code16/machina

Machine to machine authentication for Laravel
1,253 3
Install
composer require code16/machina
Latest Version:v1.9.0
PHP:8.3.*|8.4.*|8.5.*
License:MIT
Last Updated:Apr 13, 2026
Links: GitHub  ·  Packagist
Maintainer: code16

Machina

This package is a wrapper around tymons\jwt-auth, aimed at providing a simple & flexible machine-to-machine authentication for Laravel 5.5+.

Installation

    composer require code16/machina

Configuration

If you want to customize some default options like the prefix used for /login and /refresh endpoints by the package, you can publish it to your application folder :

    php artisan config:publish code16/machina

Then run this command, which will add a JWT_SECRET entry in your .env file:

    php artisan jwt:secret

Defining machine guard

In config/auth.php :

    'guards' => [
        'web' => [
            'driver' => 'session',
            'provider' => 'users',
        ],

        'machina' => [
            'driver' => 'machina',
            'provider' => Api\ClientRepository::class,
        ],
    ],

Creating a ClientRepository class

This package does not come with an opinionated way of retrieving clients, but instead provides a very simple way to adapt it to your application, by providing a class implementing Code16\Machina\ClientRepositoryInterface.

Example :


    namespace App;

    use Code16\Machina\ClientRepositoryInterface;

    class ClientRepository implements ClientRepositoryInterface
    {
        public function findByKey($key)
        {
            return User::find($key);
        }

        public function findByCredentials($client, $secret)
        {
            return User::where('id', $client)->where('secret', $secret)->first();
        }

    }

Note that here we used the standard App\User model DB to identify our client, but you can use whichever model / fields you like.

Protecting routes

    Route::get('protected', 'ApiController@index')->middleware('auth:machina');

Authenticating and retrieving token

Send a POST request the /auth/login endpoint with client and secret as parameters :

    {
        client : "1",
        secret : "x7jfajleug64hggi"
    }

If the credentials are correct, the API will return a JWT token that can be used to access protected routes.

Accessing protected routes

There is two ways of passing the token along the request :

  • Passing the token in the authorization header with the following string format : Bearer <token>

  • Passing the token as a query parameter : https://app.dev/protected?token=<token>

Implementing client applications

For your client applications, you can use our companion package, machina client.

Related Packages

doctrine/dbal

Powerful PHP database abstraction layer (DBAL) with many features for database s...

637,827,751 9,703
laravel/framework

The Laravel Framework.

589,172,971 34,950
laravel/tinker

Powerful REPL for the Laravel framework.

498,216,183 7,442
laravel/serializable-closure

Laravel Serializable Closure provides an easy and secure way to serialize closur...

413,412,504 609
nunomaduro/collision

Cli error handling for console/command-line PHP applications.

394,964,158 4,660

Version History

Version Released PHP Laravel License
v1.9.0 8.3.*|8.4.*|8.5.* ^11.0|^12.0|^13.0 MIT
v1.8.0 ^8.1 ^8.0|^9.0|^10.0|^11.0|^12.0 MIT
v1.7.0 ^8.1 ^8.0|^9.0|^10.0|^11.0|^12.0 MIT
v1.6.0 ^8.1|^8.2|^8.3 ^8.0|^9.0|^10.0|^11.0 MIT
v1.5.0 ^8.1|^8.2 ^8.0|^9.0|^10.0 MIT