PackageTrack
Sign in Get early access

laravel/fortify

Backend controllers and scaffolding for Laravel authentication.

v1.38.0 58M downloads/mo #293 most downloaded on Packagist laravel/fortify

What this package is like to depend on

Last release 16 days ago

07 Aug 2026

Ships fairly regularly

a new release about every 4 weeks

Nearly every release is documented

notes for 112 of 113 stable releases

Nothing withdrawn

no release was ever pulled

6 years old

113 releases · first in 2020

19 releases in the last 12 months

see the full history below

Release timeline

113 releases · Aug 2020 to Aug 2026
2021 2022 2023 2024 2025 2026
Release Pre-release

Releases

latest 60 of 113
  1. v1.38.0 07 Aug 2026
    Release notes
    Open source →
    Release notes
    • Bump actions/checkout from 7.0.0 to 7.0.1 in the github-actions group by @dependabot[bot] in https://github.com/laravel/fortify/pull/690
    • [1.x] Supports PHPStan 2 by @crynobone in https://github.com/laravel/fortify/pull/691
    • Add option to override RecoveryCode class by @TobiasNagel01 in https://github.com/laravel/fortify/pull/694
    Open source →
  2. v1.37.3 29 Jun 2026
    Release notes
    • Add Dependabot cooldown of 5 days by @nunomaduro in #679
    • Enable Dependabot auto-merge by @nunomaduro in #680
    • Bump actions/checkout from 6.0.2 to 6.0.3 in the github-actions group by @dependabot[bot] in #681
    • Bump shivammathur/setup-php from 2.37.1 to 2.37.2 in the github-actions group by @dependabot[bot] in #684
    • Bump actions/checkout from 6.0.3 to 7.0.0 in the github-actions group by @dependabot[bot] in #686
    • [1.x] Use literal status code in LockoutResponse to fix PHPStan analysis by @jklejczyk in #688
    • [1.x] Respect lowercase_usernames config when resetting password by @jklejczyk in #687
    Open source →
    Release notes
    • Add Dependabot cooldown of 5 days by @nunomaduro in https://github.com/laravel/fortify/pull/679
    • Enable Dependabot auto-merge by @nunomaduro in https://github.com/laravel/fortify/pull/680
    • Bump actions/checkout from 6.0.2 to 6.0.3 in the github-actions group by @dependabot[bot] in https://github.com/laravel/fortify/pull/681
    • Bump shivammathur/setup-php from 2.37.1 to 2.37.2 in the github-actions group by @dependabot[bot] in https://github.com/laravel/fortify/pull/684
    • Bump actions/checkout from 6.0.3 to 7.0.0 in the github-actions group by @dependabot[bot] in https://github.com/laravel/fortify/pull/686
    • [1.x] Use literal status code in LockoutResponse to fix PHPStan analysis by @jklejczyk in https://github.com/laravel/fortify/pull/688
    • [1.x] Respect lowercase_usernames config when resetting password by @jklejczyk in https://github.com/laravel/fortify/pull/687
    Open source →
  3. v1.37.2 15 May 2026
    Release notes

    What's Changed

    Full Changelog: v1.37.1...v1.37.2

    Open source →
    Release notes

    What's Changed

    • [1.x] Fix passkey password confirmation defaults by @benbjurstrom in https://github.com/laravel/fortify/pull/678

    Full Changelog: https://github.com/laravel/fortify/compare/v1.37.1...v1.37.2

    Open source →
  4. v1.37.1 15 May 2026
    Release notes

    What's Changed

    • [1.x] Bump actions/checkout from v4 to v6 by @mon4ssi in #673
    • Pin GitHub Actions to commit SHAs and add Dependabot config by @joetannenbaum in #674
    • [1.x] update passkeys and set passkeys management middleware by @benbjurstrom in #676
    • Bump shivammathur/setup-php from 2.37.0 to 2.37.1 in the github-actions group by @dependabot[bot] in #677

    New Contributors

    Full Changelog: v1.37.0...v1.37.1

    Open source →
    Release notes

    What's Changed

    • [1.x] Bump actions/checkout from v4 to v6 by @mon4ssi in https://github.com/laravel/fortify/pull/673
    • Pin GitHub Actions to commit SHAs and add Dependabot config by @joetannenbaum in https://github.com/laravel/fortify/pull/674
    • [1.x] update passkeys and set passkeys management middleware by @benbjurstrom in https://github.com/laravel/fortify/pull/676
    • Bump shivammathur/setup-php from 2.37.0 to 2.37.1 in the github-actions group by @dependabot[bot] in https://github.com/laravel/fortify/pull/677

    New Contributors

    • @mon4ssi made their first contribution in https://github.com/laravel/fortify/pull/673
    • @joetannenbaum made their first contribution in https://github.com/laravel/fortify/pull/674
    • @dependabot[bot] made their first contribution in https://github.com/laravel/fortify/pull/677

    Full Changelog: https://github.com/laravel/fortify/compare/v1.37.0...v1.37.1

    Open source →
  5. v1.37.0 28 Apr 2026
    Release notes
    Open source →
    Release notes
    • Drop support for PHP 8.1 and Laravel 10 by @benbjurstrom in https://github.com/laravel/fortify/pull/669
    • Fix incompatibility between Laravel Fortify and FormRequest::failOnUnknownFields() by @crynobone in https://github.com/laravel/fortify/pull/670
    • Feat/add passkeys by @benbjurstrom in https://github.com/laravel/fortify/pull/668
    Open source →
  6. v1.36.2 20 Mar 2026
    Release notes
    • Rewrite Fortify core guidelines and skill descriptions in imperative style by @pushpak1300 in #662
    • Update reference from Jetstream to Starter Kits by @MrPunyapal in #663
    Open source →
    Release notes
    • Rewrite Fortify core guidelines and skill descriptions in imperative style by @pushpak1300 in https://github.com/laravel/fortify/pull/662
    • Update reference from Jetstream to Starter Kits by @MrPunyapal in https://github.com/laravel/fortify/pull/663
    Open source →
  7. v1.36.1 10 Mar 2026
    Release notes
    Open source →
    Release notes
    • [1.x] Makes imports consistent by @nunomaduro in https://github.com/laravel/fortify/pull/659
    Open source →
  8. v1.36.0 27 Feb 2026
    Release notes
    Open source →
    Release notes
    • Rename Skill by @pushpak1300 in https://github.com/laravel/fortify/pull/657
    Open source →
  9. v1.35.0 24 Feb 2026
    Release notes
    Open source →
    Release notes
    • Add @throws annotation to create() docblock by @mohammadRezaei1380 in https://github.com/laravel/fortify/pull/634
    • Add @throws annotation to function() docblock by @mohammadRezaei1380 in https://github.com/laravel/fortify/pull/635
    • Use scoped bindings for Octane compatibility by @vrodriguero in https://github.com/laravel/fortify/pull/637
    • Clarify Two-Factor Authentication database column requirements by @mohammadRezaei1380 in https://github.com/laravel/fortify/pull/638
    • add @throws \Illuminate\Validation\ValidationException to functions() in Http\Responses by @mohammadRezaei1380 in https://github.com/laravel/fortify/pull/639
    • Clarify Sanctum usage in SPA authentication setup by @mohammadRezaei1380 in https://github.com/laravel/fortify/pull/641
    • Clarify Two-Factor Authentication JSON responses for SPA mode by @mohammadRezaei1380 in https://github.com/laravel/fortify/pull/640
    • Clarify required guard for SPA authentication setup by @mohammadRezaei1380 in https://github.com/laravel/fortify/pull/643
    • add @throws in function UpdateUserProfileInformation.php by @mohammadRezaei1380 in https://github.com/laravel/fortify/pull/644
    • Update @return type of toResponse() to mixed for accuracy by @mohammadRezaei1380 in https://github.com/laravel/fortify/pull/645
    • add @throws ValidationException function in AttemptToAuthenticate.php by @mohammadRezaei1380 in https://github.com/laravel/fortify/pull/646
    • Fix docblock for index() to reflect array or JsonResponse return type by @mohammadRezaei1380 in https://github.com/laravel/fortify/pull/650
    • add @throws ValidationException function in ConfirmTwoFactorAuthentication.php by @mohammadRezaei1380 in https://github.com/laravel/fortify/pull/649
    • Fix two-factor QR code controller return type by @mohammadRezaei1380 in https://github.com/laravel/fortify/pull/652
    • Update docblock return type for email verification store method by @mohammadRezaei1380 in https://github.com/laravel/fortify/pull/654
    Open source →
  10. v1.34.1 03 Feb 2026
    Release notes
    Open source →
    Release notes
    • Supports Laravel 13 by @crynobone in https://github.com/laravel/fortify/pull/631
    Open source →
  11. v1.34.0 26 Jan 2026
    Release notes

    What's Changed

    • [1.x] Add Skills support by @pushpak1300 in https://github.com/laravel/fortify/pull/630

    Full Changelog: https://github.com/laravel/fortify/compare/v1.33.0...v1.34.0

    Open source →
  12. v1.33.0 15 Dec 2025
    Release notes
    • Added dedicated Request object to PasswordResetLinkController by @chrispage1 in https://github.com/laravel/fortify/pull/628
    • Change callback parameter type to callable|string by @Propaganistas in https://github.com/laravel/fortify/pull/629
    Open source →
  13. v1.32.1 21 Nov 2025
    Release notes
    • [1.x] PHP 8.5 Compatibility by @crynobone in https://github.com/laravel/fortify/pull/621
    Open source →
  14. v1.32.0 16 Nov 2025
    Release notes
    • [1.x] Add Features::canUpdatePasswords() method by @jrd-lewis in https://github.com/laravel/fortify/pull/617
    • [1.x] chore: bump to pragmarx/google2fa v9 by @joostdebruijn in https://github.com/laravel/fortify/pull/619
    Open source →
  15. v1.31.3 07 Nov 2025
    Release notes
    • Resolves issue #592 - RecoveryCodeReplaced event dispatched twice by @coolAlias in https://github.com/laravel/fortify/pull/616
    Open source →
  16. v1.31.2 21 Oct 2025
    Release notes
    • [1.x] Add Laravel Fortify guidelines for boost by @pushpak1300 in https://github.com/laravel/fortify/pull/614
    Open source →
  17. v1.31.1 03 Oct 2025
    Release notes
    • Breaking Change: Revert "Validate password is a string when confirming password" by @themsaid in https://github.com/laravel/fortify/pull/612
    Open source →
  18. v1.31.0 30 Sep 2025
    Release notes
    • [1.x] single indentation on multiline ternarys by @browner12 in https://github.com/laravel/fortify/pull/605
    • Validate password is a string when confirming password by @devfrey in https://github.com/laravel/fortify/pull/606
    • Fix conflicts with app factories, causing recursive definitions in IDE by @crynobone in https://github.com/laravel/fortify/pull/609
    • Add Fortify::encryptUsing() to allow customising the default encryption by @crynobone in https://github.com/laravel/fortify/pull/611
    • Regenerate session on register by @valorin in https://github.com/laravel/fortify/pull/610
    Open source →
  19. v1.30.0 29 Aug 2025
    Release notes
    • [1.x] Add InteractsWithTwoFactorState Trait to handle 2FA state between requests by @pushpak1300 in https://github.com/laravel/fortify/pull/604
    Open source →
  20. v1.29.0 14 Aug 2025
    Release notes
    • fix: add missing route name to /user/two-factor-recovery-codes by @Barbapapazes in https://github.com/laravel/fortify/pull/602
    Open source →
  21. v1.28.0 22 Jul 2025
    Release notes
    • feat() : make Fortify honour Model::encryptUsing to enable app key rotation by @sebestenyb in https://github.com/laravel/fortify/pull/601
    Open source →
  22. v1.27.0 11 Jun 2025
    Release notes
    • Allow RedirectIfTwoFactorAuthenticatable to be resolved via the Container by @Junveloper in https://github.com/laravel/fortify/pull/599
    Open source →
  23. v1.26.0 05 Jun 2025
    Release notes
    • Delete existing tokens when user updates password by @patrickomeara in https://github.com/laravel/fortify/pull/598
    Open source →
  24. v1.25.4 26 Jan 2025
    Release notes
    • Prevent empty username fields from being added to requests by @edvardsr in https://github.com/laravel/fortify/pull/590
    • Supports Laravel 12 by @crynobone in https://github.com/laravel/fortify/pull/591
    Open source →
  25. v1.25.3 17 Jan 2025
    Release notes
    • DisableTwoFactorAuthentication should always set two_factor_confirmed_at to null when it has a value by @crynobone in https://github.com/laravel/fortify/pull/589
    Open source →
  26. v1.25.2 10 Jan 2025
    Release notes
    • [1.x] Use retrieveByCredentials() on the User Provider instead of a hardcoded Eloquent query by @pascalbaljet in https://github.com/laravel/fortify/pull/582
    • Changed migration of users table by @aronbeurskens in https://github.com/laravel/fortify/pull/586
    Open source →
  27. v1.25.1 27 Nov 2024
    Release notes
    • Replace implicitly nullable parameters for PHP 8.4 by @JeppeKnockaert in https://github.com/laravel/fortify/pull/580
    Open source →
  28. v1.25.0 21 Nov 2024
    Release notes
    • Add Remember Me Functionality to Registered User Login by @cvairlis in https://github.com/laravel/fortify/pull/579
    Open source →
  29. v1.24.5 12 Nov 2024
    Release notes
    • [1.x] Supports PHP 8.4 by @crynobone in https://github.com/laravel/fortify/pull/576
    Open source →
  30. v1.24.4 29 Oct 2024
    Release notes
    • Rename POST routes to avoid regression bugs by @cima-alfa in https://github.com/laravel/fortify/pull/574
    Open source →
  31. v1.24.3 18 Oct 2024
    Release notes
    • Update logo to support dark/light theme by @milewski in https://github.com/laravel/fortify/pull/569
    • Fix unnamed routes when views are disabled (with original code formatting) by @cima-alfa in https://github.com/laravel/fortify/pull/571
    Open source →
  32. v1.24.2 16 Sep 2024
    Release notes
    • Adding context length configuration for 2FA to ensure better security standards by @MattLoyeD in https://github.com/laravel/fortify/pull/568
    Open source →
  33. v1.24.1 03 Sep 2024
    Release notes
    • [1.x] Add X-Retry-After to /user/confirm-password/status response by @crynobone in https://github.com/laravel/fortify/pull/565
    Open source →
  34. v1.24.0 20 Aug 2024
    Release notes
    • [1.x] Support case insensitive password resets by @mattmcdonald-uk in https://github.com/laravel/fortify/pull/562
    • Dispatch RecoveryCodeReplaced Event by @stephenjude in https://github.com/laravel/fortify/pull/564
    Open source →
  35. v1.23.0 02 Aug 2024
    Release notes
    • Fire ValidTwoFactorAuthenticationCodeProvided Event when 2FA session is authenticated by @stefanzweifel in https://github.com/laravel/fortify/pull/559
    Open source →
  36. v1.22.0 22 Jul 2024
    Release notes
    • [1.x] Rehash password if required when user uses two factor by @gdebrauwer in https://github.com/laravel/fortify/pull/557
    • [1.x] Add TwoFactorAuthenticationFailed event by @antergos98 in https://github.com/laravel/fortify/pull/558
    Open source →
  37. v1.21.5 04 Jul 2024
    Release notes
    • [1.x] Allow redirect()->intended() responses to be resolved via the Container by @crynobone in https://github.com/laravel/fortify/pull/551
    Open source →
  38. v1.21.4 27 Jun 2024
    Release notes
    • [1.x] Use available $name property from SessionGuard if the value exists by @crynobone in https://github.com/laravel/fortify/pull/553
    Open source →
  39. v1.21.3 08 May 2024
    Release notes
    • [1.x] Ensure logout route is authenticated by @timacdonald in https://github.com/laravel/fortify/pull/536
    Open source →
  40. v1.21.2 25 Apr 2024
    Release notes
    • [1.x] Bacon QR 3.0 support by @eshimischi in https://github.com/laravel/fortify/pull/534
    Open source →
  41. v1.21.1 19 Mar 2024
    Release notes
    • Specify return type array type by @santigarcor in https://github.com/laravel/fortify/pull/525
    • [1.x] Make commands lazy by @timacdonald in https://github.com/laravel/fortify/pull/527
    Open source →
  42. v1.21.0 08 Mar 2024
    Release notes
    • [1.x] Adds fortify:install Artisan command by @nunomaduro in https://github.com/laravel/fortify/pull/524
    Open source →
  43. v1.20.1 08 Feb 2024
    Release notes
    • Don't overwrite an already two factor secret unless force = true by @danmatthews in https://github.com/laravel/fortify/pull/518
    • Use Date facade for storing the password confirmation timestamp by @chrisvanlier2005 in https://github.com/laravel/fortify/pull/520
    Open source →
  44. v1.20.0 15 Jan 2024
    Release notes
    • [1.x] Merges develop by @nunomaduro in https://github.com/laravel/fortify/pull/515
    Open source →
  45. v1.19.1 11 Dec 2023
    Release notes
    • Deprecate the password rule and use illuminate password rule by @ricklambrechts in https://github.com/laravel/fortify/pull/511
    Open source →
  46. v1.19.0 27 Nov 2023
    Release notes
    • Add new event by @taylorotwell in https://github.com/laravel/fortify/commit/2da721fead1f3bc18af983e4903c4e1df67177e7
    Open source →
  47. v1.18.1 18 Oct 2023
    Release notes
    • Fix paths in default config using nested arrays by @sebj54 in https://github.com/laravel/fortify/pull/501
    Open source →
  48. v1.18.0 12 Sep 2023
    Release notes
    • Added case-sensitivity option for usernames by @Radiergummi in https://github.com/laravel/fortify/pull/485
    • Added response contract for email verification notification by @m-thalmann in https://github.com/laravel/fortify/pull/489
    Open source →
  49. v1.17.6 04 Sep 2023
    Release notes
    • Update logout to invalidate and regenerate session only if session is present (Issue #486) by @karmendra in https://github.com/laravel/fortify/pull/487
    Open source →
  50. v1.17.5 02 Aug 2023
    Release notes
    • [1.x] Laravel Pint fixes by @iruoy in https://github.com/laravel/fortify/pull/480
    Open source →
  51. v1.17.4 18 Jun 2023
    Release notes
    • Port security fixes to default login rate limiter by @staudenmeir in https://github.com/laravel/fortify/pull/473
    Open source →
  52. v1.17.3 02 Jun 2023
    Release notes
    • Fix contract implementation by @jessarcher in https://github.com/laravel/fortify/pull/472
    Open source →
  53. v1.17.2 26 Apr 2023
    Release notes
    • Revert "Add rate limiter for a registration" by @taylorotwell in https://github.com/laravel/fortify/pull/465
    Open source →
  54. v1.17.1 19 Apr 2023
    Release notes
    • Add rate limiter for a registration by @trbsi in https://github.com/laravel/fortify/pull/460
    Open source →
  55. v1.17.0 17 Apr 2023
    Release notes
    • Add ability to override routes with custom paths by @stephenglass in https://github.com/laravel/fortify/pull/458
    Open source →
  56. v1.16.0 06 Jan 2023
    Release notes

    Added

    • Laravel v10 Support by @driesvints in https://github.com/laravel/fortify/pull/435
    Open source →
  57. v1.15.0 03 Jan 2023
    Release notes

    Changed

    • Update PrepareAuthenticatedSession.php by @francoism90 in https://github.com/laravel/fortify/pull/434
    • Uses PHP Native Type Declarations 🐘 by @nunomaduro in https://github.com/laravel/fortify/pull/421

    Fixed

    • Fix error while preparing PasswordResetResponse with views turned off by @leonkllr0 in https://github.com/laravel/fortify/pull/433
    Open source →
  58. v1.14.1 09 Dec 2022
    Release notes

    Changed

    • Only fire event when actually updating the database to disable two factor authentication by @taylorotwell in https://github.com/laravel/fortify/commit/04b4b9c20e421c415d0427904a72e08a21bdec27
    Open source →
  59. v1.14.0 23 Nov 2022
    Release notes

    Added

    • Add more Response contract bindings by @bdsumon4u in https://github.com/laravel/fortify/pull/425
    Open source →
  60. v1.13.7 04 Nov 2022
    Release notes

    Changed

    • Update parameter order for hash_equals function in TwoFactorLoginRequest by @jayan-blutui in https://github.com/laravel/fortify/pull/422

    Fixed

    • Use boolean rather than filled for remember by @Codeatron5000 in https://github.com/laravel/fortify/pull/423
    Open source →

Every package, every release, already written down.

The archive is open and free. Watching your own project is what we are building next.

Browse the archive