A FIELD GUIDE TO LARAVEL · VOLUME II · THE ECOSYSTEM
ENTRY II.11 · AUTHENTICATION
Passport
Laravel\Passport · Package · first recorded 16 August 2016, v0.1.0 on Packagist; with Laravel 5.3
A full OAuth2 server for a Laravel app, on the League OAuth2 server. Third parties register a client, your users approve scopes, and signed access tokens guard the API. For plain API tokens, Sanctum is the simpler choice.
Specification
Kind Package, in-process. Routes under /oauth, five oauth_* tables
Protocol OAuth2: auth code, PKCE, device, client credentials, personal tokens
Client Any OAuth2 client; Bearer token in the Authorization header
Installed by php artisan install:api --passport · HasApiTokens, OAuthenticatable
Voice passport:keys · passport:client · passport:purge
Scales by One row per token; passport:purge on a schedule keeps the tables lean
Range Cloud: yes. Keys from env with PASSPORT_PRIVATE_KEY
Forge, VPS: yes. passport:keys once, keys kept out of git
Vapor: yes, with keys loaded from env variables
Neighbours
Sanctum issues API tokens and SPA cookies without OAuth2, and the Passport docs send you there unless you must support OAuth2. Socialite runs the other way: your app signing in with someone else's OAuth server. Passport is for when other people's apps need tokens to yours.
Field marks
config/passport.php
storage/oauth-private.key
'driver' => 'passport' in auth.php
Laravel\Passport\HasApiTokens
Fig. II.11.1 · the authorization code grant, exploded
Parts
1 Client. Registered with passport:client or ClientRepository. A UUID id, a secret, and the redirect URIs it may use.
2 Authorize. /oauth/authorize shows your view of the scopes asked for. prompt=none|consent|login steers the screen.
3 Token. The code goes back to /oauth/token with the secret, or a PKCE verifier. Out come access and refresh tokens.
4 Keys. storage/oauth-private.key signs every access token; passport:keys makes them, env can carry them instead.
5 Tables. oauth_clients, oauth_access_tokens, refresh tokens, auth codes, device codes. passport:purge prunes them.
6 Guard. auth:api with the passport driver reads the Bearer header; CheckToken::using('orders:read') checks scopes.
Hidden joinery
Access tokens live a year unless tokensExpireIn says otherwise, and the expiry rides inside the signed token: the expires_at columns are display only. Password and implicit grants remain but are no longer recommended. A client credentials token's sub is the client UUID, so it cannot collide with a user's integer id.
Every line checked on 2026-10-08 against the 13.x docs, the laravel/passport source and Packagist.
TITLE
Passport · the OAuth2 grant
SOURCES
laravel.com/docs/13.x/passport · github.com/laravel/passport · packagist.org/packages/laravel/passport · packagist.org/packages/laravel/framework · laravel.com/docs/13.x/sanctum · laravel.com/docs/13.x/socialite
STATUS
Verified · 2026-10-08
SHEET
II.11 of 48
REV
A · 2026-10-08
DRAWN
BS
FINISH
All faces, including the back