NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
Packagist · #347 most downloaded on Packagist
OAuth 2.0 Client Library
Last release 21 days ago
16 Sep 2026
Ships fairly regularly
a new release about every 10 months
Nearly every release is documented
notes for 38 of 41 stable releases
Nothing withdrawn
no release was ever pulled
14 years old
45 releases · first in 2013
Add support for Guzzle v8 #1112
Add support for PHP 8.5 #1081
One column per quarter.
Only provide scopes in access token when set in options #1053
Set minimum version of Guzzle to 6.5.8 and 7.4.5, due to security vulnerabilities reported in earlier versions #1022
expires is not a number #929SettableRefreshTokenInterface to support setting the refresh token #994AbstractProvider::prepareAccessTokenResponse() #1025
Add support for PKCE (Proof Key for Code Exchange, RFC 7636 ) #901
Fix deprecation notices, providing full support for PHP 8.1 #919 #920
Allow time to be set for testing purposes #852
Released: 2020-10-27
Allow Guzzle 7.x to be used #847
Revert to use of AccessToken in type hints to preserve backwards compatibility; this fixes the issue reported in #752 and #753
Add HttpBasicAuthOptionProvider to ease implementation for providers requiring HTTP basic auth
HttpBasicAuthOptionProvider to ease implementation for providers requiring HTTP basic authGuardedPropertyTrait to allow providers the ability to specify properties that may not be overridden by user-defined values passed to the provider constructorAccessTokenInterface and ResourceOwnerAccessTokenInterface to allow providers the ability to override the default AccessTokenAllow paragonie/random_compat's empty 9.99.99 placeholder
UnexpectedValueException on non-JSON responses from access tokenAbstractProvider::getAccessToken())Released: 2018-11-19
UnexpectedValueException on non-JSON responses from access token
request (when calling AbstractProvider::getAccessToken())Add ProviderRedirectTrait tool for 3rd-party provider libraries to use when handling provider redirections
Released: 2018-01-13
ProviderRedirectTrait tool for 3rd-party provider libraries to use when
handling provider redirectionsgetResourceOwner() receives a non-JSON ResponseFix potential type error when HTTP 500 errors are encountered
Released: 2017-04-25
random_compat versionsAllow base URLs to contain query parameters
Released: 2017-02-01
+ being improperly encoded in URL parametersstate option from authorization parametersAllow expires_in with a value of 0
Released: 2017-01-24
expires_in with a value of 0Rename getResponse() to getParsedResponse()
Released: 2017-01-12
getResponse() to getParsedResponse()getResponse() method that returns the unparsed PSR-7 Response instanceRandomFactory, switched to native random functionsNothing published for this version
Add QueryBuilderTrait to standardize query string generation.
Released: 2016-04-29
QueryBuilderTrait to standardize query string generation.Add AccessToken::getValues() to access additional vendor data provided with tokens.
Released: 2016-04-19
AccessToken::getValues() to access additional vendor data provided with tokens.Enable dynamic parameters being passed into the authorization URL.
Released: 2016-02-13
Add resource_owner_id to the JSON-serialized representation of the access token.
Released: 2016-01-23
resource_owner_id to the JSON-serialized representation of the access token.Add ArrayAccessorTrait, update AbstractProvider to utilize.
Released: 2015-11-13
ArrayAccessorTrait, update AbstractProvider to utilize.expires to serialize access tokens.Allow access tokens to be created from storage (see #431).
Released: 2015-09-22
Allow required parameters checked using the RequiredParameterTrait to be set as false, null, "0", etc.
Released: 2015-08-26
RequiredParameterTrait to be set as false, null, "0", etc.We are running code-quality builds through Scrutinizer, and we are running unit test builds on the new Travis CI container-based infrastructure.
Released: 2015-08-19
BREAK: Add toArray() to ResourceOwnerInterface.
Released: 2015-08-12
BREAK: Convert all uses of "User" to "ResourceOwner" to more closely match the OAuth 2.0 specification.
Released: 2015-07-16
StandardProvider to GenericProvider.AbstractProvider. It was previously handled in the AbstractGrant.Content-Type header with value of application/x-www-form-urlencoded to the request header when retrieving access tokens. This adheres to the OAuth 2.0 specification and fixes issues where certain OAuth servers expect this header.json_encode() serialization of AccessToken; when using json_encode() on an AccessToken, it will return a JSON object with these properties: access_token, refresh_token, and expires_in.BREAK: Renamed AbstractProvider::ACCESS_TOKEN_METHOD_GET to AbstractProvider::METHOD_GET.
Released: 2015-07-04
AbstractProvider::ACCESS_TOKEN_METHOD_GET to AbstractProvider::METHOD_GET.AbstractProvider::ACCESS_TOKEN_METHOD_POST to AbstractProvider::METHOD_POST.AbstractProvider::prepareUserDetails() to AbstractProvider::createUser().AbstractProvider::getUserDetails() to AbstractProvider::getUser().$token parameter from AbstractProvider::getDefaultHeaders().AbstractProvider::getBaseAccessTokenUrl() to accept a required array of parameters, allowing providers the ability to vary the access token URL, based on the parameters.README.PROVIDERS.md.README.PROVIDER-GUIDE.md.This release contains numerous BC breaks from the 0.x series. Please note these breaks and refer to the upgrade guide.
Released: 2015-06-25
This release contains numerous BC breaks from the 0.x series. Please note these breaks and refer to the upgrade guide.
public properties have been set as protected or private and getters/setters have been introduced for access to these properties.Provider\ProviderInterface has been removed. Please extend from and override Provider\AbstractProvider.Entity\User has been removed. Providers should implement the Provider\UserInterface and provide user functionality instead of expecting it in this base library.Grant\GrantInterface has been removed. Providers needing to provide a new grant type should extend from and override Grant\AbstractGrant.Provider\StandardProvider has been introduced, which may be used as a client to integrate with most OAuth 2.0 compatible servers.Grant\GrantFactory has been introduced as a means to register and retrieve singleton grants from a registry.Tool\BearerAuthorizationTrait and Tool\MacAuthorizationTrait), which providers may use to enable these header authorization types.FIX: Scope separators for LinkedIn and Instagram are now correctly a single space
Released: 2015-06-20
BREAK: LinkedIn Provider: Default scopes removed from LinkedIn Provider. See "Managing LinkedIn Scopes" in the README for information on how to set sc
Released: 2015-06-15
publicProfileUrl was not set, generating a PHP notice; this has been fixed.Identity Provider: Better handling of error responses
Released: 2015-04-25
FIX: Invalid JSON triggering fatal error
Released: 2015-04-02
getAccessToken() requestsProviders: Added getHeaders() to ProviderInterface and updated AbstractProvider to provide the method
Released: 2015-03-10
getHeaders() to ProviderInterface and updated AbstractProvider to provide the method$authorizationHeader propertygetResponseBody() method to IDPExceptionAdd AbstractProvider::prepareAccessTokenResult() to provide additional token response preparation to providers
Released: 2015-02-24
AbstractProvider::prepareAccessTokenResult() to provide additional token response preparation to providersAllow approval_prompt to be set by providers. This fixes an issue where some providers have problems if the approval_prompt is present in the query st
Released: 2015-02-12
approval_prompt to be set by providers. This fixes an issue where some providers have problems if the approval_prompt is present in the query string.Facebook Provider: Upgrade to Graph API v2.2
Released: 2015-02-10
access_type parameter for Google authorization URLGitHub Provider: Fix regression
Released: 2015-02-03
Google Provider: fixed issue where Google API was not returning the user ID
Released: 2015-01-06
Google Provider: Updated scopes and endpoints to remove deprecated values
Released: 2014-12-29
userUid(), userEmail(), and userScreenName())Added ability to specify a redirect handler for providers through use of a callback (see Provider\AbstractProvider::setRedirectHandler())
Released: 2014-12-03
Added ClientCredentials and Password grants
Released: 2014-11-28
ClientCredentials and Password grantsuid parameter key namehd (hosted domain) parameterstate parameter to the authorization URLpictureUrl is now an optional response element.gitattributes fileAdded ProviderInterface and removed IdentityProvider.
Released: 2014-10-28
ProviderInterface and removed IdentityProvider.League\OAuth2\Client\Provider\User to League\OAuth2\Client\Entity\User.gender and locale propertiesNothing published for this version
Nothing published for this version
Your coding agent can read these notes before it upgrades. Set up the MCP server →