laravel-api-keys maintained by boone-studios
Description
Prefixed, hashed API keys with scope-to-permission mapping for multi-tenant Laravel APIs.
Author
Last update
2026/07/11 23:57
(dev-master)
License
Downloads
37
Tags
boone-studios/laravel-api-keys
Prefixed, hashed API keys with scope-to-permission mapping for multi-tenant Laravel APIs. Pairs naturally with boone-studios/laravel-scoped-roles via TokenPermissionResolver.
Features
- Brand-prefixed secrets (
app_live_…) with masked display prefixes - Hashed storage with prefix lookup +
Hash::check - Revocation and expiration support
- Scope → permission bridge for unified API + dashboard authorization
- Configurable tenant guard hook (e.g. block deleted organizations)
Requirements
- PHP 8.2+
- Laravel 12 or 13
boone-studios/laravel-scoped-roles(for token permission integration)
Installation
composer require boone-studios/laravel-scoped-roles boone-studios/laravel-api-keys
php artisan vendor:publish --tag=api-keys-config
php artisan vendor:publish --tag=api-keys-migrations
php artisan migrate
Quick start
- Implement
ResolvesScopePermissionson your scope enum (mapsread/write/admin→ permission strings). - Implement
ResolvesEnvironmentFromTokenPrefixif you support multiple environments. - Optionally implement
GuardsAuthenticatedTenantfor tenant availability checks. - Extend
BooneStudios\ApiKeys\Models\ApiKeyand add your tenant relation. - Register middleware:
auth.api_key.
License
MIT © Boone Studios, LLC