it supports the following grants:

  • Authorization code grant
  • Client credentials grant
  • Device authorization grant
  • Implicit grant
  • Refresh grant
  • Resource owner password credentials grant

The following RFCs are implemented:

This library was created by Alex Bilbie. Find him on Twitter at @alexbilbie.


The latest version of this package supports the following versions of PHP:

  • PHP 8.1
  • PHP 8.2
  • PHP 8.3

The openssl and json extensions are also required.

All HTTP messages passed to the server should be PSR-7 compliant. This ensures interoperability with other packages and frameworks.


composer require league/oauth2-server


The library documentation can be found at https://oauth2.thephpleague.com. You can contribute to the documentation in the gh-pages branch.


The library uses PHPUnit for unit tests.


Continuous Integration

We use Github Actions, Scrutinizer, and StyleCI for continuous integration. Check out our configuration files if you'd like to know more.

Community Integrations


See the project changelog


Contributions are always welcome. Please see CONTRIBUTING.md and CODE_OF_CONDUCT.md for details.


Bugs and feature request are tracked on GitHub.

If you have any questions about OAuth please open a ticket here; please don't email the address below.


If you discover any security related issues, please email andrew@noexceptions.io instead of using the issue tracker.


This package is released under the MIT License. See the bundled LICENSE file for details.


This code is principally developed and maintained by Andy Millington.

Between 2012 and 2017 this library was developed and maintained by Alex Bilbie.

PHP OAuth 2.0 Server is one of many packages provided by The PHP League. To find out more, please visit our website.

Special thanks to all of these awesome contributors.

Additional thanks go to the Mozilla Secure Open Source Fund for funding a security audit of this library.

The initial code was developed as part of the Linkey project which was funded by JISC under the Access and Identity Management programme.