A FIELD GUIDE TO LARAVEL · VOLUME II · THE ECOSYSTEM
ENTRY II.8 · OAUTH LOGIN
Socialite
Laravel\Socialite · Package · first recorded 24 August 2014, v1.0.0 on Packagist
OAuth login with a provider's account instead of a password. Two routes: one redirects to GitHub, Google or Slack, the other receives the callback and hands you a user with id, email and token to match against your own table.
Specification
Kind Package: two routes and a facade; no tables, no config file
Protocol OAuth 2.0; OAuth 1.0 for the older Twitter driver
Client Facebook, X, LinkedIn, Google, GitHub, GitLab, Bitbucket, Slack
Installed by composer require laravel/socialite
Voice none. No artisan commands of its own
Scales by One redirect and one callback per login; only the state is kept
Range Cloud: yes. The callback URL is set per environment
Forge, VPS: yes, the same two routes
Vapor: yes. Two HTTP requests; the state rides in Vapor's cookie session
Neighbours
Passport makes your app the OAuth2 server that other apps sign in to; Socialite makes it the client of someone else's. Sanctum issues your own tokens, and Fortify handles password login. Socialite only fetches the provider's user: matching it to your users table is your code.
Field marks
GITHUB_CLIENT_ID in .env
config/services.php => 'github'
Socialite::driver('...')
/auth/redirect, /auth/callback
Fig. II.8.1 · One login, two routes, exploded
Parts
1 Credentials. client_id, client_secret and redirect under the provider's key in config/services.php.
2 Redirect. Socialite::driver('github')->redirect() sends the browser to the provider with the scopes asked for.
3 Provider, GitHub here. The user signs in and consents there; your application never sees the password.
4 Callback. The provider returns a code to your second route; ->user() checks state, swaps it for token and profile.
5 User object. id, nickname, name, email, avatar, plus token, refreshToken and expiresIn for OAuth 2.
6 Your table. User::updateOrCreate(['github_id' => ...]) then Auth::login($user). Socialite stops at the handoff.
Hidden joinery
The state parameter is checked on the callback unless ->stateless() says the API has no session. A relative redirect is resolved to a full URL. scopes() merges with earlier calls, setScopes() replaces them. Slack issues a bot token via asBotUser(), then only token is filled. Socialite::fake() tests it offline.
Every line checked on 2026-10-08 against the 13.x docs, the laravel/socialite source and Packagist.
TITLE
Socialite · one login, two routes
SOURCES
laravel.com/docs/13.x/socialite · github.com/laravel/socialite · packagist.org/packages/laravel/socialite · laravel.com/docs/13.x/passport · laravel.com/docs/13.x/sanctum · laravel.com/docs/13.x/starter-kits · cloud.laravel.com/docs/environments · docs.vapor.build/projects/environments · laravel.com/docs/13.x/fortify
STATUS
Verified · 2026-10-08
SHEET
II.8 of 48
REV
A · 2026-10-08
DRAWN
BS
FINISH
All faces, including the back