thephpleague/oauth2-client
69.0
Adequate · 19 September 2026
2.4k
lines of production code
PHP
primary language
1
measurement over time
What this system is
This system is a PHP library for implementing OAuth 2.0 client-side authentication, providing a structured way to interact with identity providers. It supports standard grant types like Authorization Code and Client Credentials, allowing providers to authenticate via HTTP Basic or POST body methods. The library manages access tokens with features for expiration handling, refresh tokens, and resource owner identification, while offering reusable tools for common HTTP and data processing tasks.
How it got here
2013–2014 — League OAuth2 Client v2 migration
9 changes.
The project underwent a major refactoring to rebrand as League OAuth2 Client, migrating to PSR-4 autoloading and modernizing dependencies like Guzzle. This period introduced a new token system with refresh token support, restructured grant types with a factory pattern, and added HTTP Basic Auth capabilities for providers.
2015–2017 — Provider tooling and error handling
4 changes.
This period focused on enhancing the library's infrastructure by introducing reusable tooling traits and classes to simplify OAuth2 provider implementation. It also added comprehensive exception handling for raw provider responses and expanded unit test coverage for core HTTP and authentication components.
Features
Initial project scaffolding and documentation structure
The repository is initialized with essential project files, including a comprehensive README detailing OAuth 2.0 client usage and supported PHP versions (7.1–8.5), a CHANGELOG tracking versions from 1.0.0 to 2.9.1, and standard governance documents like CONTRIBUTING.md, CODE\_OF\_CONDUCT.md, and CREDITS.md. The build and test infrastructure is established with a PHPUnit configuration (phpunit.xml.dist) and a .gitattributes file to exclude development artifacts (tests, docs, CI configs) from distribution packages.
(repo-wide) · high confidence
Introduce HTTP Basic Auth for access token requests
Providers can now authenticate with the authorization server using HTTP Basic Authentication instead of the default POST body credentials. This is achieved by injecting an \HttpBasicAuthOptionProvider\ (which implements the new \OptionProviderInterface\) into the provider's collaborators; the provider then includes a Base64-encoded \Authorization: Basic\ header in access token requests, as specified by RFC 6749 Section 2.3.1.
src/Provider · high confidence
New AccessToken implementation with resource owner ID and refresh token support
The library introduces a new \AccessToken\ class and associated interfaces (\AccessTokenInterface\, \ResourceOwnerAccessTokenInterface\, \SettableRefreshTokenInterface\) in the \src/Token\ directory. This change allows access tokens to carry a \resource\_owner\_id\ (exposed via \getResourceOwnerId()\) and supports setting or retrieving a \refresh\_token\ (via \getRefreshToken()\ and \setRefreshToken()\). The token now handles expiration logic more robustly by accepting both \expires\_in\ and \expires\ options, automatically converting relative seconds to absolute timestamps when necessary, and includes a mechanism to check if the token has expired (\hasExpired()\). Additionally, the token implements \JsonSerializable\ to allow serialization of its properties, including the resource owner ID and refresh token, into JSON format.
src/Token · high confidence
New IdentityProviderException exposes raw response body
A new \IdentityProviderException\ class has been introduced in the \League\\OAuth2\\Client\\Provider\\Exception\ namespace to handle errors returned by identity providers. This exception captures the raw response body from the provider, making it accessible via the \getResponseBody()\ method, which allows users to inspect the specific error details returned by the OAuth2 provider rather than relying solely on the exception message.
src/Provider/Exception · high confidence
New reusable tooling traits and classes for OAuth2 providers
The src/Tool directory now provides a set of reusable components to simplify provider implementation. This includes traits for Bearer and MAC authorization headers, array navigation (dot-notation access), guarded property mass-assignment, and required parameter validation. It also introduces a query builder using RFC 3986 encoding, a redirect follower with a configurable limit, and a PSR-7 request factory, giving providers standardized ways to handle common HTTP and data-structure tasks.
src/Tool · high confidence
Removals
Removal of legacy OAuth2 client implementation
The entire legacy OAuth2 client library located in \src/OAuth/Client\ has been removed. This deletion eliminates the \IDP\ base class, the \Provider\ factory, and all specific provider implementations (including Facebook, Google, GitHub, Twitter, and others), along with their associated token classes. Users relying on this legacy \OAuth2\ namespace for authentication will no longer have access to these identity providers or the underlying client infrastructure.
src/OAuth · high confidence
Behavioural changes
Refactored grant types to use a common base class and factory
The grant implementation in src/Grant has been restructured to use a new AbstractGrant base class, which centralizes access token request parameter preparation and validation. Specific grant types (AuthorizationCode, ClientCredentials, Password, RefreshToken) now extend this base class, and a new GrantFactory has been introduced to manage and retrieve these grant instances by name, replacing the previous direct interface-based approach.
src/Grant · high confidence
Test coverage
Added unit tests for AccessToken expiration and refresh token handling; Added unit tests for HTTP Basic and Post Auth option providers; Added unit tests for OAuth2 grant types and factory; Added unit tests for Tool traits and RequestFactory; Expanded test coverage for OAuth2 Provider components.
Dependencies
Library rebranded to League OAuth2 Client with modernized dependencies
The library has been renamed from \lncd/oauth2-client\ to \league/oauth2-client\ and migrated to the \League\\OAuth2\\Client\ namespace using PSR-4 autoloading. PHP support is now restricted to versions 7.1 through 8.5, and the HTTP client dependency has been updated from the deprecated \guzzle/guzzle\ to \guzzlehttp/guzzle\ (supporting versions 6.5.8, 7.8.2, and 8.0+). The package also introduces a strict requirement for the \ext-json\ extension, updates development tools to support PHPUnit 7–11 and Mockery, and adds keywords for identity and SSO.
(dependencies) · high confidence
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
How this codebase got here
Baseline
- First survey — no prior run to compare against. CAI 69.
Lenses
- Code Health 98
- Architecture 100
- Maturity 54
- Readiness 79
- Security 77
Changes since last survey
- 300 commits — 282 feature/other, 18 fixes
By area
- (repo) — 103 commits
- docs/providers — 64 commits
- (root) — 35 commits
- docs/Gemfile.lock — 32 commits
- .github/workflows — 22 commits
- src/Provider — 9 commits
- test/src — 9 commits
- src/Token — 7 commits
- docs/usage.md — 4 commits
- docs/.ruby-version — 3 commits
- .github/dependabot.yml — 2 commits
- docs/_config.yml — 2 commits
- docs/_layouts — 2 commits
- docs/index.md — 2 commits
- src/Tool — 2 commits
- .github/ISSUE_TEMPLATE.md — 1 commit
- docs/_data — 1 commit
Notable commits
- fix: Fix Markdown link in list of 3rd-party providers
- fix: Fix TestCase class name
- fix: Fix docblock parameter type
- fix: Fix tests by returning array from PSR7's ResponseInterface::getHeader() (#1026)
- fix: Merge branch 'master' into feature/php-8.1-fix-call-to-http_build-query
- fix: Merge pull request #1000 from thephpleague/fix/netlify-build
- fix: Merge pull request #766 from thephpleague/fix/upgrade-docs
- fix: Merge pull request #767 from thephpleague/fix/docs-https-mixed
- fix: Merge pull request #768 from thephpleague/fix/docs-https-mixed
- fix: Merge pull request #769 from thephpleague/fix/docs-https-mixed
- fix: Merge pull request #801 from thephpleague/fix/update-gems
- fix: Merge pull request #919 from jrfnl/feature/php-8.1-fix-missing-return-type
- fix: Merge pull request #920 from jrfnl/feature/php-8.1-fix-call-to-http_build-query
- fix: PHP 8.1: fix deprecation notice
- fix: PHP 8.1: fix deprecation warnings / http_build_query()
- fix: Revert BC break by only providing scopes in access token when set in options (#1053)
- fix: Revert to using AccessToken instead of AccessTokenInterface
- fix: fix for invalid expires value
- change: - thirdparty: mkaverin/oauth2-donationalerts (#983)
- change: .gitignore: ignore PHPUnit cache file
- …and 280 more
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
Survey your own repository
thephpleague/oauth2-client was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.
About this page
- The score is its most recent published measurement, taken on 19 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
- Measured at commit 8cedfef9d01a8d1fd2ecfabb41734b17592c4b71 — the exact code this score is about.
- Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
- Measured by watchdog.canine.dev using codehealth-analyzer preprod-13a154b7f5d1.