Weave Code
Code Weaver
Helps Laravel developers discover, compare, and choose open-source packages. See popularity, security, maintainers, and scores at a glance to make better decisions.
Feedback
Share your thoughts, report bugs, or suggest improvements.
Subject
Message

Jwt Auth Bundle Laravel Package

auth0/jwt-auth-bundle

Symfony bundle for Auth0 authentication and management APIs. Supports PHP 8.1+ and Symfony 6.4/7/8. Install via Composer, configure domain/client credentials and callback/logout URLs, then use the SDK for login, tokens, and user sessions.

View on GitHub
Deep Wiki
Context7
5.9.0

Full Changelog

Fixed

  • Security fix: Resolve CVE-2026-50157
5.8.0

Full Changelog

Fixed

  • Security fix: Resolve CVE-2026-34236
5.7.0

Full Changelog

Added

Fixed

5.6.0

Full Changelog

Fixed

  • Security fix: Resolve CVE-2025-68129
5.5.0

Full Changelog

Fixed

  • Security fix: Resolve CVE-2025-58769
5.4.1

Full Changelog

Fixed

5.4.0

Full Changelog

Fixed

  • Security fix: Resolve CVE-2025-47275
5.3.1

Full Changelog

Fixed

5.3.0

Full Changelog

This release includes experimental community-contributed support for Symfony 7. If you encounter any issues, please open an issue on GitHub.

Added

Changed

  • Dashes in JWT permissions/scopes are now normalized. #184 (mkilmanas)

Fixed

  • Fixed an issue in controller constructors using a $container argument. #190) (mkilmanas)
5.2.3

Full Changelog

Fixed

  • Syntax typo in AuthenticationController::__construct() #180 (mkilmanas)
  • Controller container property assignment #179 (mkilmanas)
5.2.2

Full Changelog

Fixed

  • Disallow installation with Symfony 7.0 until fully compatible
5.2.1

Full Changelog

Fixed

5.2.0

Added

  • Implement support for Back-Channel Logout #167 (evansims) ¹

Changed

  • Bumped auth0-php dependency version range to ^8.10.
  • Raised the minimum supported PHP version to 8.1.
  • Added support for Symfony ^6.4.
    • Symfony ^7.0 support will be added in a forthcoming release.

[!NOTE] ¹ To use this feature, an Auth0 tenant must have support for it enabled.

5.1.0

Added

  • Organization Name support added for Authentication API and token handling ¹

Changed

  • Bumped auth0-php dependency version range to ^8.7.
  • Updated telemetry to indicate new symfony package name (previously jwt-auth-bundle.)

Note ¹ To use this feature, an Auth0 tenant must have support for it enabled. This feature is not yet available to all tenants.

5.0.0

Full Changelog

Warning This SDK is in beta and is subject to breaking changes. It is not recommended for production use, but your feedback and help in testing is appreciated!

This release introduces PHP 8.0 support, Symfony 6.1+ support, and upgrades the bundle to use Auth0's Auth0-PHP SDK 8.x branch. It also introduces a new configuration format, full authorization support, and other improvements. Please review the updated README.md for guidance on updating your application.

4.0.0

Full Changelog

This release introduces PHP 8.0 support and upgrades the bundle to use Auth0's PHP SDK 7.x branch. It also includes expanded JWT validation options, upgraded caching support, a simplified configuration format, and other improvements.

This release includes potential breaking changes that may require minor changes to host applications to support. Please review UPGRADING.md for guidance on updating your application.

Added

  • Introduce PHP 8.0 support #108 (olix21)
  • Update to latest Auth0 PHP SDK version #108 (evansims)
    • Configuration format updated. See README for example.
    • Cache support updated to support PSR-6 or PSR-16 caches. This cache is handed off to the Auth0 PHP SDK for use in JWK fetching.
    • Added opt-in JWT validation checks around nonce, azp, org_id, and aud claims, and support for max_age and leeway checks.
    • Enforces strict typing and expands type hinting.
    • Upgrades to PHPUnit 9, and updates unit tests to support syntax changes.
    • Adds unit tests for new helper classes.
    • Adds phpcs and phpstan checks.
  • Adds support for Auth0 Organizations, currently in closed beta testing

Changed

  • Use Symfony PSR-6 > PSR-16 cache adapter #110 (darthf1)
3.4.0

Full Changelog

Added

  • Add support for autowiring #94 (dunglas)
  • Give access to the raw JWT in the user provider #97 (dunglas)

Changed

  • Remove unused argument, and unused property #95 (dunglas)
3.3.1

Full Changelog

Fixed

  • Configuration authorized_issuer string or array compatibility #89 (antzo)
3.3.0

Full Changelog

Closed issues

  • new release #86
  • Remove SimplePreAuthenticatorInterface? #80

Added

Fixed

3.2.0

Full Changelog

Added

  • GuardAuthenticator implementation for Symfony 2.8 and later #75 (niels-nijens)
3.1.0

Full Changelog

Closed issues

  • Support Symfony4 #55
  • Allow multiple audiences in config #54

Added

  • Add multiple audiences capability to JWT verification #57 (joshcanhelp)
  • Allow symfony/framework-bundle 4.x #56 (ricbra)
3.0.2

Full Changelog

Added

2.0.0

Full Changelog

Closed issues:

  • Symfony 3.0 Upgrade #24
  • ... but is not mandatory #20

Merged pull requests:

1.2.8

Full Changelog

Merged pull requests:

1.2.7

Full Changelog

Merged pull requests:

  • updated auth0-php dependency #21 (glena)
1.2.6

Full Changelog

Closed issues:

  • Setting secret_base64_encoded as false causes an exception #18
  • Installation method is incorrect #15

Merged pull requests:

  • [#18] Remove "cannotBeEmpty" property of secret_base64_encoded #19 (mickadoo)
  • Replaces scope: 'openid profile' #17 (aguerere)
1.2.5

Full Changelog

Closed issues:

  • Deps are wrong #16

Merged pull requests:

1.2.4

Full Changelog

Merged pull requests:

1.2.3

Full Changelog

Merged pull requests:

  • New info headers scheme #9 (glena)
1.2.2

Full Changelog

Merged pull requests:

  • Added optional domain config + support for auth0-php 1.0.2 #8 (glena)
1.2.1

Full Changelog

Closed issues:

  • SDK Client headers spec compliant #6

Merged pull requests:

  • SDK Client headers spec compliant #6 #7 (glena)
1.2.0

Full Changelog

Implemented enhancements:

  • Use auth0-php instead of custom implementation no Auth0Service #4
  • Auth0 settings should be optional #3
  • Remove auth0 dependency from the project #2

Closed issues:

  • Update readme #1

Merged pull requests:

  • Api v2 + SDK 1.0 support #5 (glena)
0.0.1

* This Change Log was automatically generated by github_changelog_generator

Weaver

How can I help you explore Laravel packages today?

Conversation history is not saved when not logged in.
Prompt
Add packages to context
No packages found.
terminal42/code-quality-tools
codifyo/ts-generator-bundle
andydefer/laravel-cluster
testo/fiber
mintobit/jobqueue
a4sex/maintenance-bundle
a4sex/entity-date-update
a4sex/client-identifier
a4sex/base-utilites
a4sex/key-value-storage
a4sex/micro-status
chilldev/dependency-injection-extra
datinglibre/datinglibre-app-api
biberltd/corebundle
bricre/symfony-bundle-test
biberltd/logbundle
dominium/http-adapter-bundle
dominium/google-analytics
a4sex/auto-clean-entity
christhompsontldr/laravel-inky