tymondesigns/jwt-auth
48.1
Weak · 26 September 2026
5.2k
lines of production code
PHP
primary language
4
measurements over time
What this system is
This release introduces comprehensive support for asymmetric signing algorithms (RSA and ECDSA) via the Lcobucci JWT provider, enabling public/private key pair authentication. The library undergoes a major architectural refactor, introducing a modular, object-oriented claims system, dedicated payload and token validators, and a configurable HTTP parser chain for flexible token extraction. Additionally, the package updates its dependencies to support Laravel 9–13 and PHP 8.0+, while adding extensive test coverage and new console commands for secret generation.
Features
Add Illuminate auth provider implementation
A new \Illuminate\ class has been added to \src/Providers/Auth/Illuminate.php\, implementing the \Tymon\\JWTAuth\\Contracts\\Providers\\Auth\ interface. This class wraps the \Illuminate\\Contracts\\Auth\\Guard\ to handle credential verification, user lookup by ID, and retrieving the authenticated user, enabling JWT-Auth to delegate authentication checks to Laravel's native guard system.
src/Providers/Auth · high confidence
Added Parser contract for HTTP request parsing
A new \Parser\ interface has been introduced in the \Tymon\\JWTAuth\\Contracts\\Http\ namespace. This contract defines a \parse\ method for extracting data from an \Illuminate\\Http\\Request\, providing a standardized way to handle HTTP request parsing within the library.
src/Contracts/Http · high confidence
Added project configuration and documentation scaffolding
The repository now includes standard configuration files to enforce code style and automate testing. An .editorconfig file defines consistent formatting rules (UTF-8, 4-space indentation), while .styleci.yml configures the StyleCI linter with the Laravel preset. A phpunit.xml.dist file is added to configure the test suite, specifying coverage exclusions for service providers and console commands. Additionally, a mkdocs.yml file establishes the structure for the project's documentation site, and a .gitattributes file ensures consistent line endings and excludes non-essential files from exports.
(repo-wide) · high confidence
Introduce Blacklist, Claim, and Payload refactoring for token invalidation and claim handling
The library introduces a new Blacklist class to manage token invalidation, supporting a configurable grace period and the ability to blacklist tokens indefinitely. A new Claim contract and associated classes provide a structured way to handle JWT claims, while the Payload class is refactored to work with a Claims Collection. These changes enable more robust token lifecycle management, including forced invalidation and persistent claim handling during token refresh.
src · high confidence
Introduce abstract service provider and framework-specific implementations
The library now provides an abstract \AbstractServiceProvider\ that defines the core registration logic and middleware aliases, with concrete \LaravelServiceProvider\ and \LumenServiceProvider\ classes handling framework-specific setup such as config publishing, middleware aliasing, and parser chain configuration. This structure allows the JWT authentication package to cleanly separate shared logic from framework-specific integrations, ensuring consistent behavior across Laravel and Lumen environments.
src/Providers · high confidence
New Facades for JWT Authentication, Payload Factory, and Provider
Users can now access JWT authentication, payload creation, and provider services via the new Laravel facades: Tymon\\JWTAuth\\Facades\\JWTAuth, JWTFactory, and JWTProvider. These classes extend Illuminate\\Support\\Facades\\Facade and map to the respective service container bindings (tymon.jwt.auth, tymon.jwt.payload.factory, and tymon.jwt.provider.jwt), enabling convenient static access to JWT-related functionality.
src/Facades · high confidence
New HTTP token parsing components and chain-based extraction
The library now extracts JWT tokens from multiple sources via a configurable parser chain. New parser classes have been introduced for headers (AuthHeaders), cookies (Cookies), query strings (QueryString), route parameters (RouteParams, LumenRouteParams), and input sources (InputSource), all sharing a common KeyTrait for key configuration. The central Parser class manages a chain of these parsers, allowing users to add, reorder, or replace parsers to control which request attribute is checked first for a token. This enables more flexible token retrieval strategies, such as decrypting cookies or handling alternative header formats.
src/Http/Parser · high confidence
New JWT secret generation command with enhanced options
A new console command, JWTGenerateSecretCommand, has been added to the src/Console directory. This command allows users to generate a new JWT secret key, with support for displaying the key without modifying files (--show), skipping generation if a key already exists (--always-no), and bypassing the confirmation prompt for overwriting (--force). The command also includes a fix to correctly handle the .env file path for older Laravel versions (pre-5.4.17) and increases the generated secret key length to 64 characters.
src/Console · high confidence
New Lcobucci-based JWT provider with asymmetric signing support
The JWT provider implementation has been replaced with a new \Lcobucci\ class that uses the \lcobucci/jwt\ library. This change adds support for asymmetric signing algorithms (RSA and ECDSA) alongside the existing symmetric ones, allowing users to configure public/private key pairs for token signing and verification.
src/Providers/JWT · high confidence
New authentication, JWT, and storage contracts introduced
The library now provides explicit interface contracts for core providers: Auth (for credential and user lookup), JWT (for encoding and decoding tokens), and Storage (for managing token blacklisting and caching). These interfaces define the expected methods for authentication, token handling, and storage operations, allowing for more flexible implementations and better testability within the JWT-Auth package.
src/Contracts/Providers · high confidence
New configuration options for asymmetric signing and persistent claims
The library now supports asymmetric signing algorithms (RSA and ECDSA) by introducing new configuration keys for public, private, and passphrase settings, allowing users to sign tokens with public/private key pairs instead of a shared secret. Additionally, the configuration file introduces a \persistent\_claims\ option, enabling users to specify which claim keys should be preserved when refreshing a token, alongside existing settings for token time-to-live, refresh time-to-live, and required claims.
config · high confidence
New exception classes for JWT validation errors
The library introduces a new hierarchy of exception classes in the src/Exceptions directory to handle specific JWT-related errors. A base JWTException class is added, from which specialized exceptions like InvalidClaimException, PayloadException, TokenBlacklistedException, TokenExpiredException, TokenInvalidException, and UserNotDefinedException are derived. This structure allows for more granular error handling and identification of specific failure modes, such as invalid claims, expired tokens, or blacklisted tokens.
src/Exceptions · high confidence
New support utilities and traits for JWT handling
The src/Support directory now includes three new files: CustomClaims.php, RefreshFlow.php, and Utils.php. The CustomClaims trait provides methods to set and retrieve custom claims on JWTs. The RefreshFlow trait manages a flag for refresh flow operations. The Utils class adds helper methods for time handling, including isPast and isFuture checks with leeway support, and static methods for current time and timestamp conversion.
src/Support · high confidence
Architecture
Refactored Claims into a modular, object-oriented structure
The Claims system has been refactored into a modular, object-oriented structure. Each JWT claim (such as 'aud', 'exp', 'iat', 'iss', 'jti', 'nbf', 'sub') is now a dedicated class extending a new abstract \Claim\ base class. A \Collection\ class manages groups of claims, and a \Factory\ handles their creation and mapping. This change introduces a \DatetimeTrait\ to standardize date/time handling for relevant claims and allows claim classes to be overridden or extended via the \Factory\'s class map.
src/Claims · high confidence
Behavioural changes
Add Laravel 5.8+ compatibility to the Illuminate storage provider
The \Illuminate\ storage provider now handles a breaking change in Laravel 5.8 and later, where the cache \put\ method expects an integer TTL in seconds rather than minutes. The provider detects the Laravel version and automatically converts the TTL from minutes to seconds for those versions, ensuring correct cache expiration behavior.
src/Providers/Storage · high confidence
Deprecates and restructures HTTP middleware classes
The HTTP middleware classes (Authenticate, AuthenticateAndRenew, BaseMiddleware, Check, and RefreshToken) have been moved to the Tymon\\JWTAuth\\Http\\Middleware namespace and marked as @deprecated. This change reorganizes the authentication and token-refresh logic into a shared BaseMiddleware and its specific implementations, while the old middleware locations are effectively superseded by this new structure.
src/Http/Middleware · high confidence
Introduce dedicated payload and token validators
The validation logic for JWTs has been refactored into two new, distinct validator classes: PayloadValidator and TokenValidator. The PayloadValidator now handles validation of the payload's structure (ensuring required claims like 'iss', 'iat', 'exp', 'nbf', 'sub', and 'jti' are present) and supports a configurable refresh TTL for token refresh flows. The TokenValidator is responsible for verifying the structural integrity of the raw token string (checking for three segments and valid formatting). Both classes implement the existing ValidatorContract, allowing the library to validate tokens and their payloads with more granular control and clearer separation of concerns.
src/Validators · high confidence
Test coverage
Add comprehensive tests for HTTP token parsing; Added comprehensive test suite for JWT-Auth core components; Added test coverage for JWT middleware components; Added test coverage for JWT payload and token validators; Added test key files for ECDSA and RSA; Added test stubs for JWT authentication scenarios; Added tests for the Illuminate storage provider; Added unit tests for JWT claim classes; Added unit tests for the Illuminate Auth provider; Added unit tests for the JWT provider implementations.
Dependencies
Support for Laravel 9–13 and PHP 8.0+
The package now requires PHP 8.0 or higher and supports Laravel 9, 10, 11, 12, and 13. It also updates the lcobucci/jwt dependency to versions 4.0 or 5.0, and nesbot/carbon to 2.69 or 3.0, ensuring compatibility with modern versions of these libraries.
(dependencies) · high confidence
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
How this codebase got here
This is the PUBLIC form of this artifact. Findings are listed in full, but the details of SECURITY findings — which rule fired, in which file, on which line, and how to fix it — are deliberately withheld, and any secret-scanner results are excluded entirely. Where detail is absent here it was REMOVED FOR PUBLICATION; it is not missing from the analysis. The complete artifact is available from the repository owner.
Score
- CAI 44 → 48 (+4.5)
- Rubric changed (rubric-2026.08.15 → rubric-2026.09.15) — scores are not directly comparable.
Lenses
- Code Health 100 → 100 (+0.0)
- Architecture 94 → 90 (-3.6)
- Maturity 45 → 31 (-13.8)
- Readiness 27 → 46 (+18.5)
- Security 50 → 69 (+19.0)
Resolved (10)
- Coverage not measured — test suite did not build
- Dimension evaluation failed
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- LLM evaluation failed
- No exposed public API
- No tests found
- Test reliability not included
New (12)
- Dependency hygiene PARTLY measured — Composer dependencies read, no committed lock to grade for currency
- Documentation: no installation or build instructions (README.md)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- Medium: security finding (details withheld)
- Medium: security finding (details withheld)
- No dependency advisory monitoring
- Orphaned files with no living knowledge
- Workflow token permissions not restricted
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
Survey your own repository
tymondesigns/jwt-auth was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.
About this page
- The score is its most recent published measurement, taken on 26 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
- Measured at commit 6c70930a92710d97e8e52b182fca2176097f33be — the exact code this score is about.
- Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
- Measured by watchdog.canine.dev using codehealth-analyzer preprod-a15879f6f801.