NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
Packagist · #167 most downloaded on Packagist
Laravel Sanctum provides a featherweight authentication system for SPAs and simple APIs.
Last release 3 months ago
23 Jun 2026
Release timing varies
gaps range from 8 days to 4 months
Nearly every release is documented
notes for 60 of the last 60 stable releases
Nothing withdrawn
no release was ever pulled
7 years old
79 releases · first in 2020
One column per quarter.
Pin GitHub Actions to commit SHAs and add Dependabot config by @joetannenbaum in #598
[4.x] Update config/sanctum.php to follow skeleton laravel/pint format by @crynobone in #597
config/sanctum.php to follow skeleton laravel/pint format by @crynobone in #597[4.x] Supports Laravel 13 by @crynobone in #587
Add optional last_used_at tracking configuration by @MElkmeshi in #583
Allow nullable $passwordHash by @BnitoBzh in #582
Allow null password hash by @patrickomeara in #581
Support HMAC password hash format from Laravel 12.45.0+ by @ams-ryanolson in #578
[4.x] Remove @return docblocks on constructors by @CasEbb in #575
@return docblocks on constructors by @CasEbb in #575@return docblocks on constructors by @CasEbb in https://github.com/laravel/sanctum/pull/575[Refactor] Add indexes to personal_access_tokens by @keshav-k3 in #571
[4.x] Factor token last_used_at update into separate method by @cosmastech in #567
last_used_at update into separate method by @cosmastech in #567last_used_at update into separate method by @cosmastech in https://github.com/laravel/sanctum/pull/567Fixes inconsistency in Sanctum::currentApplicationUrlWithPort() and Sanctum::currentRequestHost() by @denjaland in https://github.com/laravel/sanctum/
Update logo by @iamdavidhill in https://github.com/laravel/sanctum/pull/562
Supports Laravel 12 by @crynobone in https://github.com/laravel/sanctum/pull/556
[4.x] Add tokenCant() helper function to HasApiTokens by @chester-sykes in https://github.com/laravel/sanctum/pull/552
tokenCant() helper function to HasApiTokens by @chester-sykes in https://github.com/laravel/sanctum/pull/552Add leading slash to @template tag in HasTokens by @omnicolor in https://github.com/laravel/sanctum/pull/550
[4.x] Supports PHP 8.4 by @crynobone in https://github.com/laravel/sanctum/pull/542
[4.x] Add Generics to HasApiTokens by @cosmastech in https://github.com/laravel/sanctum/pull/544
HasApiTokens by @cosmastech in https://github.com/laravel/sanctum/pull/544Fix: Cast Model Key to Integer for PostgreSQL Performance Improvement by @BakhadyrovF in https://github.com/laravel/sanctum/pull/524
Fix/unable to logout by @GigaGiorgadze in https://github.com/laravel/sanctum/pull/511
[4.x] Make commands lazy by @timacdonald in https://github.com/laravel/sanctum/pull/502
[4.x] Adds Laravel 11 support by @nunomaduro in https://github.com/laravel/sanctum/pull/480
Updated CsrfCookieController to use named arguments by @OussamaMater in https://github.com/laravel/sanctum/pull/487
CsrfCookieController to use named arguments by @OussamaMater in https://github.com/laravel/sanctum/pull/487Fix typo in config by @cosmastech in https://github.com/laravel/sanctum/pull/476
Sanctum[@getAccessTokenFromRequestUsing](https://github.com/getAccessTokenFromRequestUsing)() by @cosmastech in https://github.com/laravel/sanctum/pull/477Re-arrange middleware by @taylorotwell in https://github.com/laravel/sanctum/commit/d1f8bf7f2bdc39ba2a11f1d067b96d31d18246c8
Use crc32b instead of crc32 by @marzvrover in https://github.com/laravel/sanctum/pull/468
Add deprecated annotation in MissingScopeException by @hungthai1401 in https://github.com/laravel/sanctum/pull/462
MissingScopeException by @hungthai1401 in https://github.com/laravel/sanctum/pull/462Fix middleware by @taylorotwell in https://github.com/laravel/sanctum/commit/8ebda85d59d3c414863a7f4d816ef8302faad876
Check for validate CSRF token by @taylorotwell in https://github.com/laravel/sanctum/commit/f5bae6156c760545f368438198327e2609ba7bf1
Revert "check for validate csrf token middleware" by @driesvints in https://github.com/laravel/sanctum/commit/6281ce796d464592867f768eb890642aa1954bd0
Check for validate csrf token middleware by @taylorotwell in https://github.com/laravel/sanctum/commit/bbcb052de3fe075a67446e8c5c8ffcb191a1fb24
Fix bearer token format validation by @krasucki in https://github.com/laravel/sanctum/pull/417
Laravel v10 Support by @driesvints in https://github.com/laravel/sanctum/pull/415
Uses PHP Native Type Declarations 🐘 by @nunomaduro in https://github.com/laravel/sanctum/pull/405
Update migration's primary identifier change by @suyar in https://github.com/laravel/sanctum/pull/386
Expiration dates for tokens by @bjhijmans in https://github.com/laravel/sanctum/pull/252
Added custom auth token header support by @CodesignDev in https://github.com/laravel/sanctum/pull/354
Add sanctum:prune-expired command for removing expired tokens. by @yuraplohov in https://github.com/laravel/sanctum/pull/348
Use config function by @taylorotwell in commit
Add helper for current app url with port
### Changed - Laravel 9 support
Add an event on successful token validation (#327, b656bc1)
### Changed - Add guard to config
Rename CheckScopes and CheckForAnyScope to CheckAbilities and CheckForAnyAbility
CheckScopes and CheckForAnyScope to CheckAbilities and CheckForAnyAbility (#312)Add CheckScopes and CheckForAnyScope Middleware
Revert "fix: replace hardcoded "web" guard by config('sanctum.guard')"
config('sanctum.guard')" (#309)Replace hardcoded "web" guard by config('sanctum.guard')
config('sanctum.guard') (#307)Ignore updating last_used_at for deciding the DB connection host (#283, 2c8b9a1)
Only parse APP_URL for default stateful domains when it's set
Sanctum::$accessTokenAuthenticationCallback callback for more granular control over access token validation (#275, 9c07921, #276)
Add HasApiTokens contract to complement trait
### Changed - Use app helper
Environment APP_URL added into the default sanctum.stateful configuration
Changed Primary Key will not be used in created token's plainTextToken
Avoid running string functions when domain is null
Add multiple guard support for SPA auth (#246, f5695ae)
Fix user provider in sanctum guard
sanctum guard (#225)Add default nextjs address to stateful
### Added - PHP 8 Support
### Added - Adds origin header fallback
### Changed - Shorten tokens
Your coding agent can read these notes before it upgrades. Set up the MCP server →