laravel/sanctum
Laravel Sanctum provides a featherweight authentication system for SPAs and simple APIs.
v4.3.3
208M downloads/mo
#170 most downloaded on composer
laravel/sanctum
What this package is like to depend on
Last release 2 months ago
23 Jun 2026
Release timing varies
gaps range from 8 days to 4 months
Nearly every release is documented
notes for 79 of 79 stable releases
Nothing withdrawn
no release was ever pulled
7 years old
79 releases · first in 2020
8 releases in the last 12 months
see the full history below
Release timeline
79 releases · Jan 2020 to Jun 2026
2021
2022
2023
2024
2025
2026
Releases
latest 60 of 79-
v4.3.323 Jun 2026Release notes
Open source →- Pin GitHub Actions to commit SHAs and add Dependabot config by @joetannenbaum in #598
- Bump shivammathur/setup-php from 2.37.0 to 2.37.1 in the github-actions group by @dependabot[bot] in #602
- Pin pull requests and issues workflows to latest laravel/.github by @nunomaduro in #605
- Add Dependabot cooldown of 5 days by @nunomaduro in #606
- Enable Dependabot auto-merge by @nunomaduro in #610
- Bump actions/checkout from 6.0.2 to 6.0.3 in the github-actions group by @dependabot[bot] in #611
- Bump shivammathur/setup-php from 2.37.1 to 2.37.2 in the github-actions group by @dependabot[bot] in #612
- Bump actions/checkout from 6.0.3 to 7.0.0 in the github-actions group by @dependabot[bot] in #613
Release notes
Open source →- Pin GitHub Actions to commit SHAs and add Dependabot config by @joetannenbaum in https://github.com/laravel/sanctum/pull/598
- Bump shivammathur/setup-php from 2.37.0 to 2.37.1 in the github-actions group by @dependabot[bot] in https://github.com/laravel/sanctum/pull/602
- Pin pull requests and issues workflows to latest laravel/.github by @nunomaduro in https://github.com/laravel/sanctum/pull/605
- Add Dependabot cooldown of 5 days by @nunomaduro in https://github.com/laravel/sanctum/pull/606
- Enable Dependabot auto-merge by @nunomaduro in https://github.com/laravel/sanctum/pull/610
- Bump actions/checkout from 6.0.2 to 6.0.3 in the github-actions group by @dependabot[bot] in https://github.com/laravel/sanctum/pull/611
- Bump shivammathur/setup-php from 2.37.1 to 2.37.2 in the github-actions group by @dependabot[bot] in https://github.com/laravel/sanctum/pull/612
- Bump actions/checkout from 6.0.3 to 7.0.0 in the github-actions group by @dependabot[bot] in https://github.com/laravel/sanctum/pull/613
-
v4.3.230 Apr 2026Release notes
Open source →- [4.x] Update
config/sanctum.phpto follow skeletonlaravel/pintformat by @crynobone in #597
Release notes
Open source →- [4.x] Update
config/sanctum.phpto follow skeletonlaravel/pintformat by @crynobone in https://github.com/laravel/sanctum/pull/597
- [4.x] Update
-
v4.3.107 Feb 2026Release notes
Open source →- [4.x] Supports Laravel 13 by @crynobone in https://github.com/laravel/sanctum/pull/587
-
v4.3.022 Jan 2026Release notes
Open source →- Add optional last_used_at tracking configuration by @MElkmeshi in #583
- [4.x] Fix tests by @jackbayliss in #584
- [4.x] Fix failing test on Laravel > 11 by @jackbayliss in #585
- [4.x] Use property promotion by @jackbayliss in #586
Release notes
Open source →- Add optional last_used_at tracking configuration by @MElkmeshi in https://github.com/laravel/sanctum/pull/583
- [4.x] Fix tests by @jackbayliss in https://github.com/laravel/sanctum/pull/584
- [4.x] Fix failing test on Laravel > 11 by @jackbayliss in https://github.com/laravel/sanctum/pull/585
- [4.x] Use property promotion by @jackbayliss in https://github.com/laravel/sanctum/pull/586
-
v4.2.415 Jan 2026Release notes
Open source →- Allow nullable $passwordHash by @BnitoBzh in https://github.com/laravel/sanctum/pull/582
-
v4.2.311 Jan 2026Release notes
Open source →- Allow null password hash by @patrickomeara in https://github.com/laravel/sanctum/pull/581
-
v4.2.206 Jan 2026Release notes
Open source →- Support HMAC password hash format from Laravel 12.45.0+ by @ams-ryanolson in #578
Release notes
Open source →- Support HMAC password hash format from Laravel 12.45.0+ by @ams-ryanolson in https://github.com/laravel/sanctum/pull/578
-
v4.2.121 Nov 2025Release notes
Open source →- [4.x] Remove
@returndocblocks on constructors by @CasEbb in #575 - [4.x] PHP 8.5 Compatibility by @crynobone in #576
Release notes
Open source →- [4.x] Remove
@returndocblocks on constructors by @CasEbb in https://github.com/laravel/sanctum/pull/575 - [4.x] PHP 8.5 Compatibility by @crynobone in https://github.com/laravel/sanctum/pull/576
- [4.x] Remove
-
v4.2.009 Jul 2025Release notes
Open source →- [Refactor] Add indexes to personal_access_tokens by @keshav-k3 in https://github.com/laravel/sanctum/pull/571
-
v4.1.201 Jul 2025Release notes
Open source →- [4.x] Factor token
last_used_atupdate into separate method by @cosmastech in #567 - refactor: use text for name column by @reidsolon in #570
Release notes
Open source →- [4.x] Factor token
last_used_atupdate into separate method by @cosmastech in https://github.com/laravel/sanctum/pull/567 - refactor: use text for name column by @reidsolon in https://github.com/laravel/sanctum/pull/570
- [4.x] Factor token
-
v4.1.123 Apr 2025Release notes
Open source →- Fixes inconsistency in Sanctum::currentApplicationUrlWithPort() and Sanctum::currentRequestHost() by @denjaland in https://github.com/laravel/sanctum/pull/565
-
v4.1.022 Apr 2025Release notes
Open source →- Update logo by @iamdavidhill in https://github.com/laravel/sanctum/pull/562
- Feature to treat same domain requests to be from frontend and make stateful by @denjaland in https://github.com/laravel/sanctum/pull/564
-
v4.0.826 Jan 2025Release notes
Open source →- Supports Laravel 12 by @crynobone in https://github.com/laravel/sanctum/pull/556
-
v4.0.711 Dec 2024Release notes
Open source →- [4.x] Add
tokenCant()helper function toHasApiTokensby @chester-sykes in https://github.com/laravel/sanctum/pull/552
- [4.x] Add
-
v4.0.626 Nov 2024Release notes
Open source →- Add leading slash to @template tag in HasTokens by @omnicolor in https://github.com/laravel/sanctum/pull/550
-
v4.0.526 Nov 2024Release notes
Open source →- [4.x] Supports PHP 8.4 by @crynobone in https://github.com/laravel/sanctum/pull/542
- [4.x] Remove generic requirement that token is an instance of a Model by @cosmastech in https://github.com/laravel/sanctum/pull/549
-
v4.0.415 Nov 2024Release notes
Open source →- [4.x] Add Generics to
HasApiTokensby @cosmastech in https://github.com/laravel/sanctum/pull/544 - [4.x] Add generics by @cosmastech in https://github.com/laravel/sanctum/pull/545
- [4.x] Add Generics to
-
v4.0.327 Sep 2024Release notes
Open source →- Fix: Cast Model Key to Integer for PostgreSQL Performance Improvement by @BakhadyrovF in https://github.com/laravel/sanctum/pull/524
- Revert "Fix: Cast Model Key to Integer for PostgreSQL Performance Improvement" by @driesvints in https://github.com/laravel/sanctum/pull/526
- Replace dead link in Security Policy by @Jubeki in https://github.com/laravel/sanctum/pull/528
- Update logo to support dark/light theme by @milewski in https://github.com/laravel/sanctum/pull/536
-
v4.0.210 Apr 2024Release notes
Open source →- Fix/unable to logout by @GigaGiorgadze in https://github.com/laravel/sanctum/pull/511
-
v4.0.119 Mar 2024Release notes
Open source →- [4.x] Make commands lazy by @timacdonald in https://github.com/laravel/sanctum/pull/502
-
v4.0.012 Mar 2024Release notes
Open source →- [4.x] Adds Laravel 11 support by @nunomaduro in https://github.com/laravel/sanctum/pull/480
- Matching method to contract for createToken() by @gammamatrix in https://github.com/laravel/sanctum/pull/498
-
v3.3.319 Dec 2023Release notes
Open source →- Updated
CsrfCookieControllerto use named arguments by @OussamaMater in https://github.com/laravel/sanctum/pull/487 - Extract generate token method by @mowangjuanzi in https://github.com/laravel/sanctum/pull/488
- Updated
-
v3.3.203 Nov 2023Release notes
Open source →- Fix typo in config by @cosmastech in https://github.com/laravel/sanctum/pull/476
- Accept null as a parameter for
Sanctum[@getAccessTokenFromRequestUsing](https://github.com/getAccessTokenFromRequestUsing)()by @cosmastech in https://github.com/laravel/sanctum/pull/477
-
v3.3.107 Sep 2023Release notes
Open source →- Re-arrange middleware by @taylorotwell in https://github.com/laravel/sanctum/commit/d1f8bf7f2bdc39ba2a11f1d067b96d31d18246c8
-
v3.3.004 Sep 2023Release notes
Open source →- Use crc32b instead of crc32 by @marzvrover in https://github.com/laravel/sanctum/pull/468
- Ensure device has not been logged out by @crynobone in https://github.com/laravel/sanctum/pull/467
- Do not prefix by default by @taylorotwell https://github.com/laravel/sanctum/commit/95a0181900019e2d79acbd3e2ee7d57e3d0a086b
-
v3.2.622 Aug 2023Release notes
Open source →- Make tokens identifiable with prefix and checksum by @marzvrover in https://github.com/laravel/sanctum/pull/459
- Add deprecated annotation in
MissingScopeExceptionby @hungthai1401 in https://github.com/laravel/sanctum/pull/462
-
v3.2.501 May 2023Release notes
Open source →- Fix middleware by @taylorotwell in https://github.com/laravel/sanctum/commit/8ebda85d59d3c414863a7f4d816ef8302faad876
-
v3.2.426 Apr 2023Release notes
Open source →- Check for validate CSRF token by @taylorotwell in https://github.com/laravel/sanctum/commit/f5bae6156c760545f368438198327e2609ba7bf1
-
v3.2.325 Apr 2023Release notes
Open source →- Revert "check for validate csrf token middleware" by @driesvints in https://github.com/laravel/sanctum/commit/6281ce796d464592867f768eb890642aa1954bd0
-
v3.2.221 Apr 2023Release notes
Open source →- Check for validate csrf token middleware by @taylorotwell in https://github.com/laravel/sanctum/commit/bbcb052de3fe075a67446e8c5c8ffcb191a1fb24
-
v3.2.113 Jan 2023Release notes
Open source →Fixed
- Fix bearer token format validation by @krasucki in https://github.com/laravel/sanctum/pull/417
-
v3.2.006 Jan 2023Release notes
Open source →Added
- Laravel v10 Support by @driesvints in https://github.com/laravel/sanctum/pull/415
-
v3.1.003 Jan 2023Release notes
Open source →Changed
- Uses PHP Native Type Declarations 🐘 by @nunomaduro in https://github.com/laravel/sanctum/pull/405
-
v3.0.129 Jul 2022Release notes
Open source →Changed
- Update migration's primary identifier change by @suyar in https://github.com/laravel/sanctum/pull/386
- Prune expires_at tokens by @iruoy in https://github.com/laravel/sanctum/pull/385
-
v3.0.025 Jul 2022Release notes
Open source →Added
- Expiration dates for tokens by @bjhijmans in https://github.com/laravel/sanctum/pull/252
Changed
- Improves console output by @nunomaduro in https://github.com/laravel/sanctum/pull/382
- Shorter tokens by @taylorotwell in https://github.com/laravel/sanctum/commit/c46fc083ab52f2ddac97ee4510486f90fc94f220
Removed
- Drop old Laravel and PHP versions by @driesvints in https://github.com/laravel/sanctum/pull/378
-
v2.15.108 Apr 2022Release notes
Open source →Changed
- Added custom auth token header support by @CodesignDev in https://github.com/laravel/sanctum/pull/354
-
v2.15.028 Mar 2022Release notes
Open source →Added
- Add sanctum:prune-expired command for removing expired tokens. by @yuraplohov in https://github.com/laravel/sanctum/pull/348
Fixed
- Add exit codes to command by @driesvints in https://github.com/laravel/sanctum/pull/351
-
v2.14.216 Feb 2022 -
v2.14.115 Feb 2022 -
v2.14.012 Jan 2022 -
v2.13.014 Dec 2021 -
v2.12.216 Nov 2021 -
v2.12.126 Oct 2021Release notes
Open source →Changed
- Rename
CheckScopesandCheckForAnyScopetoCheckAbilitiesandCheckForAnyAbility(#312)
- Rename
-
v2.12.019 Oct 2021 -
v2.11.413 Oct 2021Release notes
Open source →Fixed
- Revert "fix: replace hardcoded "web" guard by
config('sanctum.guard')" (#309)
- Revert "fix: replace hardcoded "web" guard by
-
v2.11.312 Oct 2021 -
v2.11.215 Jun 2021 -
v2.11.125 May 2021Release notes
Open source →Changed
- Only parse APP_URL for default stateful domains when it's set (#279)
-
v2.11.011 May 2021 -
v2.10.020 Apr 2021 -
v2.9.406 Apr 2021 -
v2.9.330 Mar 2021Release notes
Open source →Changed
- Environment APP_URL added into the default sanctum.stateful configuration (#264)
-
v2.9.223 Mar 2021Release notes
Open source →Fixed
- Changed Primary Key will not be used in created token's plainTextToken (#262)
-
v2.9.109 Mar 2021 -
v2.9.026 Jan 2021 -
v2.8.224 Nov 2020 -
v2.8.117 Nov 2020 -
v2.8.003 Nov 2020 -
v2.7.020 Oct 2020 -
v2.6.001 Sep 2020