NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
Packagist · #258 most downloaded on Packagist
A lightweight and powerful OAuth 2.0 authorization and resource server library with support for all the core specification grants. This library will allow you to secure your API with OAuth and allow your applications users to approve apps that want to access their data from your API.
Last release 3 months ago
25 Jun 2026
Release timing varies
gaps range from 2 weeks to 9 months
Nearly every release is documented
notes for 57 of the last 60 stable releases
Nothing withdrawn
no release was ever pulled
14 years old
116 releases · first in 2012
Ensure empty() function call only contains variable to be compatible with PHP 5.4 (PR #918)
empty() function call only contains variable to be compatible with PHP 5.4 (PR #918)Less restrictive on Authorization header check (Issue #652)
- Enable Symfony 3.0 support
One column per quarter.
Fix for determining access token in header (Issue #328)
hash_hmac() should output raw binary data, not hexits (Issue #370)Docblock, namespace and inconsistency fixes (Issue #303)
.travis.yml updatesRemove side-effects in hash_equals() implementation (Issue #290)
Changed symfony/http-foundation dependency version to ~2.4 so package can be installed in Laravel 4.1.*
symfony/http-foundation dependency version to ~2.4 so package can be installed in Laravel 4.1.*Added MAC token support (Issue #158)
Prevent duplicate session in auth code grant (Issue #282)
Ensure refresh token hasn't expired (Issue #270)
Fix bad type hintings (Issue #267)
Improved interfaces (Issue #255)
getScopeDelimiter() and setScopeDelimiter() methods have been renamedAlias the master branch in composer.json (Issue #243)
Check out the documentation - http://oauth2.thephpleague.com
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Support Authorization being an environment variable. See more
Normalize headers when getallheaders() is available (Issues #108 and #114)
getallheaders() is available (Issues #108 and #114)Forgot to tell TravisCI from testing PHP 5.3
Nothing published for this version
Nothing published for this version
Added conditional isValid() flag to check for Authorization header only (thanks @alexmcroberts)
isValid() flag to check for Authorization header only (thanks @alexmcroberts)requireScopeParam() and requireStateParam() by changing their default value to trueFixed oauth_session_token_scopes table primary key
oauth_session_token_scopes table primary keyDEFAULT '' that has slipped into some tablesSessionInterface::associateRefreshToken()Renamed primary key in oauth_client_endpoints table
Fixed a link to code in composer.json
Updated README with wiki guides
null as default parameters in some methods in the storage interfacesNothing published for this version
Fixed check for required state parameter
Added method requireStateParam()
requireStateParam()requireScopeParam()Added links to tutorials in the README
state parameter request to the checkAuthoriseParams() method.Fixed the SQL example for SessionInterface::getScopes()
Nothing published for this version
Changed all instances of the "authentication server" to "authorization server"
Fixed version number in composer.json
Updated AuthServer.php to use self::getParam()
self::getParam()[Unreleased]: https://github.com/thephpleague/oauth2-server/compare/9.4.1...HEAD [9.4.1]: https://github.com/thephpleague/oauth2-server/compare/9.4.0.
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Your coding agent can read these notes before it upgrades. Set up the MCP server →