NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
Packagist · #279 most downloaded on Packagist
Backend controllers and scaffolding for Laravel authentication.
Last release 9 days ago
28 Sep 2026
Ships fairly regularly
a new release about every 3 weeks
Nearly every release is documented
notes for 60 of the last 60 stable releases
Nothing withdrawn
no release was ever pulled
6 years old
116 releases · first in 2020
One column per quarter.
Migration from Mockery to Double by @jasonmccreary in #699
Introduction of Timebox to prevent Timing-based Username Enumeration by @bretto36 in #697
Fix repeat 2FA enable deleting pending secret by @wakqasahmed in #696
Bump actions/checkout from 7.0.0 to 7.0.1 in the github-actions group by @dependabot [bot] in #690
Add Dependabot cooldown of 5 days by @nunomaduro in #679
[1.x] Fix passkey password confirmation defaults by @benbjurstrom in #678
Full Changelog: v1.37.1...v1.37.2
Full Changelog: https://github.com/laravel/fortify/compare/v1.37.1...v1.37.2
[1.x] Bump actions/checkout from v4 to v6 by @mon4ssi in #673
Full Changelog: v1.37.0...v1.37.1
Full Changelog: https://github.com/laravel/fortify/compare/v1.37.0...v1.37.1
Drop support for PHP 8.1 and Laravel 10 by @benbjurstrom in #669
FormRequest::failOnUnknownFields() by @crynobone in #670FormRequest::failOnUnknownFields() by @crynobone in https://github.com/laravel/fortify/pull/670Rewrite Fortify core guidelines and skill descriptions in imperative style by @pushpak1300 in #662
[1.x] Makes imports consistent by @nunomaduro in #659
Rename Skill by @pushpak1300 in #657
Add @throws annotation to create() docblock by @mohammadRezaei1380 in #634
Supports Laravel 13 by @crynobone in #631
[1.x] Add Skills support by @pushpak1300 in https://github.com/laravel/fortify/pull/630
Full Changelog: https://github.com/laravel/fortify/compare/v1.33.0...v1.34.0
Added dedicated Request object to PasswordResetLinkController by @chrispage1 in https://github.com/laravel/fortify/pull/628
[1.x] PHP 8.5 Compatibility by @crynobone in https://github.com/laravel/fortify/pull/621
[1.x] Add Features::canUpdatePasswords() method by @jrd-lewis in https://github.com/laravel/fortify/pull/617
Features::canUpdatePasswords() method by @jrd-lewis in https://github.com/laravel/fortify/pull/617Resolves issue #592 - RecoveryCodeReplaced event dispatched twice by @coolAlias in https://github.com/laravel/fortify/pull/616
[1.x] Add Laravel Fortify guidelines for boost by @pushpak1300 in https://github.com/laravel/fortify/pull/614
Breaking Change: Revert "Validate password is a string when confirming password" by @themsaid in https://github.com/laravel/fortify/pull/612
[1.x] single indentation on multiline ternarys by @browner12 in https://github.com/laravel/fortify/pull/605
Fortify::encryptUsing() to allow customising the default encryption by @crynobone in https://github.com/laravel/fortify/pull/611[1.x] Add InteractsWithTwoFactorState Trait to handle 2FA state between requests by @pushpak1300 in https://github.com/laravel/fortify/pull/604
InteractsWithTwoFactorState Trait to handle 2FA state between requests by @pushpak1300 in https://github.com/laravel/fortify/pull/604fix: add missing route name to /user/two-factor-recovery-codes by @Barbapapazes in https://github.com/laravel/fortify/pull/602
/user/two-factor-recovery-codes by @Barbapapazes in https://github.com/laravel/fortify/pull/602feat() : make Fortify honour Model::encryptUsing to enable app key rotation by @sebestenyb in https://github.com/laravel/fortify/pull/601
Allow RedirectIfTwoFactorAuthenticatable to be resolved via the Container by @Junveloper in https://github.com/laravel/fortify/pull/599
RedirectIfTwoFactorAuthenticatable to be resolved via the Container by @Junveloper in https://github.com/laravel/fortify/pull/599Delete existing tokens when user updates password by @patrickomeara in https://github.com/laravel/fortify/pull/598
Prevent empty username fields from being added to requests by @edvardsr in https://github.com/laravel/fortify/pull/590
DisableTwoFactorAuthentication should always set two_factor_confirmed_at to null when it has a value by @crynobone in https://github.com/laravel/forti
DisableTwoFactorAuthentication should always set two_factor_confirmed_at to null when it has a value by @crynobone in https://github.com/laravel/fortify/pull/589[1.x] Use retrieveByCredentials() on the User Provider instead of a hardcoded Eloquent query by @pascalbaljet in https://github.com/laravel/fortify/pu
retrieveByCredentials() on the User Provider instead of a hardcoded Eloquent query by @pascalbaljet in https://github.com/laravel/fortify/pull/582Replace implicitly nullable parameters for PHP 8.4 by @JeppeKnockaert in https://github.com/laravel/fortify/pull/580
Add Remember Me Functionality to Registered User Login by @cvairlis in https://github.com/laravel/fortify/pull/579
[1.x] Supports PHP 8.4 by @crynobone in https://github.com/laravel/fortify/pull/576
Rename POST routes to avoid regression bugs by @cima-alfa in https://github.com/laravel/fortify/pull/574
POST routes to avoid regression bugs by @cima-alfa in https://github.com/laravel/fortify/pull/574Update logo to support dark/light theme by @milewski in https://github.com/laravel/fortify/pull/569
Adding context length configuration for 2FA to ensure better security standards by @MattLoyeD in https://github.com/laravel/fortify/pull/568
[1.x] Add X-Retry-After to /user/confirm-password/status response by @crynobone in https://github.com/laravel/fortify/pull/565
X-Retry-After to /user/confirm-password/status response by @crynobone in https://github.com/laravel/fortify/pull/565[1.x] Support case insensitive password resets by @mattmcdonald-uk in https://github.com/laravel/fortify/pull/562
Fire ValidTwoFactorAuthenticationCodeProvided Event when 2FA session is authenticated by @stefanzweifel in https://github.com/laravel/fortify/pull/559
[1.x] Rehash password if required when user uses two factor by @gdebrauwer in https://github.com/laravel/fortify/pull/557
[1.x] Allow redirect()->intended() responses to be resolved via the Container by @crynobone in https://github.com/laravel/fortify/pull/551
redirect()->intended() responses to be resolved via the Container by @crynobone in https://github.com/laravel/fortify/pull/551[1.x] Use available $name property from SessionGuard if the value exists by @crynobone in https://github.com/laravel/fortify/pull/553
$name property from SessionGuard if the value exists by @crynobone in https://github.com/laravel/fortify/pull/553[1.x] Ensure logout route is authenticated by @timacdonald in https://github.com/laravel/fortify/pull/536
[1.x] Bacon QR 3.0 support by @eshimischi in https://github.com/laravel/fortify/pull/534
Specify return type array type by @santigarcor in https://github.com/laravel/fortify/pull/525
[1.x] Adds fortify:install Artisan command by @nunomaduro in https://github.com/laravel/fortify/pull/524
fortify:install Artisan command by @nunomaduro in https://github.com/laravel/fortify/pull/524Don't overwrite an already two factor secret unless force = true by @danmatthews in https://github.com/laravel/fortify/pull/518
Date facade for storing the password confirmation timestamp by @chrisvanlier2005 in https://github.com/laravel/fortify/pull/520[1.x] Merges develop by @nunomaduro in https://github.com/laravel/fortify/pull/515
Deprecate the password rule and use illuminate password rule by @ricklambrechts in https://github.com/laravel/fortify/pull/511
Add new event by @taylorotwell in https://github.com/laravel/fortify/commit/2da721fead1f3bc18af983e4903c4e1df67177e7
Fix paths in default config using nested arrays by @sebj54 in https://github.com/laravel/fortify/pull/501
Added case-sensitivity option for usernames by @Radiergummi in https://github.com/laravel/fortify/pull/485
Update logout to invalidate and regenerate session only if session is present (Issue #486) by @karmendra in https://github.com/laravel/fortify/pull/48
[1.x] Laravel Pint fixes by @iruoy in https://github.com/laravel/fortify/pull/480
Port security fixes to default login rate limiter by @staudenmeir in https://github.com/laravel/fortify/pull/473
Fix contract implementation by @jessarcher in https://github.com/laravel/fortify/pull/472
Revert "Add rate limiter for a registration" by @taylorotwell in https://github.com/laravel/fortify/pull/465
Add rate limiter for a registration by @trbsi in https://github.com/laravel/fortify/pull/460
Add ability to override routes with custom paths by @stephenglass in https://github.com/laravel/fortify/pull/458
Laravel v10 Support by @driesvints in https://github.com/laravel/fortify/pull/435
Update PrepareAuthenticatedSession.php by @francoism90 in https://github.com/laravel/fortify/pull/434
Your coding agent can read these notes before it upgrades. Set up the MCP server →