Kind
Package, in-process. Routes under /oauth, five oauth_* tables
Protocol
OAuth2: auth code, PKCE, device, client credentials, personal tokens
Client
Any OAuth2 client; Bearer token in the Authorization header
Installed by
php artisan install:api --passport · HasApiTokens, OAuthenticatable
Voice
passport:keys · passport:client · passport:purge
Scales by
One row per token; passport:purge on a schedule keeps the tables lean
Range
Cloud: yes. Keys from env with PASSPORT_PRIVATE_KEY
Forge, VPS: yes. passport:keys once, keys kept out of git
Vapor: yes, with keys loaded from env variables