v1.0.7 2016-12-02 14:20 UTC

This package is not auto-updated.

Last update: 2024-04-08 11:28:13 UTC


The main motivation for creating this package is to have a lot more flexibility and security for API based communication. I have used JWT in the past and found it to be scarily easy to hack!

I have followed the principles outlined and implemented at Twitter.


To make API requests, please use the following plugins Angular

How it works

Client sends a request to the API with a series of headers. A HMAC SHA512 is generated based on these along with request data therefore it eliminates man in the middle attacks, replay attacks and injections.

A user is identified via an access token (which expires) or an api key.

The headers are:

'key' or 'access-token'
'client-nonce' (randomly generated string on the client side to prevent replay attacks as the nonce is stored against an api log on the database)
'hash' (generated with all the headers and request data as a json array)
'token' (not used to generate hash obviously)

Quick Start


Run composer command

$ composer require linkthrow/hmac-packet-auth

In your config/app.php add 'LinkThrow\HmacPacketAuth\Provider\HmacPacketAuthServiceProvider' to the end of the $providers array

'providers' => array(



Run the artisan command below to publish the configuration file

$ php artisan vendor:publish

Add the following properties to your .env file


Run the migrate command below to add the database tables required

$ php artisan migrate

Add 'auth.hmac' to any routes you want to protect!!!


