NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
Packagist · #2024 most downloaded on Packagist
Auth0 Laravel SDK. Straight-forward and tested methods for implementing authentication, and accessing Auth0's Management API endpoints.
Last release 2 months ago
31 Jul 2026
Release timing varies
gaps range from 3 weeks to 10 months
Some releases are documented
notes for 31 of the last 60 stable releases
Nothing withdrawn
no release was ever pulled
12 years old
83 releases · first in 2014
Removed the deprecated/ v6 to v7 compatibility shims
⚠️ This is a beta release. It moves the SDK onto auth0-php v9, which rewrites the Management API. The Authentication API is unchanged. Please consult the v7 to v8 Upgrade Guide before upgrading.
This release makes the Auth0 Laravel SDK compatible with auth0-php v9. The SDK wraps the Authentication API, which is unchanged in v9, so authentication flows require no changes. The changes are all in the Management API surface.
management() returns the base ManagementClient - Auth0::management() and $guard->management() return a v9 ManagementClient built from your existing guard configuration (domain, client_id, client_secret), with automatic client credentials token management and PSR-6 caching$management->users->list()), and built-in Pager<T> paginationmanagement() accepts an options array (timeout, maxRetries, additionalHeaders, and more), settable per call or as defaults under a management key in config/auth0.php (global or per-guard)The Authentication surface is completely unchanged. Login, logout, callback, and token handling work exactly as before.
The Management API usage has changed:
| Area | v7 | v8 |
|---|---|---|
| Sub-client access | ->users()->getAll() |
->users->list() |
| Request params | Associative arrays | Typed classes (ListUsersRequestParameters) |
| Responses | ResponseInterface + HttpResponse::decodeContent() |
Typed objects ($user->getEmail()) |
| Pagination | getResponsePaginator() |
foreach ($pager as $user) |
| Return type | ManagementInterface |
ManagementClient |
composer require auth0/login:8.0.0-beta.0use Auth0\Laravel\Facade\Auth0;
use Auth0\SDK\API\Management\Users\Requests\ListUsersRequestParameters;
$management = Auth0::management();
$users = $management->users->list(
new ListUsersRequestParameters(['perPage' => 25, 'page' => 0, 'includeTotals' => true])
);
foreach ($users as $user) {
echo $user->getEmail();
}auth0/auth0-php dependency from ^8.19 to ^9.0management() now returns the base ManagementClient instead of ManagementInterfacedeprecated/ v6 to v7 compatibility shimsThis is a beta release - we would love your feedback! Please open an issue if you encounter any problems or have suggestions.
One column per quarter.
Laravel 13 support #491 ( cosmastech )
Added
Fixed
Changed
Added
Fixed
Changed
Security fix: Resolve CVE-2026-34236
Fixed
Security fix: Resolve CVE-2025-68129
Fixed
Security fix: Resolve CVE-2025-58769
Fixed
feat: add macroable guards (#459) by erikn69
Security fix: Resolve CVE-2025-47275
Fixed
Laravel 12 Support #470 ( lee-to )
perf: Update getCredential to only refresh credential once per request #453 ( ComputerTinker )
Changed
Changed
refactor: add additional Telescope state check #447 ( samuelhgf )
Add support for Laravel 11 \#445 (evansims)
Added
Changed
Implement support for Back-Channel Logout \#435 (evansims)
Significant performance improvements by eliminating redundant user queries.
Added
AUTH0_SESSION_STORAGE and AUTH0_TRANSIENT_STORAGE now support a cookie value to enable the native Auth0-PHP SDK cookie session handler. See docs/Cookies.md for more information.Fixed
Changed
auth0_session entry in the Laravel session store, rather than in multiple keys.Documentation
Addressed an issue where, under certain circumstances, permissions state could be lost after authenticating.
Fixed
Organization Name support added for Authentication API and token handling ¹
Added
Changed
auth0-php dependency version range to ^8.7.laravel package name (previously laravel-auth0.)Fixed
AUTH0_ dotenv values could erroneously be interpreted as true configuration values.Note ¹ To use this feature, an Auth0 tenant must have support for it enabled. This feature is not yet available to all tenants.
Resolved an issue where, under certain circumstances, the AuthenticationGuard middleware could get erroneously added to the api middleware group, caus
Fixed
api middleware group, causing a session to be established in a stateless request. (#415)SDK configuration (config/auth0.php) now supports a configurationPath property for specifying a custom search path for .auth0.*.json and .env* files.
Resolved an issue where parsing .env files could sometimes throw an exception when handling non-key-value pair strings. (\#395)
Fixed
.env files could sometimes throw an exception when handling non-key-value pair strings. (#395)This release adds support for authenticating using [Pushed Authorization Requests](https://www.rfc-editor.org/rfc/rfc6749).
Added
This release adds support for authenticating using Pushed Authorization Requests.
This release introduces two new Authentication Guards which provide a streamlined integration experience for developers that need to simultaneously support both session-based authentication and token-based endpoint authorization in their Laravel applications.
| Guard | Class | Description |
|---|---|---|
auth0.authenticator |
Auth0\Laravel\Auth\Guards\AuthenticationGuard |
Session-based authentication. |
auth0.authorizer |
Auth0\Laravel\Auth\Guards\AuthorizationGuard |
Token-based authorization. |
These guards are compatible with Laravel's Authentication API and support the standard auth middleware.
These guards are compatible with Laravel's Authorization API and support the standard can middleware, and the Guard facade, and work with the Policies API.
3 new pre-built Guards are available: scope and permission, as well as a dynamic *:*. This enables you to verify whether the user's access token has a particular scope or (if RBAC is enabled on the Auth0 API) a particular permission. For example Gate::check('scope', 'email') or Route::get(/*...*/)->can('read:messages').
The SDK now automatically registers these guards to Laravel's standard web and api middleware groups, respectively. Manual Guard setup in config/auth.php is no longer necessary.
The SDK now automatically registers the Authentication routes. Manual route setup in routes/web.php is no longer necessary.
2 new routing Middleware have been added: Auth0\Laravel\Http\Middleware\AuthenticatorMiddleware and Auth0\Laravel\Http\Middleware\AuthorizerMiddleware. These are automatically registered with your Laravel application, and ensure the Auth0 Guards are used for authentication for web routes and authorization for api routes, respectively. This replaces the need for the guard middleware or otherwise manual Guard assignment in your routes.
Changed
We've introduced a new configuration syntax. This new syntax is more flexible and allows for more complex configuration scenarios, and introduces support for multiple guard instances. Developers using the previous syntax will have their existing configurations applied to all guards uniformly.
The SDK can now configure itself using a .auth0.json file in the project root directory. This file can be generated using the Auth0 CLI, and provides a significantly simpler configuration experience for developers.
The previous auth0.guard Guard (Auth0\Laravel\Auth\Guard) has been refactored as a lightweight wrapper around the new AuthenticationGuard and AuthorizationGuard guards.
Auth0\Laravel\Auth0 now has a management() shortcut method for issuing Management API calls. (\#376)
Added
Auth0\Laravel\Auth0 now has a management() shortcut method for issuing Management API calls. (#376)
Auth0\Laravel\Auth0\Guard now has a refreshUser() method for querying /userinfo endpoint and refreshing the authenticated user's cached profile data. (#375)
Auth0\Laravel\Http\Controller\Stateful\Login now raises a LoginAttempting event, offering an opportunity to customize the authorization parameters before the login redirect is issued. (#382)
Changed
tokenCache, managementTokenCache, sessionStorage and transientStorage configuration values now support false or string values pointing to class names (e.g. \Some\Cache::class) or class aliases (e.g. cache.psr6) registered with Laravel. (#381)Auth0\Laravel\Http\Middleware\Guard, new middleware that forces Laravel to route requests through a group using a specific Guard. (\#362)
Added
Auth0\Laravel\Http\Middleware\Guard, new middleware that forces Laravel to route requests through a group using a specific Guard. (#362)Changed
Auth0\Laravel\Http\Middleware\Stateful\Authenticate now remembers the intended route (using redirect()->setIntendedUrl()) before kicking off the authentication flow redirect. Users will be returned to the memorized intended route after completing their authentication flow. (#364)Fixed
$session, not $token (#353)Relaxed response types from middleware to use low-level Symfony\Component\HttpFoundation\Response class, allowing for broader and custom response type
Fixed
Symfony\Component\HttpFoundation\Response class, allowing for broader and custom response types.Resolved an issue wherein custom user repositories could fail to be instantiated under certain circumstances.
Fixed
As previous guidance had been to instantiate these using their class names, this should not be a breaking change in most cases. However, if you had us…
This release includes support for Laravel 10, and major improvements to the internal state handling mechanisms of the SDK.
Added
Auth0\Laravel\Traits\Imposter trait to allow for easier testing. Example usageChanged
The following changes have no effect on the external API of this package but may affect internal usage.
Guard will now more reliably detect changes in the underlying Auth0-PHP SDK session state.
Guard will now more reliably sync changes back to the underlying Auth0-PHP SDK session state.
StateInstance concept has been replaced by a new Credentials entity.
Guard updated to use new Credentials entity as primary internal storage for user data.
Auth0\Laravel\Traits\ActingAsAuth0User was updated to use new Credentials entity.
The HTTP middleware has been refactored to more clearly differentiate between token and session-based identities.
The authenticate, authenticate.optional and authorize.optional HTTP middleware now supports scope filtering, as authorize already did.
Upgraded test suite to use PEST 2.0 framework.
Updated test coverage to 100%.
Fixed
Guard would not always honor the provider configuration value in config/auth.php.Guard is no longer defined as a Singleton to better support applications that need multi-guard configurations.user() behaviorThis release includes a significant behavior change around the user() method of the Guard. Previously, by simply invoking the method, the SDK would search for any available credential (access token, device session, etc.) and automatically assign the user within the Guard. The HTTP middleware has been upgraded to handle the user assignment step, and user() now only returns the current state of the user assignment without altering it.
A new property has been added to the config/auth0.php configuration file: behavior. This is an array. At this time, there is a single option: legacyGuardUserMethod, a bool. If this value is set to true, or if the key is missing, the previously expected behavior will be applied, and user() will behave as it did before this release. The property defaults to false.
We identified an issue with using identical alias naming for both the Guard and Provider singletons under Laravel 10, which has required us to rename these aliases. As previous guidance had been to instantiate these using their class names, this should not be a breaking change in most cases. However, if you had used auth0 as the name for either the Guard or the Provider drivers, kindly note that these have changed. Please use auth0.guard for the Guard driver and auth0.provider for the Provider driver. This is a regrettable change but was necessary for adequate Laravel 10 support.
feat: Add Auth0\Laravel\Event\Middleware\... event hooks \#340
add: Raise additional Laravel Auth Events \#331
Restore php artisan vendor:publish command \#321
The SDK now requires ^3.0 of the psr/cache dependency, to accommodate breaking changes made in the upstream interface (typed parameters and return typ…
Fixed
Auth0\Laravel\Store\LaravelSession has been added as the default sessionStorage and transientStorage interfaces for the underlying Auth0-PHP SDK. The
Changed
Auth0\Laravel\Store\LaravelSession has been added as the default sessionStorage and transientStorage interfaces for the underlying Auth0-PHP SDK. The SDK now leverages the native Laravel Session APIs by default. #307¹Auth0\Laravel\Cache\LaravelCachePool and Auth0\Laravel\Cache\LaravelCacheItem have been added as the default tokenCache and managementTokenCache interfaces for the underlying Auth0-PHP SDK. The SDK now leverages the native Laravel Cache APIs by default. #307Auth0\Laravel\Auth\Guard now supports the viaRemember method. #306Auth0\Laravel\Http\Middleware\Stateless\Authorize now returns a 401 status instead of 403 for unauthenticated users. #304¹ This change may require your application's users to re-authenticate. You can avoid this by changing the sessionStorage and transientStorage options in your SDK configuration to their previous default instances of Auth0\SDK\Store\CookieStore, but it is recommended you migrate to the new LaravelSession default.
Return interfaces instead of concrete classes \#296
Fixed an issue in Auth0\Laravel\Http\Controller\Stateful\Callback where $errorDescription's value was assigned an incorrect value when an error was en
Fixed
Auth0\Laravel\Http\Controller\Stateful\Callback where $errorDescription's value was assigned an incorrect value when an error was encountered. #266As expected with a major release, Auth0 Laravel SDK v7 includes breaking changes. Please review the upgrade guide thoroughly to understand the changes…
Auth0 Laravel SDK v7 includes many significant changes over previous versions:
As expected with a major release, Auth0 Laravel SDK v7 includes breaking changes. Please review the upgrade guide thoroughly to understand the changes required to migrate your application to v7.
Auth0\Login to Auth0\LaravelChangelog entries for releases prior to 8.0 have been relocated to CHANGELOG.ARCHIVE.md.
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Your coding agent can read these notes before it upgrades. Set up the MCP server →