Looking to hire Laravel developers? Try LaraJobs

crypto-for-laravel maintained by roundly-consulting

Description
Native, audited cryptographic and encoding primitives for Laravel: JWS/JOSE, TOTP/HOTP, WebAuthn signature verification, HMAC, authenticated encryption (AES-256-GCM), CSPRNG tokens, and codecs — zero-config, à la carte.
Last update
2026/10/03 19:58 (dev-main)
License
Downloads
0

Comments
comments powered by Disqus

Cryptographic Primitives for Laravel

Native cryptographic and encoding primitives for Laravel — JWS/JOSE and JWK, TOTP/HOTP, WebAuthn signature verification, HMAC, AES-256-GCM authenticated encryption, X.509, CSPRNG tokens and codecs — with zero third-party crypto dependencies. It is zero-config: every key is an explicit argument, and every primitive works on its own.

Installation

Requires PHP 8.4 (ext-openssl, ext-hash, ext-mbstring; ext-sodium for Ed25519), Laravel 12 or 13.

composer require roundly-consulting/crypto-for-laravel

Usage

Sign and verify a token — the algorithm is always pinned, never read from the token:

use RoundlyConsulting\Crypto\Facades\Crypto;
use RoundlyConsulting\Crypto\Signature\Algorithm;

$key = Crypto::keys()->ec()->fromStorageOrGenerate('local', 'keys/jwt.pem'); // P-256, created on first boot

$token = Crypto::jws()->sign(
    ['kid' => 'k1'],
    ['sub' => 'alice', 'exp' => now()->addHour()->timestamp],
    Crypto::es($key),
);

$claims = Crypto::jws()->verify($token, Crypto::es($key), Algorithm::ES256);
$claims->assertTemporal(leeway: 30);   // throws once expired
$claims->string('sub');                // "alice"

Check a webhook, encrypt a value bound to its record, and verify a one-time password:

$expected = 'sha256='.Crypto::hmac()->signHex($request->getContent(), $webhookSecret);
Crypto::constantTimeEquals($expected, $request->header('X-Hub-Signature-256', ''));

$dataKey = Crypto::randomBytes(32);
$sealed = Crypto::aes256Gcm()->seal($dataKey, $iban, associatedData: 'invoices:42');
$iban = Crypto::aes256Gcm()->open($dataKey, $sealed, associatedData: 'invoices:42');

$secret = Crypto::randomSecret();      // base32, for an authenticator app
Crypto::provisioningUri($secret, 'alice@example.com', 'Acme Inc');
Crypto::totp()->verify($secret, $code); // the matched time step, or false

Documentation

The full documentation — configuration, every feature and its API, and testing — lives on our website: roundly-consulting.com/open-source/docs/crypto-for-laravel

Release notes are in CHANGELOG.md. To contribute, see the contributing guide.

Support our work

This package is free and open source, built and maintained by Roundly Consulting. If it saves you time, please consider supporting our open-source work — a one-time donation, a monthly pledge on Patreon or a crypto donation helps fund maintenance, new features and new packages.

License

The MIT License (MIT). See LICENSE.md.