Skip to content
CAI
Software that uses CAICheck a score

tymondesigns/jwt-auth

48.1

Weak · 26 September 2026

5.2k

lines of production code

PHP

primary language

4

measurements over time

CAI band scale
CAI trend line
CAI lens gauges

What this system is

This release introduces comprehensive support for asymmetric signing algorithms (RSA and ECDSA) via the Lcobucci JWT provider, enabling public/private key pair authentication. The library undergoes a major architectural refactor, introducing a modular, object-oriented claims system, dedicated payload and token validators, and a configurable HTTP parser chain for flexible token extraction. Additionally, the package updates its dependencies to support Laravel 9–13 and PHP 8.0+, while adding extensive test coverage and new console commands for secret generation.

Features

Add Illuminate auth provider implementation

A new \Illuminate\ class has been added to \src/Providers/Auth/Illuminate.php\, implementing the \Tymon\\JWTAuth\\Contracts\\Providers\\Auth\ interface. This class wraps the \Illuminate\\Contracts\\Auth\\Guard\ to handle credential verification, user lookup by ID, and retrieving the authenticated user, enabling JWT-Auth to delegate authentication checks to Laravel's native guard system.

src/Providers/Auth · high confidence

Added Parser contract for HTTP request parsing

A new \Parser\ interface has been introduced in the \Tymon\\JWTAuth\\Contracts\\Http\ namespace. This contract defines a \parse\ method for extracting data from an \Illuminate\\Http\\Request\, providing a standardized way to handle HTTP request parsing within the library.

src/Contracts/Http · high confidence

Added project configuration and documentation scaffolding

The repository now includes standard configuration files to enforce code style and automate testing. An .editorconfig file defines consistent formatting rules (UTF-8, 4-space indentation), while .styleci.yml configures the StyleCI linter with the Laravel preset. A phpunit.xml.dist file is added to configure the test suite, specifying coverage exclusions for service providers and console commands. Additionally, a mkdocs.yml file establishes the structure for the project's documentation site, and a .gitattributes file ensures consistent line endings and excludes non-essential files from exports.

(repo-wide) · high confidence

Introduce Blacklist, Claim, and Payload refactoring for token invalidation and claim handling

The library introduces a new Blacklist class to manage token invalidation, supporting a configurable grace period and the ability to blacklist tokens indefinitely. A new Claim contract and associated classes provide a structured way to handle JWT claims, while the Payload class is refactored to work with a Claims Collection. These changes enable more robust token lifecycle management, including forced invalidation and persistent claim handling during token refresh.

src · high confidence

Introduce abstract service provider and framework-specific implementations

The library now provides an abstract \AbstractServiceProvider\ that defines the core registration logic and middleware aliases, with concrete \LaravelServiceProvider\ and \LumenServiceProvider\ classes handling framework-specific setup such as config publishing, middleware aliasing, and parser chain configuration. This structure allows the JWT authentication package to cleanly separate shared logic from framework-specific integrations, ensuring consistent behavior across Laravel and Lumen environments.

src/Providers · high confidence

New Facades for JWT Authentication, Payload Factory, and Provider

Users can now access JWT authentication, payload creation, and provider services via the new Laravel facades: Tymon\\JWTAuth\\Facades\\JWTAuth, JWTFactory, and JWTProvider. These classes extend Illuminate\\Support\\Facades\\Facade and map to the respective service container bindings (tymon.jwt.auth, tymon.jwt.payload.factory, and tymon.jwt.provider.jwt), enabling convenient static access to JWT-related functionality.

src/Facades · high confidence

New HTTP token parsing components and chain-based extraction

The library now extracts JWT tokens from multiple sources via a configurable parser chain. New parser classes have been introduced for headers (AuthHeaders), cookies (Cookies), query strings (QueryString), route parameters (RouteParams, LumenRouteParams), and input sources (InputSource), all sharing a common KeyTrait for key configuration. The central Parser class manages a chain of these parsers, allowing users to add, reorder, or replace parsers to control which request attribute is checked first for a token. This enables more flexible token retrieval strategies, such as decrypting cookies or handling alternative header formats.

src/Http/Parser · high confidence

New JWT secret generation command with enhanced options

A new console command, JWTGenerateSecretCommand, has been added to the src/Console directory. This command allows users to generate a new JWT secret key, with support for displaying the key without modifying files (--show), skipping generation if a key already exists (--always-no), and bypassing the confirmation prompt for overwriting (--force). The command also includes a fix to correctly handle the .env file path for older Laravel versions (pre-5.4.17) and increases the generated secret key length to 64 characters.

src/Console · high confidence

New Lcobucci-based JWT provider with asymmetric signing support

The JWT provider implementation has been replaced with a new \Lcobucci\ class that uses the \lcobucci/jwt\ library. This change adds support for asymmetric signing algorithms (RSA and ECDSA) alongside the existing symmetric ones, allowing users to configure public/private key pairs for token signing and verification.

src/Providers/JWT · high confidence

New authentication, JWT, and storage contracts introduced

The library now provides explicit interface contracts for core providers: Auth (for credential and user lookup), JWT (for encoding and decoding tokens), and Storage (for managing token blacklisting and caching). These interfaces define the expected methods for authentication, token handling, and storage operations, allowing for more flexible implementations and better testability within the JWT-Auth package.

src/Contracts/Providers · high confidence

New configuration options for asymmetric signing and persistent claims

The library now supports asymmetric signing algorithms (RSA and ECDSA) by introducing new configuration keys for public, private, and passphrase settings, allowing users to sign tokens with public/private key pairs instead of a shared secret. Additionally, the configuration file introduces a \persistent\_claims\ option, enabling users to specify which claim keys should be preserved when refreshing a token, alongside existing settings for token time-to-live, refresh time-to-live, and required claims.

config · high confidence

New exception classes for JWT validation errors

The library introduces a new hierarchy of exception classes in the src/Exceptions directory to handle specific JWT-related errors. A base JWTException class is added, from which specialized exceptions like InvalidClaimException, PayloadException, TokenBlacklistedException, TokenExpiredException, TokenInvalidException, and UserNotDefinedException are derived. This structure allows for more granular error handling and identification of specific failure modes, such as invalid claims, expired tokens, or blacklisted tokens.

src/Exceptions · high confidence

New support utilities and traits for JWT handling

The src/Support directory now includes three new files: CustomClaims.php, RefreshFlow.php, and Utils.php. The CustomClaims trait provides methods to set and retrieve custom claims on JWTs. The RefreshFlow trait manages a flag for refresh flow operations. The Utils class adds helper methods for time handling, including isPast and isFuture checks with leeway support, and static methods for current time and timestamp conversion.

src/Support · high confidence

Architecture

Refactored Claims into a modular, object-oriented structure

The Claims system has been refactored into a modular, object-oriented structure. Each JWT claim (such as 'aud', 'exp', 'iat', 'iss', 'jti', 'nbf', 'sub') is now a dedicated class extending a new abstract \Claim\ base class. A \Collection\ class manages groups of claims, and a \Factory\ handles their creation and mapping. This change introduces a \DatetimeTrait\ to standardize date/time handling for relevant claims and allows claim classes to be overridden or extended via the \Factory\'s class map.

src/Claims · high confidence

Behavioural changes

Add Laravel 5.8+ compatibility to the Illuminate storage provider

The \Illuminate\ storage provider now handles a breaking change in Laravel 5.8 and later, where the cache \put\ method expects an integer TTL in seconds rather than minutes. The provider detects the Laravel version and automatically converts the TTL from minutes to seconds for those versions, ensuring correct cache expiration behavior.

src/Providers/Storage · high confidence

Deprecates and restructures HTTP middleware classes

The HTTP middleware classes (Authenticate, AuthenticateAndRenew, BaseMiddleware, Check, and RefreshToken) have been moved to the Tymon\\JWTAuth\\Http\\Middleware namespace and marked as @deprecated. This change reorganizes the authentication and token-refresh logic into a shared BaseMiddleware and its specific implementations, while the old middleware locations are effectively superseded by this new structure.

src/Http/Middleware · high confidence

Introduce dedicated payload and token validators

The validation logic for JWTs has been refactored into two new, distinct validator classes: PayloadValidator and TokenValidator. The PayloadValidator now handles validation of the payload's structure (ensuring required claims like 'iss', 'iat', 'exp', 'nbf', 'sub', and 'jti' are present) and supports a configurable refresh TTL for token refresh flows. The TokenValidator is responsible for verifying the structural integrity of the raw token string (checking for three segments and valid formatting). Both classes implement the existing ValidatorContract, allowing the library to validate tokens and their payloads with more granular control and clearer separation of concerns.

src/Validators · high confidence

Test coverage

Add comprehensive tests for HTTP token parsing; Added comprehensive test suite for JWT-Auth core components; Added test coverage for JWT middleware components; Added test coverage for JWT payload and token validators; Added test key files for ECDSA and RSA; Added test stubs for JWT authentication scenarios; Added tests for the Illuminate storage provider; Added unit tests for JWT claim classes; Added unit tests for the Illuminate Auth provider; Added unit tests for the JWT provider implementations.

Dependencies

Support for Laravel 9–13 and PHP 8.0+

The package now requires PHP 8.0 or higher and supports Laravel 9, 10, 11, 12, and 13. It also updates the lcobucci/jwt dependency to versions 4.0 or 5.0, and nesbot/carbon to 2.69 or 3.0, ensuring compatibility with modern versions of these libraries.

(dependencies) · high confidence

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

How this codebase got here

This is the PUBLIC form of this artifact. Findings are listed in full, but the details of SECURITY findings — which rule fired, in which file, on which line, and how to fix it — are deliberately withheld, and any secret-scanner results are excluded entirely. Where detail is absent here it was REMOVED FOR PUBLICATION; it is not missing from the analysis. The complete artifact is available from the repository owner.

Score

  • CAI 44 → 48 (+4.5)
  • Rubric changed (rubric-2026.08.15 → rubric-2026.09.15) — scores are not directly comparable.

Lenses

  • Code Health 100 → 100 (+0.0)
  • Architecture 94 → 90 (-3.6)
  • Maturity 45 → 31 (-13.8)
  • Readiness 27 → 46 (+18.5)
  • Security 50 → 69 (+19.0)

Resolved (10)

  • Coverage not measured — test suite did not build
  • Dimension evaluation failed
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • LLM evaluation failed
  • No exposed public API
  • No tests found
  • Test reliability not included

New (12)

  • Dependency hygiene PARTLY measured — Composer dependencies read, no committed lock to grade for currency
  • Documentation: no installation or build instructions (README.md)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • Medium: security finding (details withheld)
  • Medium: security finding (details withheld)
  • No dependency advisory monitoring
  • Orphaned files with no living knowledge
  • Workflow token permissions not restricted

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

Survey your own repository

tymondesigns/jwt-auth was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.

About this page

  • The score is its most recent published measurement, taken on 26 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
  • Measured at commit 6c70930a92710d97e8e52b182fca2176097f33be — the exact code this score is about.
  • Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
  • Measured by watchdog.canine.dev using codehealth-analyzer preprod-a15879f6f801.