PackageTrack
Sign in Get early access

laravel/sanctum

Laravel Sanctum provides a featherweight authentication system for SPAs and simple APIs.

v4.3.3 208M downloads/mo #170 most downloaded on composer laravel/sanctum

What this package is like to depend on

Last release 2 months ago

23 Jun 2026

Release timing varies

gaps range from 8 days to 4 months

Nearly every release is documented

notes for 79 of 79 stable releases

Nothing withdrawn

no release was ever pulled

7 years old

79 releases · first in 2020

8 releases in the last 12 months

see the full history below

Release timeline

79 releases · Jan 2020 to Jun 2026
2021 2022 2023 2024 2025 2026
Release Pre-release

Releases

latest 60 of 79
  1. v4.3.3 23 Jun 2026
    Release notes
    • Pin GitHub Actions to commit SHAs and add Dependabot config by @joetannenbaum in #598
    • Bump shivammathur/setup-php from 2.37.0 to 2.37.1 in the github-actions group by @dependabot[bot] in #602
    • Pin pull requests and issues workflows to latest laravel/.github by @nunomaduro in #605
    • Add Dependabot cooldown of 5 days by @nunomaduro in #606
    • Enable Dependabot auto-merge by @nunomaduro in #610
    • Bump actions/checkout from 6.0.2 to 6.0.3 in the github-actions group by @dependabot[bot] in #611
    • Bump shivammathur/setup-php from 2.37.1 to 2.37.2 in the github-actions group by @dependabot[bot] in #612
    • Bump actions/checkout from 6.0.3 to 7.0.0 in the github-actions group by @dependabot[bot] in #613
    Open source →
    Release notes
    • Pin GitHub Actions to commit SHAs and add Dependabot config by @joetannenbaum in https://github.com/laravel/sanctum/pull/598
    • Bump shivammathur/setup-php from 2.37.0 to 2.37.1 in the github-actions group by @dependabot[bot] in https://github.com/laravel/sanctum/pull/602
    • Pin pull requests and issues workflows to latest laravel/.github by @nunomaduro in https://github.com/laravel/sanctum/pull/605
    • Add Dependabot cooldown of 5 days by @nunomaduro in https://github.com/laravel/sanctum/pull/606
    • Enable Dependabot auto-merge by @nunomaduro in https://github.com/laravel/sanctum/pull/610
    • Bump actions/checkout from 6.0.2 to 6.0.3 in the github-actions group by @dependabot[bot] in https://github.com/laravel/sanctum/pull/611
    • Bump shivammathur/setup-php from 2.37.1 to 2.37.2 in the github-actions group by @dependabot[bot] in https://github.com/laravel/sanctum/pull/612
    • Bump actions/checkout from 6.0.3 to 7.0.0 in the github-actions group by @dependabot[bot] in https://github.com/laravel/sanctum/pull/613
    Open source →
  2. v4.3.2 30 Apr 2026
    Release notes
    • [4.x] Update config/sanctum.php to follow skeleton laravel/pint format by @crynobone in #597
    Open source →
    Release notes
    • [4.x] Update config/sanctum.php to follow skeleton laravel/pint format by @crynobone in https://github.com/laravel/sanctum/pull/597
    Open source →
  3. v4.3.1 07 Feb 2026
    Release notes
    Open source →
    Release notes
    • [4.x] Supports Laravel 13 by @crynobone in https://github.com/laravel/sanctum/pull/587
    Open source →
  4. v4.3.0 22 Jan 2026
    Release notes
    Open source →
    Release notes
    • Add optional last_used_at tracking configuration by @MElkmeshi in https://github.com/laravel/sanctum/pull/583
    • [4.x] Fix tests by @jackbayliss in https://github.com/laravel/sanctum/pull/584
    • [4.x] Fix failing test on Laravel > 11 by @jackbayliss in https://github.com/laravel/sanctum/pull/585
    • [4.x] Use property promotion by @jackbayliss in https://github.com/laravel/sanctum/pull/586
    Open source →
  5. v4.2.4 15 Jan 2026
    Release notes
    Open source →
    Release notes
    • Allow nullable $passwordHash by @BnitoBzh in https://github.com/laravel/sanctum/pull/582
    Open source →
  6. v4.2.3 11 Jan 2026
    Release notes
    Open source →
    Release notes
    • Allow null password hash by @patrickomeara in https://github.com/laravel/sanctum/pull/581
    Open source →
  7. v4.2.2 06 Jan 2026
    Release notes
    Open source →
    Release notes
    • Support HMAC password hash format from Laravel 12.45.0+ by @ams-ryanolson in https://github.com/laravel/sanctum/pull/578
    Open source →
  8. v4.2.1 21 Nov 2025
    Release notes
    Open source →
    Release notes
    • [4.x] Remove @return docblocks on constructors by @CasEbb in https://github.com/laravel/sanctum/pull/575
    • [4.x] PHP 8.5 Compatibility by @crynobone in https://github.com/laravel/sanctum/pull/576
    Open source →
  9. v4.2.0 09 Jul 2025
    Release notes
    • [Refactor] Add indexes to personal_access_tokens by @keshav-k3 in #571
    Open source →
    Release notes
    • [Refactor] Add indexes to personal_access_tokens by @keshav-k3 in https://github.com/laravel/sanctum/pull/571
    Open source →
  10. v4.1.2 01 Jul 2025
    Release notes
    Open source →
    Release notes
    • [4.x] Factor token last_used_at update into separate method by @cosmastech in https://github.com/laravel/sanctum/pull/567
    • refactor: use text for name column by @reidsolon in https://github.com/laravel/sanctum/pull/570
    Open source →
  11. v4.1.1 23 Apr 2025
    Release notes
    • Fixes inconsistency in Sanctum::currentApplicationUrlWithPort() and Sanctum::currentRequestHost() by @denjaland in https://github.com/laravel/sanctum/pull/565
    Open source →
  12. v4.1.0 22 Apr 2025
    Release notes
    • Update logo by @iamdavidhill in https://github.com/laravel/sanctum/pull/562
    • Feature to treat same domain requests to be from frontend and make stateful by @denjaland in https://github.com/laravel/sanctum/pull/564
    Open source →
  13. v4.0.8 26 Jan 2025
    Release notes
    • Supports Laravel 12 by @crynobone in https://github.com/laravel/sanctum/pull/556
    Open source →
  14. v4.0.7 11 Dec 2024
    Release notes
    • [4.x] Add tokenCant() helper function to HasApiTokens by @chester-sykes in https://github.com/laravel/sanctum/pull/552
    Open source →
  15. v4.0.6 26 Nov 2024
    Release notes
    • Add leading slash to @template tag in HasTokens by @omnicolor in https://github.com/laravel/sanctum/pull/550
    Open source →
  16. v4.0.5 26 Nov 2024
    Release notes
    • [4.x] Supports PHP 8.4 by @crynobone in https://github.com/laravel/sanctum/pull/542
    • [4.x] Remove generic requirement that token is an instance of a Model by @cosmastech in https://github.com/laravel/sanctum/pull/549
    Open source →
  17. v4.0.4 15 Nov 2024
    Release notes
    • [4.x] Add Generics to HasApiTokens by @cosmastech in https://github.com/laravel/sanctum/pull/544
    • [4.x] Add generics by @cosmastech in https://github.com/laravel/sanctum/pull/545
    Open source →
  18. v4.0.3 27 Sep 2024
    Release notes
    • Fix: Cast Model Key to Integer for PostgreSQL Performance Improvement by @BakhadyrovF in https://github.com/laravel/sanctum/pull/524
    • Revert "Fix: Cast Model Key to Integer for PostgreSQL Performance Improvement" by @driesvints in https://github.com/laravel/sanctum/pull/526
    • Replace dead link in Security Policy by @Jubeki in https://github.com/laravel/sanctum/pull/528
    • Update logo to support dark/light theme by @milewski in https://github.com/laravel/sanctum/pull/536
    Open source →
  19. v4.0.2 10 Apr 2024
    Release notes
    • Fix/unable to logout by @GigaGiorgadze in https://github.com/laravel/sanctum/pull/511
    Open source →
  20. v4.0.1 19 Mar 2024
    Release notes
    • [4.x] Make commands lazy by @timacdonald in https://github.com/laravel/sanctum/pull/502
    Open source →
  21. v4.0.0 12 Mar 2024
    Release notes
    • [4.x] Adds Laravel 11 support by @nunomaduro in https://github.com/laravel/sanctum/pull/480
    • Matching method to contract for createToken() by @gammamatrix in https://github.com/laravel/sanctum/pull/498
    Open source →
  22. v3.3.3 19 Dec 2023
    Release notes
    • Updated CsrfCookieController to use named arguments by @OussamaMater in https://github.com/laravel/sanctum/pull/487
    • Extract generate token method by @mowangjuanzi in https://github.com/laravel/sanctum/pull/488
    Open source →
  23. v3.3.2 03 Nov 2023
    Release notes
    • Fix typo in config by @cosmastech in https://github.com/laravel/sanctum/pull/476
    • Accept null as a parameter for Sanctum[@getAccessTokenFromRequestUsing](https://github.com/getAccessTokenFromRequestUsing)() by @cosmastech in https://github.com/laravel/sanctum/pull/477
    Open source →
  24. v3.3.1 07 Sep 2023
    Release notes
    • Re-arrange middleware by @taylorotwell in https://github.com/laravel/sanctum/commit/d1f8bf7f2bdc39ba2a11f1d067b96d31d18246c8
    Open source →
  25. v3.3.0 04 Sep 2023
    Release notes
    • Use crc32b instead of crc32 by @marzvrover in https://github.com/laravel/sanctum/pull/468
    • Ensure device has not been logged out by @crynobone in https://github.com/laravel/sanctum/pull/467
    • Do not prefix by default by @taylorotwell https://github.com/laravel/sanctum/commit/95a0181900019e2d79acbd3e2ee7d57e3d0a086b
    Open source →
  26. v3.2.6 22 Aug 2023
    Release notes
    • Make tokens identifiable with prefix and checksum by @marzvrover in https://github.com/laravel/sanctum/pull/459
    • Add deprecated annotation in MissingScopeException by @hungthai1401 in https://github.com/laravel/sanctum/pull/462
    Open source →
  27. v3.2.5 01 May 2023
    Release notes
    • Fix middleware by @taylorotwell in https://github.com/laravel/sanctum/commit/8ebda85d59d3c414863a7f4d816ef8302faad876
    Open source →
  28. v3.2.4 26 Apr 2023
    Release notes
    • Check for validate CSRF token by @taylorotwell in https://github.com/laravel/sanctum/commit/f5bae6156c760545f368438198327e2609ba7bf1
    Open source →
  29. v3.2.3 25 Apr 2023
    Release notes
    • Revert "check for validate csrf token middleware" by @driesvints in https://github.com/laravel/sanctum/commit/6281ce796d464592867f768eb890642aa1954bd0
    Open source →
  30. v3.2.2 21 Apr 2023
    Release notes
    • Check for validate csrf token middleware by @taylorotwell in https://github.com/laravel/sanctum/commit/bbcb052de3fe075a67446e8c5c8ffcb191a1fb24
    Open source →
  31. v3.2.1 13 Jan 2023
    Release notes

    Fixed

    • Fix bearer token format validation by @krasucki in https://github.com/laravel/sanctum/pull/417
    Open source →
  32. v3.2.0 06 Jan 2023
    Release notes

    Added

    • Laravel v10 Support by @driesvints in https://github.com/laravel/sanctum/pull/415
    Open source →
  33. v3.1.0 03 Jan 2023
    Release notes

    Changed

    • Uses PHP Native Type Declarations 🐘 by @nunomaduro in https://github.com/laravel/sanctum/pull/405
    Open source →
  34. v3.0.1 29 Jul 2022
    Release notes

    Changed

    • Update migration's primary identifier change by @suyar in https://github.com/laravel/sanctum/pull/386
    • Prune expires_at tokens by @iruoy in https://github.com/laravel/sanctum/pull/385
    Open source →
  35. v3.0.0 25 Jul 2022
    Release notes

    Added

    • Expiration dates for tokens by @bjhijmans in https://github.com/laravel/sanctum/pull/252

    Changed

    • Improves console output by @nunomaduro in https://github.com/laravel/sanctum/pull/382
    • Shorter tokens by @taylorotwell in https://github.com/laravel/sanctum/commit/c46fc083ab52f2ddac97ee4510486f90fc94f220

    Removed

    • Drop old Laravel and PHP versions by @driesvints in https://github.com/laravel/sanctum/pull/378
    Open source →
  36. v2.15.1 08 Apr 2022
    Release notes

    Changed

    • Added custom auth token header support by @CodesignDev in https://github.com/laravel/sanctum/pull/354
    Open source →
  37. v2.15.0 28 Mar 2022
    Release notes

    Added

    • Add sanctum:prune-expired command for removing expired tokens. by @yuraplohov in https://github.com/laravel/sanctum/pull/348

    Fixed

    • Add exit codes to command by @driesvints in https://github.com/laravel/sanctum/pull/351
    Open source →
  38. v2.14.2 16 Feb 2022
    Release notes

    Changed

    • Use config function by @taylorotwell in commit
    Open source →
  39. v2.14.1 15 Feb 2022
    Release notes

    Changed

    • Add helper for current app url with port (5702317)
    Open source →
  40. v2.14.0 12 Jan 2022
    Release notes

    Changed

    • Laravel 9 support (#329)
    Open source →
  41. v2.13.0 14 Dec 2021
    Release notes

    Added

    • Add an event on successful token validation (#327, b656bc1)
    Open source →
  42. v2.12.2 16 Nov 2021
    Release notes

    Changed

    Open source →
  43. v2.12.1 26 Oct 2021
    Release notes

    Changed

    • Rename CheckScopes and CheckForAnyScope to CheckAbilities and CheckForAnyAbility (#312)
    Open source →
  44. v2.12.0 19 Oct 2021
    Release notes

    Added

    • Add CheckScopes and CheckForAnyScope Middleware (#310)
    Open source →
  45. v2.11.4 13 Oct 2021
    Release notes

    Fixed

    • Revert "fix: replace hardcoded "web" guard by config('sanctum.guard')" (#309)
    Open source →
  46. v2.11.3 12 Oct 2021
    Release notes

    Fixed

    • Replace hardcoded "web" guard by config('sanctum.guard') (#307)
    Open source →
  47. v2.11.2 15 Jun 2021
    Release notes

    Fixed

    • Ignore updating last_used_at for deciding the DB connection host (#283, 2c8b9a1)
    • Fix resolving wrong app instance on Octane (#285, #286)
    Open source →
  48. v2.11.1 25 May 2021
    Release notes

    Changed

    • Only parse APP_URL for default stateful domains when it's set (#279)
    Open source →
  49. v2.11.0 11 May 2021
    Release notes

    Added

    • Sanctum::$accessTokenAuthenticationCallback callback for more granular control over access token validation (#275, 9c07921, #276)
    Open source →
  50. v2.10.0 20 Apr 2021
    Release notes

    Added

    • Add HasApiTokens contract to complement trait (#270)
    Open source →
  51. v2.9.4 06 Apr 2021
    Release notes

    Changed

    Open source →
  52. v2.9.3 30 Mar 2021
    Release notes

    Changed

    • Environment APP_URL added into the default sanctum.stateful configuration (#264)
    Open source →
  53. v2.9.2 23 Mar 2021
    Release notes

    Fixed

    • Changed Primary Key will not be used in created token's plainTextToken (#262)
    Open source →
  54. v2.9.1 09 Mar 2021
    Release notes

    Fixed

    • Avoid running string functions when domain is null (#258)
    Open source →
  55. v2.9.0 26 Jan 2021
    Release notes

    Added

    • Add multiple guard support for SPA auth (#246, f5695ae)

    Fixed

    • Return json response when the request expects a json (#247)
    Open source →
  56. v2.8.2 24 Nov 2020
    Release notes

    Fixed

    • Fix user provider in sanctum guard (#225)
    Open source →
  57. v2.8.1 17 Nov 2020
    Release notes

    Changed

    • Add default nextjs address to stateful (e86d3e0)
    Open source →
  58. v2.8.0 03 Nov 2020
    Release notes

    Added

    • PHP 8 Support (#213)
    Open source →
  59. v2.7.0 20 Oct 2020
    Release notes

    Added

    • Adds origin header fallback (#204)
    Open source →
  60. v2.6.0 01 Sep 2020
    Release notes

    Changed

    • Shorten tokens (#186)
    Open source →

Every package, every release, already written down.

The archive is open and free. Watching your own project is what we are building next.

Browse the archive