intervention/httpauth

HTTP Authentication Management for PHP
14,233,277 83
Install
composer require intervention/httpauth
Latest Version:5.0.2
PHP:^8.2
License:MIT
Last Updated:Sep 26, 2026
Links: GitHub  ·  Packagist
Maintainer: olivervogel

Intervention HttpAuth

HTTP Authentication Management

Latest Version Tests Monthly Downloads Support me on Ko-fi

Installation

You can easily install this library using Composer. Just request the package with the following command:

composer require intervention/httpauth

Documentation

Read the full documentation for this library.

Usage

The workflow is easy. Just create an instance of Authenticator::class in the first step and secure your resource in the second step.

1. Create Authenticator Instance

To create authenticator instances you can choose between different methods.

Create Instance by Using Static Factory Method
use Intervention\HttpAuth\Authenticator;

// create http basic auth
$auth = Authenticator::basic(
    'myUsername',
    'myPassword',
    'Secured Area',
);

// create http digest auth
$auth = Authenticator::digest(
    'myUsername',
    'myPassword',
    'Secured Area',
);
Create Instance by Using Class Constructor
use Intervention\HttpAuth\Authenticator;

// alternatively choose DigestVault::class
$vault = new BasicVault(
    'myUsername',
    'myPassword',
    'Secured Area',
);

$auth = new Authenticator($vault);
Create Instance by Static Factory Method
use Intervention\HttpAuth\Authenticator;

// alternatively choose DigestVault::class
$vault = new BasicVault(
    'myUsername',
    'myPassword',
    'Secured Area',
);

$auth = Authenticator::withVault($vault);

2. Ask User for Credentials

After you created a HTTP authentication instance, you have to call secure() to secure the resource. This results in a 401 HTTP response and the browser asking for credentials.

$auth->secure();

A character string can optionally be passed to the method. This is displayed if authentication fails. Output from template engines can also be used here.

$auth->secure('Sorry, you can not access this resource!');

Server Configuration

Apache

If you are using Apache and running PHP with CGI/FastCGI, check the server configuration to make sure the authorization headers are passed correctly to PHP:

https://support.deskpro.com/en/kb/articles/missing-authorization-headers-with-apache

Authors

This library is developed and maintained by Oliver Vogel

Thanks to the community of contributors who have helped to improve this project.

License

Intervention HttpAuth is licensed under the MIT License.

Related Packages

sven/super-basic-auth

A lightweight package to add basic authentication to your Laravel app.

3,559 23
rinvex/laravel-authy

Rinvex Authy is a simple wrapper for Authy TOTP, the best rated Two-Factor Authe...

78,344 32
sarav/laravel-multiauth

A Simple Laravel Package for handling multiple authentication

31,297 50
php-http/laravel-httplug

Laravel package to integrate the Httplug generic HTTP client into Laravel

110,149 12
vjroby/laravel-nonce

This is a package for integrating nonces in Laravel in requests

42,757 3

Version History

Version Released PHP Laravel License
5.0.2 ^8.2 MIT
5.0.1 ^8.2 MIT
5.0.0 ^8.2 MIT
4.0.1 ^8.0 MIT
4.0.0 ^8.0 MIT
Pre-releases (6)
Version Released PHP License
4.0.0-beta2 ^8.0 MIT
4.0.0-beta1 ^8.0 MIT
3.0.0-rc.2 ^7.2 MIT
3.0.0-rc.1 ^7.2 MIT
3.0.0-beta2 ^7.2 MIT