NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
Packagist · #369 most downloaded on Packagist
Laravel Passport provides OAuth2 server support to Laravel.
Last release 10 days ago
28 Sep 2026
Release timing varies
gaps range from 1 weeks to 3 months
Nearly every release is documented
notes for 57 of the last 60 stable releases
Nothing withdrawn
no release was ever pulled
10 years old
189 releases · first in 2016
Fix JSON API client lookups for owner columns by @jasonmccreary in #1943
One column per quarter.
Upgrade phpseclib to v4 by @godismyjudge95 in #1939
[13.x] Clarify grant_types migration is required for integer-based cl… by @jaapredeker in #1913
Add notice of invalid tokens when user and client id match by @Levivb in #1910
[13.x] Support space-delimited prompt parameter by @hafezdivandari in #1906
[13.x] Fix session JSON serialization by @hafezdivandari in #1905
[13.X] fix: resolve user as null when user ID matches client ID on integer key setups by @Can-Kar in #1902
This change permanently invalidates client credential tokens for any user whose user ID happens to match the client ID of the token issuer.
Prevent user impersonation via client credentials token by @pushpak1300 in #1901
[13.x] Add middleware attribute by @axlon in #1897
Add Boost skill for Passport development by @pushpak1300 in #1893
Add mixin annotation for Token model in AccessToken by @fjkorf in #1886
Token model in AccessToken by @fjkorf in #1886OAuthenticatable interface step to upgrade guide by @FeBe95 in #1887Token model in AccessToken by @fjkorf in https://github.com/laravel/passport/pull/1886OAuthenticatable interface step to upgrade guide by @FeBe95 in https://github.com/laravel/passport/pull/1887[13.x] Supports Laravel 13 by @crynobone in https://github.com/laravel/passport/pull/1885
can and cant methods to Token model by @hafezdivandari in https://github.com/laravel/passport/pull/1882[13.x] Allow firebase/php-jwt v7 by @hafezdivandari in https://github.com/laravel/passport/pull/1879
firebase/php-jwt v7 by @hafezdivandari in https://github.com/laravel/passport/pull/1879Remove the usage of deprecated $request->get() by @hivokas in https://github.com/laravel/passport/pull/1873
$request->get() by @hivokas in https://github.com/laravel/passport/pull/1873Passport::actingAs() by @axlon in https://github.com/laravel/passport/pull/1876[13.x] Fix possible 500 error when retrieving user on token guard by @hafezdivandari in https://github.com/laravel/passport/pull/1871
[13.x] Add static setter for authorizationServerResponseType by @RSpeekenbrink in https://github.com/laravel/passport/pull/1867
chore(UPGRADE): v13, update oauth_clients table schema changes by @maximepvrt in https://github.com/laravel/passport/pull/1865
findForPassport to optionally receive the OAuth client by @maximepvrt in https://github.com/laravel/passport/pull/1866[13.x] Fix accessing the plain secret after creating a new confidential client via deprecated ClientController::store by @hafezdivandari in https://gi…
ClientController::store by @hafezdivandari in https://github.com/laravel/passport/pull/1861[13.x] add trailing commas in multiline constructor signatures by @browner12 in https://github.com/laravel/passport/pull/1848
[13.x] Added device code grant exception to purge command by @SuperDJ in https://github.com/laravel/passport/pull/1846
[13.x] Add an option to disable device code grant by @hafezdivandari in https://github.com/laravel/passport/pull/1842
oauth_clients table to the upgrade guide by @hafezdivandari in https://github.com/laravel/passport/pull/1843[13.x] Fix broken token relation when auth identifier is not PK by @axlon in https://github.com/laravel/passport/pull/1835
[13.x] Fix Exception Caused by Missing AccessToken Attributes by @hafezdivandari in https://github.com/laravel/passport/pull/1829
AccessToken Attributes by @hafezdivandari in https://github.com/laravel/passport/pull/1829[13.x] Fix skipping authorization consent when no scopes are requested by @hafezdivandari in https://github.com/laravel/passport/pull/1825
oauth_clients table in upgrade guide by @gdebrauwer in https://github.com/laravel/passport/pull/1823[13.x] Fix object returned by mocked validateAuthenticatedRequest() method in Passport::actingAsClient() method by @gdebrauwer in https://github.com/l
validateAuthenticatedRequest() method in Passport::actingAsClient() method by @gdebrauwer in https://github.com/laravel/passport/pull/1822Changed getTokenFromRequest method to handle null value and prevent type error by @eldair in https://github.com/laravel/passport/pull/1819
[13.x] Fix access to undefined route by @axlon in https://github.com/laravel/passport/pull/1812
[13.x] Deprecate JSON API by @hafezdivandari in https://github.com/laravel/passport/pull/1778
oauth_scopes property of the bearer token on TokenGuard by @hafezdivandari in https://github.com/laravel/passport/pull/1755OAuthServerException by @hafezdivandari in https://github.com/laravel/passport/pull/1763CheckClientCredentials middleware by @hafezdivandari in https://github.com/laravel/passport/pull/1792EnsureClientIsResourceOwner middleware by @hafezdivandari in https://github.com/laravel/passport/pull/1794Fix firebase/php jwt vuln by @jszoja in #1889
[12.x] Update property annotation for $userId to match constructor type by @ukkok in https://github.com/laravel/passport/pull/1805
Supports Laravel 12 by @crynobone in https://github.com/laravel/passport/pull/1803
[12.x] Supports PHP 8.4 by @crynobone in https://github.com/laravel/passport/pull/1799
Update logo to support dark/light theme by @milewski in https://github.com/laravel/passport/pull/1787
[12.x] Add access token revoked event by @axlon in https://github.com/laravel/passport/pull/1776
[12.x] Fix purge command by @hafezdivandari in https://github.com/laravel/passport/pull/1772
[12.x] Add refreshToken relation to Token model by @gdebrauwer in https://github.com/laravel/passport/pull/1739
refreshToken relation to Token model by @gdebrauwer in https://github.com/laravel/passport/pull/1739[12.x] Make Passport's database connection configurable by @axlon in https://github.com/laravel/passport/pull/1738
Adjust newFactory method visibility by @brandonfarber in https://github.com/laravel/passport/pull/1735
[12.x] Make commands lazy by @timacdonald in https://github.com/laravel/passport/pull/1731
[12.x] Cast session lifetime to int by @kindslayer in https://github.com/laravel/passport/pull/1727
[12.x] Adds Laravel 11 support by @nunomaduro in https://github.com/laravel/passport/pull/1702
Client::$plainSecret public by @axlon in https://github.com/laravel/passport/pull/1719Check that properties grant_types and scopes exist by @uintaam in https://github.com/laravel/passport/pull/1722
grant_types and scopes exist by @uintaam in https://github.com/laravel/passport/pull/1722[11.x] Fix getting/setting client scopes and grant types by @axlon in https://github.com/laravel/passport/pull/1717
Consistently retrieve client uuids value from Passport by @rojtjo in https://github.com/laravel/passport/pull/1711
Add getScopesAttribute and getScopesAttribute methods by @uintaam in https://github.com/laravel/passport/pull/1709
[11.x] Allow unsetting a user's access token by @axlon in https://github.com/laravel/passport/pull/1698
[11.x] Named static methods for middleware by @michaelnabil230 in https://github.com/laravel/passport/pull/1695
Add return to revokeRefreshTokensByAccessTokenId method by @aminkhoshzahmat in https://github.com/laravel/passport/pull/1693
[11.x] Allow scope repository to be constructed without parameters by @axlon in https://github.com/laravel/passport/pull/1686
[11.x] Add the ability to limit scopes by client by @axlon in https://github.com/laravel/passport/pull/1682
Add generics to client factory by @axlon in https://github.com/laravel/passport/pull/1669
Revert "[11.x] Add Provider Guard to ClientRepository for Personal Access Clients" by @driesvints in https://github.com/laravel/passport/pull/1658
Add Provider Guard to ClientRepository for Personal Access Clients by @michaelnabil230 in https://github.com/laravel/passport/pull/1655
Allow lcobucci/jwt v5 and cleaned up version constraints by @GrahamCampbell in https://github.com/laravel/passport/pull/1649
lcobucci/jwt v5 and cleaned up version constraints by @GrahamCampbell in https://github.com/laravel/passport/pull/1649Removed deprecated dates property from RefreshToken model by @siarheipashkevich in https://github.com/laravel/passport/pull/1645
dates property from RefreshToken model by @siarheipashkevich in https://github.com/laravel/passport/pull/1645dates property from AuthCode model by @siarheipashkevich in https://github.com/laravel/passport/pull/1644Allow overriding the AccessToken class by @hafezdivandari in https://github.com/laravel/passport/pull/1638
AccessToken class by @hafezdivandari in https://github.com/laravel/passport/pull/1638$userId nullable in ClientRepository->createPersonalAccessClient by @bram-pkg in https://github.com/laravel/passport/pull/1642Re-apply "Added AuthenticationException to extend the behaviour of Laravel's default exception handler" by @driesvints in https://github.com/laravel/p
Revert "Move AuthenticationException into the scope of Laravel Passport" by @driesvints in https://github.com/laravel/passport/commit/db543b0cc13ed3f5
Fix deprecated $dates property by @TonyWong9527 in https://github.com/laravel/passport/pull/1636
Add support for EncryptCookies middleware by @axlon in https://github.com/laravel/passport/pull/1628
EncryptCookies middleware by @axlon in https://github.com/laravel/passport/pull/1628Your coding agent can read these notes before it upgrades. Set up the MCP server →