roundly-consulting / crypto-for-laravel
Native, audited cryptographic and encoding primitives for Laravel: JWS/JOSE, TOTP/HOTP, WebAuthn signature verification, HMAC, authenticated encryption (AES-256-GCM), CSPRNG tokens, and codecs — zero-config, à la carte.
Package info
github.com/roundly-consulting/crypto-for-laravel
pkg:composer/roundly-consulting/crypto-for-laravel
Fund package maintenance!
Requires
- php: ^8.4
- ext-hash: *
- ext-mbstring: *
- ext-openssl: *
- illuminate/contracts: ^12.0|^13.0
- illuminate/support: ^12.0|^13.0
- roundly-consulting/package-toolkit-for-laravel: ^1.0
Requires (Dev)
- larastan/larastan: ^3.0
- laravel/pint: ^1.18
- mockery/mockery: ^1.6
- nunomaduro/collision: ^8.5
- orchestra/testbench: ^10.0|^11.0
- pestphp/pest: ^4.0
- pestphp/pest-plugin-arch: ^4.0
- pestphp/pest-plugin-laravel: ^4.0
- phpstan/phpstan-deprecation-rules: ^2.0
- roundly-consulting/testing-for-laravel: ^1.0
Suggests
- ext-sodium: Required for Ed25519 (EdDSA) signature verification; ships enabled by default on modern PHP.
Provides
None
Conflicts
None
Replaces
None
README
Cryptographic Primitives for Laravel
Native cryptographic and encoding primitives for Laravel — JWS/JOSE and JWK, TOTP/HOTP, WebAuthn signature verification, HMAC, AES-256-GCM authenticated encryption, X.509, CSPRNG tokens and codecs — with zero third-party crypto dependencies. It is zero-config: every key is an explicit argument, and every primitive works on its own.
Installation
Requires PHP 8.4 (ext-openssl, ext-hash, ext-mbstring; ext-sodium for Ed25519), Laravel 12
or 13.
composer require roundly-consulting/crypto-for-laravel
Usage
Sign and verify a token — the algorithm is always pinned, never read from the token:
use RoundlyConsulting\Crypto\Facades\Crypto; use RoundlyConsulting\Crypto\Signature\Algorithm; $key = Crypto::keys()->ec()->fromStorageOrGenerate('local', 'keys/jwt.pem'); // P-256, created on first boot $token = Crypto::jws()->sign( ['kid' => 'k1'], ['sub' => 'alice', 'exp' => now()->addHour()->timestamp], Crypto::es($key), ); $claims = Crypto::jws()->verify($token, Crypto::es($key), Algorithm::ES256); $claims->assertTemporal(leeway: 30); // throws once expired $claims->string('sub'); // "alice"
Check a webhook, encrypt a value bound to its record, and verify a one-time password:
$expected = 'sha256='.Crypto::hmac()->signHex($request->getContent(), $webhookSecret); Crypto::constantTimeEquals($expected, $request->header('X-Hub-Signature-256', '')); $dataKey = Crypto::randomBytes(32); $sealed = Crypto::aes256Gcm()->seal($dataKey, $iban, associatedData: 'invoices:42'); $iban = Crypto::aes256Gcm()->open($dataKey, $sealed, associatedData: 'invoices:42'); $secret = Crypto::randomSecret(); // base32, for an authenticator app Crypto::provisioningUri($secret, 'alice@example.com', 'Acme Inc'); Crypto::totp()->verify($secret, $code); // the matched time step, or false
Documentation
The full documentation — configuration, every feature and its API, and testing — lives on our website: roundly-consulting.com/open-source/docs/crypto-for-laravel
Release notes are in CHANGELOG.md. To contribute, see the contributing guide.
Support our work
This package is free and open source, built and maintained by Roundly Consulting. If it saves you time, please consider supporting our open-source work — a one-time donation, a monthly pledge on Patreon or a crypto donation helps fund maintenance, new features and new packages.
License
The MIT License (MIT). See LICENSE.md.