Skip to content

Custom Guards ​

Register custom authentication drivers (e.g., JWT, HMAC, LDAP) via auth()->extend():

php
// Register a custom guard
auth()->extend('jwt', fn() => new \App\Authentication\Guards\JwtGuard());

// Use it explicitly
if (auth()->guard('jwt')->check()) {
    $user = auth()->guard('jwt')->user();
}

Setting a Default Guard ​

You can set your custom guard as default in app/Config/Auth.php:

php
public string $defaultGuard = 'jwt';

Token Abilities & Scopes ​

When using token-based guards (such as Personal Access Tokens or API guards), you can inspect token permissions and scopes:

php
$user = auth()->user();

// Check if current token has permission
if ($user->tokenCan('reports:export')) {
    // Perform export
}

// Check abilities using fluent helper
if ($user->can('orders:write')) {
    // Process write
}

Revoking Tokens ​

php
// Revoke current request token
$user->currentAccessToken()->delete();

// Revoke all tokens for user
$user->tokens()->delete();

Released under the MIT License.