NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
Packagist · #3157 most downloaded on Packagist
JSON:API for Laravel applications.
Last release 2 months ago
12 Jul 2026
Release timing varies
gaps range from 2 weeks to 13 months
Nearly every release is documented
notes for 29 of 29 stable releases
Nothing withdrawn
no release was ever pulled
6 years old
39 releases · first in 2021
One column per quarter.
build: drop support for Laravel 11 by @lindyhopchris in #329
Full Changelog: v5.2.1...v5.3.0
fix: use explicit nullable types in HttpUnsupportedMediaTypeException by @isama92 in #327
Support for Laravel 13 by @aimeos in #326
Feature: add support for Laravel 12 by @lindyhopchris in #306
Full Changelog: v5.0.2...v5.1.0
composer up laravel-json-api/laravel
composer up laravel-json-api/laravelFull Changelog: v5.0.1...v5.0.2
composer up laravel-json-api/laravel
Although this is a major release with a breaking change (see below), the vast majority of applications should be able to upgrade without making any ch…
composer require laravel-json-api/laravel --no-update
composer require laravel-json-api/testing --dev --no-update
composer up "laravel-json-api/*" cloudcreativity/json-api-testingAlthough this is a major release with a breaking change (see below), the vast majority of applications should be able to upgrade without making any changes. You will only need to make a change if you're directly calling the
authorizeResource()method on a JSON:API HTTP request class.
bool or an Illuminate Auth Response.authorizeResource() method on both resource and query request classes has changed to bool|Response (where response is the Illuminate Auth response). If you are manually calling this method and relying on the return value being a boolean, this change is breaking. However, the vast majority of applications should be able to upgrade without any changes.Full Changelog: v4.1.1...v5.0.0
Fix: remove deprecation notices in PHP 8.4 by @lindyhopchris in #300
composer require laravel-json-api/laravel --no-update
composer require laravel-json-api/testing --dev --no-update
composer up "laravel-json-api/*" "cloudcreativity/json-api-testing"
Full Changelog: v4.1.0...v4.1.1
composer require laravel-json-api/laravel --no-update composer up " laravel-json-api/* "
composer require laravel-json-api/laravel --no-update
composer up "laravel-json-api/*"self link in related resource responses, and remove related link that should not exist. This has been incorrect for some time, but is definitely what the spec defines here.Full Changelog: v4.0.0...v4.1.0
composer require laravel-json-api/laravel:^4.0 --no-update composer require laravel-json-api/testing:^3.0 --dev --no-update composer up " cloudcreativ
composer require laravel-json-api/laravel:^4.0 --no-update
composer require laravel-json-api/testing:^3.0 --dev --no-update
composer up "cloudcreativity/*" "laravel-json-api/*"8.2.Full Changelog: v3.4.0...v4.0.0
### Added - #272 Added a model property type-hint to the resource stub and allowed it to be replaced via a model option on the command.
### Added - #265 Allow registration of middleware per action on both resource routes and relationship routes.
Exceptions converted to JSON:API errors when debug mode is on now include all previous exceptions.
core#12 Add ulid() method to the ID field class.
ulid() method to the ID field class.Upgraded to Laravel 10 and set minimum PHP version to 8.1.
8.1.laravel-json-api/cursor-pagination package, you now need to passed the schema's id field
to the paginator's make() method. I.e. use CursorPagination::make($this->id())Accept header for a "delete" resource request. Previously there was no checking of the Accept media
type, so anything could be sent. This is incorrect as the JSON:API specification shows the Accept header as
application/vnd.api+json for delete resource requests.New MultiPaginator that allows a schema to offer multiple different pagination strategies.
MultiPaginator that allows a schema to offer multiple different pagination strategies.fieldspagefilter### Fixed - #225 Fix validation of empty field list for a resource type in the fields query parameter, e.g. /api/v1/employees?fields[employees]=.
fields query parameter, e.g. /api/v1/employees?fields[employees]=.### Fixed - #223 Ensure Eloquent models always have fresh data after write operation. This is to prevent cached relationships from having "stale" data
Fixed PHP 8.2 deprecation messages in the laravel-json-api/validation dependency.
canEagerLoad() method.WhereNull and WhereNotNull filters.404 Not Found scenario).laravel-json-api/validation dependency.The JsonApiException class now has a context() method. Laravel's exception handler uses this to add log context when the exception is logged. This mea
JsonApiException class now has a context() method. Laravel's exception handler uses this to add log context
when the exception is logged. This means logging of JSON:API exceptions will now include the HTTP status code and the
JSON:API errors.406 Not Acceptable and 415 Unsupported Media Type messages to the following two new exception
classes:
Exceptions\HttpNotAcceptableExceptionExceptions\HttpUnsupportedMediaTypeExceptionAccept header with the media type
application/json is rejected with a 406 Not Acceptable response. Previously this media type worked, which is
incorrect as the JSON:API specification requires the media type application/vnd.api+json.null for a to-one relationship update.Added Spanish and Brazilian Portuguese translations for specification and validation error messages.
### Added - #181 The JsonApiController now extends the base Laravel controller. ### Fixed - #180 Add missing method to the Authorizer stub.
### Fixed - #175 Fix page URLs missing sparse field sets.
### Fixed - #178 Allow a resource id that is "0".
"0".### Added - #110 For requests that modify a relationship, it is now possible to get the model or models referenced in the request JSON using the toOne
toOne() or toMany() methods on the
resource request class.Number field can now be configured to
accept numeric strings by calling the acceptStrings() method on the field.Return types have been added to all internal methods in all child packages, to remove deprecation messages in PHP 8.1
readonly as a keyword. It was therefore necessary to rename the following interface
and trait:
LaravelJsonApi\Eloquent\Contracts\ReadOnly is now IsReadOnly.LaravelJsonApi\Eloquent\Fields\Concerns\ReadOnly is now IsReadOnly.Server class in an application:
LaravelJsonApi\Core\Support\AppResolver.$container property has been removed, and the $app property is now private. To access the
current application instance in your server class, use $this->app() instead.model() and modelOrFail() methods
on the ResourceQuery request class have been changed from public to protected. These were not documented for use
on this query class, and were only intended to be used publicly on the ResourceRequest class. Although technically
breaking, this change is unlikely to affect the vast majority of applications which should not be using the method.The default JSON:API resource class can now be changed via the LaravelJsonApi\Laravel\LaravelJsonApi::defaultResource() method. This should be set in
LaravelJsonApi\Laravel\LaravelJsonApi::defaultResource() method. This should be set in a service
provider's register() method.JsonApiResource class now has a
protected serializeRelation method that can be used to override the default serialization of relationships if
needed.self
routes will now include any non-standard links set on the resource relationship in the top-level links member.JsonApiResource now correctly handles conditional
fields when iterating over relationships to find a specific relation.self
route now handles a relationship not existing if it is hidden. Previously an exception was thrown when attempting to
merge relationship links into the document.self and related relationship links.The maximum PHP version is now 8.0. PHP 8.1 is not supported because it introduces a breaking change. The next major version of this package will add…
WhereHas and WhereDoesntHave filters.
Previously these were not iterating over the filters from the correct resource schema - they were iterating over the
filters from the schema to which the relationship belonged. They now correctly iterate over the filters from the
schema for the resource that is on the inverse side of the relationship.Although included in the 1.0 release, this feature is not considered production-ready. This is because we plan to make breaking changes to it, which w…
Has, WhereHas, WhereDoesntHave. Refer to
the filter documentation for details.canCount() method on a relationship. Refer to
the Countable relationships chapter in the
documentation for more details.1.x release cycle. If you are already using our cursor implementation, you can migrate in two easy steps:
composer require laravel-json-api/cursor-paginationLaravelJsonApi\Eloquent\Pagination\CursorPagination to LaravelJsonApi\CursorPagination\CursorPagination.The authorizer now has separate showRelated() and showRelationship() methods. Previously both these controller actions were authorized via the single
showRelated() and showRelationship() methods. Previously both these controller
actions were authorized via the single showRelationship() method. Adding the new showRelated method means
developers can now implement separate authorization logic for these two actions if desired. Our default implementation
remains unchanged - both are authorized using the view<RelationshipName> method on the relevant policy.isCreatingOrUpdating() helper method to determine whether the request is to create or
updated a resource.meta member.extractUsing() callback. This receives the model, column name and value. This is useful if the developer
needs to control the serialization of a few fields on their schema. However, the recommendation is to use a resource
class for complete control over the serialization of a model to a JSON:API resource.8.30. This change was required to use the $stopOnFirstFailure property on Laravel's
FormRequest class.LaravelJsonApi\Spec\UnexpectedDocumentException which was thrown if there was a failure when decoding
request JSON content before parsing it for compliance with the JSON:API specification. A JsonApiException will now
be thrown instead.201 Created response.### Fixed - #76 Pagination links will now be correctly added to related resources and relationship identifiers responses.
Eloquent schemas now support a default sort order via the $defaultSort property.
sortables() method.$defaultSort property.jsonapi:sort-field to create a custom sort field class.PostQuery and PostCollectionQuery) via the $defaultIncludePaths property. These include
paths are used if the client does not provide any include paths.BREAKING Eloquent attributes now support serializing and filling column values on related objects. This is primarily intended for use with the Eloquen
fill() method on Eloquent fields has
been updated to receive all the validated data as its third argument. This change was made to allow fields to work out
the value to fill into the model based on other JSON:API field values. If you have written any custom fields, you will
need to update the fill() method on your field class.belongsTo, hasOne, hasOneThrough and morphOne relationships that
have a withDefault() method. As part of this change, the mustExist() method was added to the Fillable interface.
If you have written any custom fields, you will need to add this method to your field class - it should return true
if the attribute needs to be filled after the primary model has been persisted.include, sort and
withCount query parameters.There is now a Core\Reponses\RelatedResponse class for returning the result for a related resources endpoint. For example, the /api/v1/posts/1/comment
withCount query parameter. For Eloquent
resources, this allows a client to request the relationship count for the primary data's relationships. Refer to
documentation for implementation details.ID field needs to implement the LaravelJsonApi\Contracts\Schema\IdEncoder interface for this to work.laravel-json-api/hashids package and using the HashId field instead of the standard Eloquent ID field. Refer to
documentation for details.laravel-json-api/non-eloquent package. Refer to documentation for implementation details.Core\Reponses\RelatedResponse class for returning the result for a related resources endpoint. For
example, the /api/v1/posts/1/comments endpoint. Previously the DataResponse class was used. While this class can
still be used, the new RelatedResponse class merges relationship meta into the top-level meta member of the
response document. For to-many relationships that are countable, this will mean the top-level meta member will
contain the count of the relationship.--non-eloquent option to generate a schema for a non-Eloquent
resource.LaravelJsonApi::registerQuery(), LaravelJsonApi::registerCollectionQuery() and
LaravelJsonApi::registerRequest() methods must now be used to register custom HTTP request classes for specified
resource types. Previously methods could be called on the RequestResolver classes, but these have now been removed.Multi-resource models are now supported. This allows developers to represent a single model class as multiple different JSON:API resource types within
MorphToMany relation field can now be used to add
polymorphic to-many relations to a schema. Refer to documentation for details.serving() method.RequestResolver::registerRequest(),
RequestResolver::registerQuery() and RequestResolver::registerCollectionQuery() static methods.The Relation::inverseType() method is deprecated and will be removed in 1.0-stable. Use Relation::type() instead.
jsonapi:authorizer generator command.indexQuery and relatableQuery methods. These allow filtering for authorization
purposes when a list of resources is being retrieved. For instance, it could filter those queries so that only models
belonging to the authenticated user are returned.searching, reading, saving, creating,
updating, deleting, readingRelated<Name>, reading<Name>, updating<Name>, attaching<Name> and
detaching<Name>.Server
classes.MetaResponse class that can be used
when returning meta-only responses. In addition, response classes have been updated to add a withServer method. This
can be used to specify the named server the response should use to encode the JSON:API document. This has to be used
when returning responses from routes that have not run the JSON:API middleware (i.e. there is no default server
available via the service container).resources, relationships and actions callbacks as the second function argument.Schema::isSingular() method.tags but the client sends posts, the
request will be rejected with an error message that posts are not supported.index and store methods on the
authorizer contract now receive the model class as their second argument. This is useful for authorizers that are used
for multiple resource types.using() must be replaced
with withRequest(). This change was made to make it clearer that the request class can be passed into query
builders.Relation::type() method must now be used when
setting the inverse resource type for the relation.fields query parameter to field set
value objects.Content-Type
header.Relation::inverseType() method is deprecated and will be removed in 1.0-stable. Use Relation::type()
instead.The JsonApiController now has the Laravel AuthorizesRequests, DispatchesJobs and ValidatesRequests traits applied.
actions() helper method when registering resources. See the PR for examples.JsonApiController now has the Laravel AuthorizesRequests, DispatchesJobs and ValidatesRequests traits
applied.when() and mergeWhen() method
should be used to add conditional relationships.$with property.existingAttributes() and existingRelationships() methods on the resource request class has been removed.
If you need to modify the existing values before the client values are merged, implement the withExisting()
method instead. This receives the model and its JSON representation (as an array).mustValidate() method must now be called on a schema relationship field. (Previously this was on the
resource relation.) By default, belongs-to and morph-to relations will be included when extracting existing
values; all other relations will not. Use the mustValidate() or notValidated() method on the schema relation
to alter whether a relation is included in the extracted values.Resource classes now support using conditional attributes in their meta() method.
hidden and serializeUsing methods to customise the serialization of models by the schema.meta() method.ArrayList and ArrayHash have been added, to distinguish between PHP zero-indexed arrays that
serialize to JSON arrays (ArrayList) and PHP associative arrays that serialize to JSON objects (ArrayHash). The
distinction is required because an empty array list can be serialized to [] in JSON whereas an empty associative
array must be serialized to null in JSON.attributes(), relationships(),
meta(), and links() methods have been changed so that they receive the HTTP request as the first (and only)
parameter. This brings the implementation in line with Laravel's Eloquent resources, which receive the request to
their toArray() method. The slight difference is our implementation allows the request to be null - this is to
cover encoding resources outside of HTTP requests, e.g. queued broadcasting. When upgrading, you will need to either
delete resource classes (as they are now optional), or update the method signatures on any classes you are retaining.v1 server after
adding this package to their Laravel application.Arr schema field has been removed - use the new ArrayList or ArrayHash
fields instead.uri method on resource and relationship routes has been removed:
$uriType property).withUriFieldName method).Initial release.
Initial release.
Your coding agent can read these notes before it upgrades. Set up the MCP server →