roundly-consulting / passkeys-for-laravel
A native WebAuthn / FIDO2 passkey relying party for Laravel — registration and authentication ceremonies with ES256/RS256/EdDSA, zero third-party crypto dependencies.
Package info
github.com/roundly-consulting/passkeys-for-laravel
pkg:composer/roundly-consulting/passkeys-for-laravel
Fund package maintenance!
Requires
- php: ^8.4
- ext-json: *
- illuminate/cache: ^12.0|^13.0
- illuminate/contracts: ^12.0|^13.0
- illuminate/database: ^12.0|^13.0
- illuminate/events: ^12.0|^13.0
- illuminate/support: ^12.0|^13.0
- roundly-consulting/crypto-for-laravel: ^1.0
- roundly-consulting/enums-for-laravel: ^1.0
- roundly-consulting/package-toolkit-for-laravel: ^1.0
Requires (Dev)
- larastan/larastan: ^3.0
- laravel/pint: ^1.0
- nunomaduro/collision: ^8.0
- orchestra/testbench: ^10.0|^11.0
- pestphp/pest: ^4.0
- roundly-consulting/testing-for-laravel: ^1.0
Suggests
- ext-sodium: Enables optional Ed25519 (EdDSA / COSE -8) signature verification.
Provides
None
Conflicts
None
Replaces
None
README
Passkeys for Laravel
A native WebAuthn / FIDO2 passkey relying party for Laravel: register passkeys and sign users in with them (ES256, RS256 and EdDSA), with no third-party crypto dependencies. It ships actions, a model, a challenge store and events, and your application wires its own endpoints on top.
Installation
Requires PHP 8.4 (ext-json; ext-sodium for EdDSA keys) and Laravel 12 or 13.
composer require roundly-consulting/passkeys-for-laravel
php artisan vendor:publish --tag="passkeys-migrations"
php artisan migrate
Set PASSKEYS_ORIGINS (e.g. https://example.com): no ceremony runs until at least one origin is
allowed. If your users have UUID/ULID keys, set PASSKEYS_KEY_TYPE before migrating.
Usage
Give your user model the contract and an opaque user-handle column:
use RoundlyConsulting\Passkeys\Concerns\InteractsWithPasskeys; use RoundlyConsulting\Passkeys\Contracts\HasPasskeys; final class User extends Authenticatable implements HasPasskeys { use InteractsWithPasskeys; } // in a migration Schema::table('users', fn (Blueprint $table) => $table->passkeyUserHandle());
Register a passkey: send the options to navigator.credentials.create(), then verify the response:
use RoundlyConsulting\Passkeys\DataTransferObjects\RegistrationResponseData; use RoundlyConsulting\Passkeys\Facades\Passkeys; return response()->json(Passkeys::for($user)->registrationOptions()); $passkey = Passkeys::for($user)->register( RegistrationResponseData::fromArray($request->all()), name: 'MacBook Touch ID', );
Sign in without a username: send the options to navigator.credentials.get(), then verify:
use RoundlyConsulting\Passkeys\DataTransferObjects\AuthenticationResponseData; return response()->json(Passkeys::authenticationOptions()); $passkey = Passkeys::authenticate(AuthenticationResponseData::fromArray($request->all())); Auth::login($passkey->authenticatable);
Documentation
The full documentation — configuration, every feature and its API, and testing — lives on our website: roundly-consulting.com/open-source/docs/passkeys-for-laravel
Release notes are in CHANGELOG.md. To contribute, see the contributing guide.
Support our work
This package is free and open source, built and maintained by Roundly Consulting. If it saves you time, please consider supporting our open-source work — a one-time donation, a monthly pledge on Patreon or a crypto donation helps fund maintenance, new features and new packages.
License
The MIT License (MIT). See LICENSE.md. Copyright © Roundly Consulting.