A FIELD GUIDE TO LARAVEL · VOLUME II · THE ECOSYSTEM
ENTRY II.21 · AUTHENTICATION
Fortify
Laravel\Fortify · Package · first recorded 31 August 2020, v0.0.1 on Packagist, with Laravel 8
A headless authentication backend: the routes and controllers for login, registration, password reset, verification, two-factor and passkeys, with every screen left to you. Blade, Inertia and a separate SPA post to the same routes.
Specification
Kind Package, in-process. Routes, controllers and actions; no views
Interface POST /login, /register, /forgot-password, /two-factor-challenge and kin
Client Your own frontend: Blade, Inertia, Livewire or a separate SPA
Installed by composer require laravel/fortify · fortify:install · migrate
Voice fortify:install · route:list to see them
Scales by Rate limiters per feature (login, two-factor, passkeys); features switched in config
Range Cloud: yes. Nothing resident
Forge, VPS: yes, the same way
Vapor: yes. Session and database only
Neighbours
The starter kits are Fortify with screens: every kit uses it for authentication. Sanctum authenticates requests, by token or SPA cookie, and the two are often used together. Breeze kept its own auth controllers in your app. Fortify's distinction is that it owns the routes and leaves every screen to you.
Field marks
config/fortify.php
FortifyServiceProvider.php
app/Actions/Fortify/
Features::twoFactorAuthentication()
Fig. II.21.1 · One login, exploded
Parts
1 Your view. Fortify::loginView(fn () => view('auth.login')). Fortify defines the GET route; you draw the form.
2 POST /login. Expects email or username, password, optional remember. XHR gets 200 or 422; a browser gets a redirect.
3 Pipeline. Throttle, canonicalise the username, redirect to 2FA if on, attempt, prepare the session. Swappable as a whole.
4 Actions. app/Actions/Fortify: CreateNewUser, ResetUserPassword and the password rules. Yours to edit after install.
5 Features. features in config/fortify.php: registration, reset, verification, two-factor, passkeys. Off means no route.
6 Home. On success, a redirect to home from config, or 200 for XHR. Bind LoginResponse for anything else.
Hidden joinery
Login throttling is per username and IP together, not IP alone, so one bad neighbour does not lock out an office. With views => false the GET routes vanish but password.reset must still be named, because the reset mail links to it. By default, changing two-factor settings asks for password confirmation first. Passkeys wrap laravel/passkeys.
Every claim checked on 2026-10-08 against the 13.x Fortify docs, the 1.x source and Packagist.
TITLE
Fortify · auth without a view
SOURCES
laravel.com/docs/13.x/fortify · laravel.com/docs/13.x/starter-kits · github.com/laravel/fortify/blob/1.x/stubs/fortify.php · github.com/laravel/fortify/blob/1.x/routes/routes.php · github.com/laravel/fortify/blob/1.x/src/FortifyServiceProvider.php · github.com/laravel/fortify/blob/1.x/src/LoginRateLimiter.php · github.com/laravel/fortify/blob/1.x/composer.json · repo.packagist.org/p2/laravel/fortify.json · github.com/laravel/breeze/tree/2.x/stubs/default/app/Http/Controllers/Auth · Monitor 710, 371
STATUS
Verified · 2026-10-08
SHEET
II.21 of 48
REV
A · 2026-10-08
DRAWN
BS
FINISH
All faces, including the back