submtd/laravel-api-token

There is no license information available for the latest version (1.0.0009) of this package.

API authentication with short lived tokens

1.0.0009 2020-06-16 16:15 UTC

This package is auto-updated.

Last update: 2024-12-17 02:38:45 UTC


README

This package allows you to use short lived API tokens to protect endpoints.

Installation

First, pull the package in via composer.

composer require submtd/laravel-api-token

Second, run the database migrations.

php artisan migrate

Configuration

This package reads values from the .env file in order to control the length of the tokens and the expiration time.

// .env
API_TOKEN_LENGTH=128
API_REFRESH_LENGTH=256
API_TOKEN_EXPIRATION_MINUTES=1440
API_REFRESH_EXPIRATION_MINUTES=10080
API_USER_MODEL=\App\User

Endpoints

This package provides several endpoints to manage api tokens.

Public Endpoints

POST: /api/v1/token/login

This endpoint accepts email and password and returns a new API token.

POST: /api/v1/token/refresh

This endpoints accepts a refresh_token parameter and returns a refreshed API token.

Protected Endpoints

The following endpoints require a valid API token for access.

GET: /api/v1/token

This endpoint lists all user tokens.

GET: /api/v1/token/{uuid}

This endpoint shows a specific API token.

DELETE: /api/v1/token/{uuid}

This endpoint destroys a specific API token.

POST: /api/v1/token/create

This endpoint creates a new API token. An optional name parameter can be provided to name the token.