laravel/fortify
Backend controllers and scaffolding for Laravel authentication.
v1.38.0
58M downloads/mo
#293 most downloaded on Packagist
laravel/fortify
What this package is like to depend on
Last release 16 days ago
07 Aug 2026
Ships fairly regularly
a new release about every 4 weeks
Nearly every release is documented
notes for 112 of 113 stable releases
Nothing withdrawn
no release was ever pulled
6 years old
113 releases · first in 2020
19 releases in the last 12 months
see the full history below
Release timeline
113 releases · Aug 2020 to Aug 2026Releases
latest 60 of 113-
v1.38.007 Aug 2026Release notes
Open source →- Bump actions/checkout from 7.0.0 to 7.0.1 in the github-actions group by @dependabot[bot] in #690
- [1.x] Supports PHPStan 2 by @crynobone in #691
- Add option to override RecoveryCode class by @TobiasNagel01 in #694
Release notes
Open source →- Bump actions/checkout from 7.0.0 to 7.0.1 in the github-actions group by @dependabot[bot] in https://github.com/laravel/fortify/pull/690
- [1.x] Supports PHPStan 2 by @crynobone in https://github.com/laravel/fortify/pull/691
- Add option to override RecoveryCode class by @TobiasNagel01 in https://github.com/laravel/fortify/pull/694
-
v1.37.329 Jun 2026Release notes
Open source →- Add Dependabot cooldown of 5 days by @nunomaduro in #679
- Enable Dependabot auto-merge by @nunomaduro in #680
- Bump actions/checkout from 6.0.2 to 6.0.3 in the github-actions group by @dependabot[bot] in #681
- Bump shivammathur/setup-php from 2.37.1 to 2.37.2 in the github-actions group by @dependabot[bot] in #684
- Bump actions/checkout from 6.0.3 to 7.0.0 in the github-actions group by @dependabot[bot] in #686
- [1.x] Use literal status code in LockoutResponse to fix PHPStan analysis by @jklejczyk in #688
- [1.x] Respect lowercase_usernames config when resetting password by @jklejczyk in #687
Release notes
Open source →- Add Dependabot cooldown of 5 days by @nunomaduro in https://github.com/laravel/fortify/pull/679
- Enable Dependabot auto-merge by @nunomaduro in https://github.com/laravel/fortify/pull/680
- Bump actions/checkout from 6.0.2 to 6.0.3 in the github-actions group by @dependabot[bot] in https://github.com/laravel/fortify/pull/681
- Bump shivammathur/setup-php from 2.37.1 to 2.37.2 in the github-actions group by @dependabot[bot] in https://github.com/laravel/fortify/pull/684
- Bump actions/checkout from 6.0.3 to 7.0.0 in the github-actions group by @dependabot[bot] in https://github.com/laravel/fortify/pull/686
- [1.x] Use literal status code in LockoutResponse to fix PHPStan analysis by @jklejczyk in https://github.com/laravel/fortify/pull/688
- [1.x] Respect lowercase_usernames config when resetting password by @jklejczyk in https://github.com/laravel/fortify/pull/687
-
v1.37.215 May 2026Release notes
Open source →What's Changed
- [1.x] Fix passkey password confirmation defaults by @benbjurstrom in #678
Full Changelog: v1.37.1...v1.37.2
Release notes
Open source →What's Changed
- [1.x] Fix passkey password confirmation defaults by @benbjurstrom in https://github.com/laravel/fortify/pull/678
Full Changelog: https://github.com/laravel/fortify/compare/v1.37.1...v1.37.2
-
v1.37.115 May 2026Release notes
Open source →What's Changed
- [1.x] Bump actions/checkout from v4 to v6 by @mon4ssi in #673
- Pin GitHub Actions to commit SHAs and add Dependabot config by @joetannenbaum in #674
- [1.x] update passkeys and set passkeys management middleware by @benbjurstrom in #676
- Bump shivammathur/setup-php from 2.37.0 to 2.37.1 in the github-actions group by @dependabot[bot] in #677
New Contributors
- @mon4ssi made their first contribution in #673
- @joetannenbaum made their first contribution in #674
- @dependabot[bot] made their first contribution in #677
Full Changelog: v1.37.0...v1.37.1
Release notes
Open source →What's Changed
- [1.x] Bump actions/checkout from v4 to v6 by @mon4ssi in https://github.com/laravel/fortify/pull/673
- Pin GitHub Actions to commit SHAs and add Dependabot config by @joetannenbaum in https://github.com/laravel/fortify/pull/674
- [1.x] update passkeys and set passkeys management middleware by @benbjurstrom in https://github.com/laravel/fortify/pull/676
- Bump shivammathur/setup-php from 2.37.0 to 2.37.1 in the github-actions group by @dependabot[bot] in https://github.com/laravel/fortify/pull/677
New Contributors
- @mon4ssi made their first contribution in https://github.com/laravel/fortify/pull/673
- @joetannenbaum made their first contribution in https://github.com/laravel/fortify/pull/674
- @dependabot[bot] made their first contribution in https://github.com/laravel/fortify/pull/677
Full Changelog: https://github.com/laravel/fortify/compare/v1.37.0...v1.37.1
-
v1.37.028 Apr 2026Release notes
Open source →- Drop support for PHP 8.1 and Laravel 10 by @benbjurstrom in #669
- Fix incompatibility between Laravel Fortify and
FormRequest::failOnUnknownFields()by @crynobone in #670 - Feat/add passkeys by @benbjurstrom in #668
Release notes
Open source →- Drop support for PHP 8.1 and Laravel 10 by @benbjurstrom in https://github.com/laravel/fortify/pull/669
- Fix incompatibility between Laravel Fortify and
FormRequest::failOnUnknownFields()by @crynobone in https://github.com/laravel/fortify/pull/670 - Feat/add passkeys by @benbjurstrom in https://github.com/laravel/fortify/pull/668
-
v1.36.220 Mar 2026Release notes
Open source →- Rewrite Fortify core guidelines and skill descriptions in imperative style by @pushpak1300 in #662
- Update reference from Jetstream to Starter Kits by @MrPunyapal in #663
Release notes
Open source →- Rewrite Fortify core guidelines and skill descriptions in imperative style by @pushpak1300 in https://github.com/laravel/fortify/pull/662
- Update reference from Jetstream to Starter Kits by @MrPunyapal in https://github.com/laravel/fortify/pull/663
-
v1.36.110 Mar 2026Release notes
Open source →- [1.x] Makes imports consistent by @nunomaduro in https://github.com/laravel/fortify/pull/659
-
v1.36.027 Feb 2026Release notes
Open source →- Rename Skill by @pushpak1300 in https://github.com/laravel/fortify/pull/657
-
v1.35.024 Feb 2026Release notes
Open source →- Add @throws annotation to create() docblock by @mohammadRezaei1380 in #634
- Add @throws annotation to function() docblock by @mohammadRezaei1380 in #635
- Use scoped bindings for Octane compatibility by @vrodriguero in #637
- Clarify Two-Factor Authentication database column requirements by @mohammadRezaei1380 in #638
- add @throws \Illuminate\Validation\ValidationException to functions() in Http\Responses by @mohammadRezaei1380 in #639
- Clarify Sanctum usage in SPA authentication setup by @mohammadRezaei1380 in #641
- Clarify Two-Factor Authentication JSON responses for SPA mode by @mohammadRezaei1380 in #640
- Clarify required guard for SPA authentication setup by @mohammadRezaei1380 in #643
- add @throws in function UpdateUserProfileInformation.php by @mohammadRezaei1380 in #644
- Update @return type of toResponse() to mixed for accuracy by @mohammadRezaei1380 in #645
- add @throws ValidationException function in AttemptToAuthenticate.php by @mohammadRezaei1380 in #646
- Fix docblock for index() to reflect array or JsonResponse return type by @mohammadRezaei1380 in #650
- add @throws ValidationException function in ConfirmTwoFactorAuthentication.php by @mohammadRezaei1380 in #649
- Fix two-factor QR code controller return type by @mohammadRezaei1380 in #652
- Update docblock return type for email verification store method by @mohammadRezaei1380 in #654
Release notes
Open source →- Add @throws annotation to create() docblock by @mohammadRezaei1380 in https://github.com/laravel/fortify/pull/634
- Add @throws annotation to function() docblock by @mohammadRezaei1380 in https://github.com/laravel/fortify/pull/635
- Use scoped bindings for Octane compatibility by @vrodriguero in https://github.com/laravel/fortify/pull/637
- Clarify Two-Factor Authentication database column requirements by @mohammadRezaei1380 in https://github.com/laravel/fortify/pull/638
- add @throws \Illuminate\Validation\ValidationException to functions() in Http\Responses by @mohammadRezaei1380 in https://github.com/laravel/fortify/pull/639
- Clarify Sanctum usage in SPA authentication setup by @mohammadRezaei1380 in https://github.com/laravel/fortify/pull/641
- Clarify Two-Factor Authentication JSON responses for SPA mode by @mohammadRezaei1380 in https://github.com/laravel/fortify/pull/640
- Clarify required guard for SPA authentication setup by @mohammadRezaei1380 in https://github.com/laravel/fortify/pull/643
- add @throws in function UpdateUserProfileInformation.php by @mohammadRezaei1380 in https://github.com/laravel/fortify/pull/644
- Update @return type of toResponse() to mixed for accuracy by @mohammadRezaei1380 in https://github.com/laravel/fortify/pull/645
- add @throws ValidationException function in AttemptToAuthenticate.php by @mohammadRezaei1380 in https://github.com/laravel/fortify/pull/646
- Fix docblock for index() to reflect array or JsonResponse return type by @mohammadRezaei1380 in https://github.com/laravel/fortify/pull/650
- add @throws ValidationException function in ConfirmTwoFactorAuthentication.php by @mohammadRezaei1380 in https://github.com/laravel/fortify/pull/649
- Fix two-factor QR code controller return type by @mohammadRezaei1380 in https://github.com/laravel/fortify/pull/652
- Update docblock return type for email verification store method by @mohammadRezaei1380 in https://github.com/laravel/fortify/pull/654
-
v1.34.103 Feb 2026Release notes
Open source →- Supports Laravel 13 by @crynobone in https://github.com/laravel/fortify/pull/631
-
v1.34.026 Jan 2026Release notes
Open source →What's Changed
- [1.x] Add Skills support by @pushpak1300 in https://github.com/laravel/fortify/pull/630
Full Changelog: https://github.com/laravel/fortify/compare/v1.33.0...v1.34.0
-
v1.33.015 Dec 2025Release notes
Open source →- Added dedicated Request object to PasswordResetLinkController by @chrispage1 in https://github.com/laravel/fortify/pull/628
- Change callback parameter type to callable|string by @Propaganistas in https://github.com/laravel/fortify/pull/629
-
v1.32.121 Nov 2025Release notes
Open source →- [1.x] PHP 8.5 Compatibility by @crynobone in https://github.com/laravel/fortify/pull/621
-
v1.32.016 Nov 2025Release notes
Open source →- [1.x] Add
Features::canUpdatePasswords()method by @jrd-lewis in https://github.com/laravel/fortify/pull/617 - [1.x] chore: bump to pragmarx/google2fa v9 by @joostdebruijn in https://github.com/laravel/fortify/pull/619
- [1.x] Add
-
v1.31.307 Nov 2025Release notes
Open source →- Resolves issue #592 - RecoveryCodeReplaced event dispatched twice by @coolAlias in https://github.com/laravel/fortify/pull/616
-
v1.31.221 Oct 2025Release notes
Open source →- [1.x] Add Laravel Fortify guidelines for boost by @pushpak1300 in https://github.com/laravel/fortify/pull/614
-
v1.31.103 Oct 2025Release notes
Open source →- Breaking Change: Revert "Validate password is a string when confirming password" by @themsaid in https://github.com/laravel/fortify/pull/612
-
v1.31.030 Sep 2025Release notes
Open source →- [1.x] single indentation on multiline ternarys by @browner12 in https://github.com/laravel/fortify/pull/605
- Validate password is a string when confirming password by @devfrey in https://github.com/laravel/fortify/pull/606
- Fix conflicts with app factories, causing recursive definitions in IDE by @crynobone in https://github.com/laravel/fortify/pull/609
- Add
Fortify::encryptUsing()to allow customising the default encryption by @crynobone in https://github.com/laravel/fortify/pull/611 - Regenerate session on register by @valorin in https://github.com/laravel/fortify/pull/610
-
v1.30.029 Aug 2025Release notes
Open source →- [1.x] Add
InteractsWithTwoFactorStateTrait to handle 2FA state between requests by @pushpak1300 in https://github.com/laravel/fortify/pull/604
- [1.x] Add
-
v1.29.014 Aug 2025Release notes
Open source →- fix: add missing route name to
/user/two-factor-recovery-codesby @Barbapapazes in https://github.com/laravel/fortify/pull/602
- fix: add missing route name to
-
v1.28.022 Jul 2025Release notes
Open source →- feat() : make Fortify honour Model::encryptUsing to enable app key rotation by @sebestenyb in https://github.com/laravel/fortify/pull/601
-
v1.27.011 Jun 2025Release notes
Open source →- Allow
RedirectIfTwoFactorAuthenticatableto be resolved via the Container by @Junveloper in https://github.com/laravel/fortify/pull/599
- Allow
-
v1.26.005 Jun 2025Release notes
Open source →- Delete existing tokens when user updates password by @patrickomeara in https://github.com/laravel/fortify/pull/598
-
v1.25.426 Jan 2025Release notes
Open source →- Prevent empty username fields from being added to requests by @edvardsr in https://github.com/laravel/fortify/pull/590
- Supports Laravel 12 by @crynobone in https://github.com/laravel/fortify/pull/591
-
v1.25.317 Jan 2025Release notes
Open source →DisableTwoFactorAuthenticationshould always settwo_factor_confirmed_attonullwhen it has a value by @crynobone in https://github.com/laravel/fortify/pull/589
-
v1.25.210 Jan 2025Release notes
Open source →- [1.x] Use
retrieveByCredentials()on the User Provider instead of a hardcoded Eloquent query by @pascalbaljet in https://github.com/laravel/fortify/pull/582 - Changed migration of users table by @aronbeurskens in https://github.com/laravel/fortify/pull/586
- [1.x] Use
-
v1.25.127 Nov 2024Release notes
Open source →- Replace implicitly nullable parameters for PHP 8.4 by @JeppeKnockaert in https://github.com/laravel/fortify/pull/580
-
v1.25.021 Nov 2024Release notes
Open source →- Add Remember Me Functionality to Registered User Login by @cvairlis in https://github.com/laravel/fortify/pull/579
-
v1.24.512 Nov 2024Release notes
Open source →- [1.x] Supports PHP 8.4 by @crynobone in https://github.com/laravel/fortify/pull/576
-
v1.24.429 Oct 2024Release notes
Open source →- Rename
POSTroutes to avoid regression bugs by @cima-alfa in https://github.com/laravel/fortify/pull/574
- Rename
-
v1.24.318 Oct 2024Release notes
Open source →- Update logo to support dark/light theme by @milewski in https://github.com/laravel/fortify/pull/569
- Fix unnamed routes when views are disabled (with original code formatting) by @cima-alfa in https://github.com/laravel/fortify/pull/571
-
v1.24.216 Sep 2024Release notes
Open source →- Adding context length configuration for 2FA to ensure better security standards by @MattLoyeD in https://github.com/laravel/fortify/pull/568
-
v1.24.103 Sep 2024Release notes
Open source →- [1.x] Add
X-Retry-Afterto/user/confirm-password/statusresponse by @crynobone in https://github.com/laravel/fortify/pull/565
- [1.x] Add
-
v1.24.020 Aug 2024Release notes
Open source →- [1.x] Support case insensitive password resets by @mattmcdonald-uk in https://github.com/laravel/fortify/pull/562
- Dispatch RecoveryCodeReplaced Event by @stephenjude in https://github.com/laravel/fortify/pull/564
-
v1.23.002 Aug 2024Release notes
Open source →- Fire ValidTwoFactorAuthenticationCodeProvided Event when 2FA session is authenticated by @stefanzweifel in https://github.com/laravel/fortify/pull/559
-
v1.22.022 Jul 2024Release notes
Open source →- [1.x] Rehash password if required when user uses two factor by @gdebrauwer in https://github.com/laravel/fortify/pull/557
- [1.x] Add TwoFactorAuthenticationFailed event by @antergos98 in https://github.com/laravel/fortify/pull/558
-
v1.21.504 Jul 2024Release notes
Open source →- [1.x] Allow
redirect()->intended()responses to be resolved via the Container by @crynobone in https://github.com/laravel/fortify/pull/551
- [1.x] Allow
-
v1.21.427 Jun 2024Release notes
Open source →- [1.x] Use available
$nameproperty fromSessionGuardif the value exists by @crynobone in https://github.com/laravel/fortify/pull/553
- [1.x] Use available
-
v1.21.308 May 2024Release notes
Open source →- [1.x] Ensure logout route is authenticated by @timacdonald in https://github.com/laravel/fortify/pull/536
-
v1.21.225 Apr 2024Release notes
Open source →- [1.x] Bacon QR 3.0 support by @eshimischi in https://github.com/laravel/fortify/pull/534
-
v1.21.119 Mar 2024Release notes
Open source →- Specify return type array type by @santigarcor in https://github.com/laravel/fortify/pull/525
- [1.x] Make commands lazy by @timacdonald in https://github.com/laravel/fortify/pull/527
-
v1.21.008 Mar 2024Release notes
Open source →- [1.x] Adds
fortify:installArtisan command by @nunomaduro in https://github.com/laravel/fortify/pull/524
- [1.x] Adds
-
v1.20.108 Feb 2024Release notes
Open source →- Don't overwrite an already two factor secret unless force = true by @danmatthews in https://github.com/laravel/fortify/pull/518
- Use
Datefacade for storing the password confirmation timestamp by @chrisvanlier2005 in https://github.com/laravel/fortify/pull/520
-
v1.20.015 Jan 2024Release notes
Open source →- [1.x] Merges develop by @nunomaduro in https://github.com/laravel/fortify/pull/515
-
v1.19.111 Dec 2023Release notes
Open source →- Deprecate the password rule and use illuminate password rule by @ricklambrechts in https://github.com/laravel/fortify/pull/511
-
v1.19.027 Nov 2023Release notes
Open source →- Add new event by @taylorotwell in https://github.com/laravel/fortify/commit/2da721fead1f3bc18af983e4903c4e1df67177e7
-
v1.18.118 Oct 2023Release notes
Open source →- Fix paths in default config using nested arrays by @sebj54 in https://github.com/laravel/fortify/pull/501
-
v1.18.012 Sep 2023Release notes
Open source →- Added case-sensitivity option for usernames by @Radiergummi in https://github.com/laravel/fortify/pull/485
- Added response contract for email verification notification by @m-thalmann in https://github.com/laravel/fortify/pull/489
-
v1.17.604 Sep 2023Release notes
Open source →- Update logout to invalidate and regenerate session only if session is present (Issue #486) by @karmendra in https://github.com/laravel/fortify/pull/487
-
v1.17.502 Aug 2023Release notes
Open source →- [1.x] Laravel Pint fixes by @iruoy in https://github.com/laravel/fortify/pull/480
-
v1.17.418 Jun 2023Release notes
Open source →- Port security fixes to default login rate limiter by @staudenmeir in https://github.com/laravel/fortify/pull/473
-
v1.17.302 Jun 2023Release notes
Open source →- Fix contract implementation by @jessarcher in https://github.com/laravel/fortify/pull/472
-
v1.17.226 Apr 2023Release notes
Open source →- Revert "Add rate limiter for a registration" by @taylorotwell in https://github.com/laravel/fortify/pull/465
-
v1.17.119 Apr 2023Release notes
Open source →- Add rate limiter for a registration by @trbsi in https://github.com/laravel/fortify/pull/460
-
v1.17.017 Apr 2023Release notes
Open source →- Add ability to override routes with custom paths by @stephenglass in https://github.com/laravel/fortify/pull/458
-
v1.16.006 Jan 2023Release notes
Open source →Added
- Laravel v10 Support by @driesvints in https://github.com/laravel/fortify/pull/435
-
v1.15.003 Jan 2023Release notes
Open source →Changed
- Update PrepareAuthenticatedSession.php by @francoism90 in https://github.com/laravel/fortify/pull/434
- Uses PHP Native Type Declarations 🐘 by @nunomaduro in https://github.com/laravel/fortify/pull/421
Fixed
- Fix error while preparing PasswordResetResponse with views turned off by @leonkllr0 in https://github.com/laravel/fortify/pull/433
-
v1.14.109 Dec 2022Release notes
Open source →Changed
- Only fire event when actually updating the database to disable two factor authentication by @taylorotwell in https://github.com/laravel/fortify/commit/04b4b9c20e421c415d0427904a72e08a21bdec27
-
v1.14.023 Nov 2022Release notes
Open source →Added
- Add more Response contract bindings by @bdsumon4u in https://github.com/laravel/fortify/pull/425
-
v1.13.704 Nov 2022Release notes
Open source →Changed
- Update parameter order for hash_equals function in TwoFactorLoginRequest by @jayan-blutui in https://github.com/laravel/fortify/pull/422
Fixed
- Use
booleanrather thanfilledfor remember by @Codeatron5000 in https://github.com/laravel/fortify/pull/423