Search by

roundly-consulting / crypto-for-laravel

mihaliak

Native, audited cryptographic and encoding primitives for Laravel: JWS/JOSE, TOTP/HOTP, WebAuthn signature verification, HMAC, authenticated encryption (AES-256-GCM), CSPRNG tokens, and codecs — zero-config, à la carte.

Package info

github.com/roundly-consulting/crypto-for-laravel

pkg:composer/roundly-consulting/crypto-for-laravel

Fund package maintenance!

Patreon

Statistics

Installs: 96

Dependents: 12

Suggesters: 0

Stars: 0

Open Issues: 0

1.0.0 2026-10-03 17:58 UTC

This package is auto-updated.

Last update: 2026-10-03 18:03:15 UTC


README

Cryptographic Primitives for Laravel — Roundly open source

Latest release Tests Code style Donate Patreon Crypto

Cryptographic Primitives for Laravel

Native cryptographic and encoding primitives for Laravel — JWS/JOSE and JWK, TOTP/HOTP, WebAuthn signature verification, HMAC, AES-256-GCM authenticated encryption, X.509, CSPRNG tokens and codecs — with zero third-party crypto dependencies. It is zero-config: every key is an explicit argument, and every primitive works on its own.

Installation

Requires PHP 8.4 (ext-openssl, ext-hash, ext-mbstring; ext-sodium for Ed25519), Laravel 12 or 13.

composer require roundly-consulting/crypto-for-laravel

Usage

Sign and verify a token — the algorithm is always pinned, never read from the token:

use RoundlyConsulting\Crypto\Facades\Crypto;
use RoundlyConsulting\Crypto\Signature\Algorithm;

$key = Crypto::keys()->ec()->fromStorageOrGenerate('local', 'keys/jwt.pem'); // P-256, created on first boot

$token = Crypto::jws()->sign(
    ['kid' => 'k1'],
    ['sub' => 'alice', 'exp' => now()->addHour()->timestamp],
    Crypto::es($key),
);

$claims = Crypto::jws()->verify($token, Crypto::es($key), Algorithm::ES256);
$claims->assertTemporal(leeway: 30);   // throws once expired
$claims->string('sub');                // "alice"

Check a webhook, encrypt a value bound to its record, and verify a one-time password:

$expected = 'sha256='.Crypto::hmac()->signHex($request->getContent(), $webhookSecret);
Crypto::constantTimeEquals($expected, $request->header('X-Hub-Signature-256', ''));

$dataKey = Crypto::randomBytes(32);
$sealed = Crypto::aes256Gcm()->seal($dataKey, $iban, associatedData: 'invoices:42');
$iban = Crypto::aes256Gcm()->open($dataKey, $sealed, associatedData: 'invoices:42');

$secret = Crypto::randomSecret();      // base32, for an authenticator app
Crypto::provisioningUri($secret, 'alice@example.com', 'Acme Inc');
Crypto::totp()->verify($secret, $code); // the matched time step, or false

Documentation

The full documentation — configuration, every feature and its API, and testing — lives on our website: roundly-consulting.com/open-source/docs/crypto-for-laravel

Release notes are in CHANGELOG.md. To contribute, see the contributing guide.

Support our work

This package is free and open source, built and maintained by Roundly Consulting. If it saves you time, please consider supporting our open-source work — a one-time donation, a monthly pledge on Patreon or a crypto donation helps fund maintenance, new features and new packages.

Donate to Roundly open source Become a patron on Patreon Donate crypto: BTC, ETH, BNB or SOL

License

The MIT License (MIT). See LICENSE.md.