class Sanctum

Constants

DEFAULT_CACHE_TTL

DEFAULT_LAST_USED_AT_UPDATE_INTERVAL

protected DEFAULT_PERSONAL_ACCESS_TOKEN_MODEL

protected DEFAULT_CURRENT_REQUEST_HOST_PLACEHOLDER

Properties

static PersonalAccessToken> $personalAccessTokenModel

The personal access client model class name.

static null|callable $accessTokenRetrievalCallback

A callback that can get the token from the request.

static null|callable $accessTokenAuthenticationCallback

A callback that can add to the validation of the access token.

static string $currentRequestHostPlaceholder

A placeholder to instruct Sanctum to include the current request host in the list of stateful domains.

Methods

static string
currentApplicationUrlWithPort()

Get the current application URL from the "APP_URL" environment variable - with port.

static string
currentRequestHost()

Get a fixed token instructing Sanctum to include the current request host in the list of stateful domains.

static bool
supportsTokens(Authenticatable|null $tokenable)

Determine if the authenticatable model supports API tokens.

static Authenticatable
actingAs(Authenticatable $user, array $abilities = [], string $guard = 'sanctum')

Set the current user for the application with the given abilities.

static void
usePersonalAccessTokenModel(string $model)

Set the personal access token model name.

static void
getAccessTokenFromRequestUsing(callable|null $callback)

Specify a callback that should be used to fetch the access token from the request.

static void
authenticateAccessTokensUsing(callable $callback)

Specify a callback that should be used to authenticate access tokens.

static string
personalAccessTokenModel()

Get the token model class name.

static void
flushState()

Flush all static state.

Details

at line 56
static string currentApplicationUrlWithPort()

Get the current application URL from the "APP_URL" environment variable - with port.

Return Value

string

at line 66
static string currentRequestHost()

Get a fixed token instructing Sanctum to include the current request host in the list of stateful domains.

Return Value

string

at line 74
static bool supportsTokens(Authenticatable|null $tokenable)

Determine if the authenticatable model supports API tokens.

Parameters

Authenticatable|null $tokenable

Return Value

bool

at line 92
static Authenticatable actingAs(Authenticatable $user, array $abilities = [], string $guard = 'sanctum')

Set the current user for the application with the given abilities.

Tests only. This installs a Mockery token double and replaces the current coroutine's authenticated user and default guard with test state.

Parameters

Authenticatable $user
array $abilities
string $guard

Return Value

Authenticatable

at line 131
static void usePersonalAccessTokenModel(string $model)

Set the personal access token model name.

Boot-only. The model class name persists in a static property for the worker lifetime and is used for every token resolution across all coroutines.

Parameters

string $model

Return Value

void

at line 142
static void getAccessTokenFromRequestUsing(callable|null $callback)

Specify a callback that should be used to fetch the access token from the request.

Boot-only. The callback persists in a static property for the worker lifetime and runs on every token retrieval across all coroutines.

Parameters

callable|null $callback

Return Value

void

at line 153
static void authenticateAccessTokensUsing(callable $callback)

Specify a callback that should be used to authenticate access tokens.

Boot-only. The callback persists in a static property for the worker lifetime and runs on every token authentication across all coroutines.

Parameters

callable $callback

Return Value

void

at line 163
static string personalAccessTokenModel()

Get the token model class name.

Return Value

string

at line 171
static void flushState()

Flush all static state.

Return Value

void