jeremykenedy/laravel2step
| Install | |
|---|---|
composer require jeremykenedy/laravel2step |
|
| Latest Version: | v6.0.0 |
| PHP: | ^7.3|^8.0 |
| License: | MIT |
| Last Updated: | Sep 11, 2026 |
| Links: | GitHub · Packagist |
Laravel 2 Step Verification
Laravel 2-Step Verification is a package to add 2-Step user authentication to any Laravel project easily. It is configurable and customizable. It uses notifications to send the user an email with a 4-digit verification code. Can be used in out the box with Laravel's authentication scaffolding or integrated into other projects.
Table of contents:
- Features
- Requirements
- Installation Instructions
- Configuration
- Usage
- Routes
- Testing
- Screenshots
- File Tree
- Future
- Opening an Issue
- License
Features
| Laravel 2 Step Verification Features |
|---|
| Uses Notification Class to send user code to users email |
| Can publish customizable views and assets |
| Lots of configuration options |
| Uses Language localization files |
| Verificaton Page |
| Locked Page |
Requirements
- PHP 7.3+ or 8.0+
- Laravel 6+, 7+, 8+, 9+, 10+, 11+, 12+, and 13+
- For Laravel 5.8 and below see the installation instructions for the release to require.
Installation Instructions
-
From your projects root folder in terminal run:
Laravel 6+ use:
composer require jeremykenedy/laravel2stepLaravel 5.8 use:
composer require jeremykenedy/laravel2step:v1.4.0Laravel 5.7 and below use:
composer require jeremykenedy/laravel2step:v1.0.2 -
Register the package
-
Laravel 5.5 and up Uses package auto discovery feature, no need to edit the
config/app.phpfile. -
Laravel 5.4 and below Register the package with laravel in
config/app.phpunderproviderswith the following:
'providers' => [
jeremykenedy\laravel2step\laravel2stepServiceProvider::class,
];
- Publish the packages views, config file, assets, and language files by running the following from your projects root folder:
php artisan vendor:publish --tag=laravel2step
-
Optionally Update your
.envfile and associated settings (see Environment File section) -
Run the migration to add the verifications codes table:
php artisan migrate
- Note: If you want to specify a different table or connection make sure you update your
.envfile with the needed configuration variables.
- Make sure your apps email is configured - this is usually done by configuring the Laravel out the box settings in the
.envfile.
Configuration
Laravel 2-Step Verification can be configured in directly in /config/laravel2step.php or in the variables in your .env file.
Environment File
Here are the .env file variables available:
LARAVEL_2STEP_ENABLED=true
LARAVEL_2STEP_DATABASE_TABLE=laravel2step
LARAVEL_2STEP_USER_MODEL=App\Models\User
LARAVEL_2STEP_EMAIL_FROM_NAME="Laravel 2 Step Verification"
LARAVEL_2STEP_EXCEEDED_COUNT=3
LARAVEL_2STEP_EXCEEDED_COUNTDOWN_MINUTES=1440
LARAVEL_2STEP_VERIFIED_LIFETIME_MINUTES=360
LARAVEL_2STEP_RESET_BUFFER_IN_SECONDS=360
LARAVEL_2STEP_CSS_FILE="css/laravel2step/app.css"
LARAVEL_2STEP_APP_CSS_ENABLED=false
LARAVEL_2STEP_APP_CSS="css/app.css"
LARAVEL_2STEP_BOOTSTRAP_CSS_CDN_ENABLED=true
LARAVEL_2STEP_BOOTSTRAP_CSS_CDN="https://cdnjs.cloudflare.com/ajax/libs/twitter-bootstrap/3.4.1/css/bootstrap.min.css"
# Optional. Defaults to your application's default database connection.
# LARAVEL_2STEP_DATABASE_CONNECTION=mysql
# Optional. Defaults to your application's MAIL_FROM_ADDRESS.
# LARAVEL_2STEP_EMAIL_FROM="verification@example.com"
# Optional. Send the verification email on a named queue.
# LARAVEL_2STEP_EMAIL_QUEUE=notifications
Usage
Laravel 2-Step Verification is enabled via middleware. You can enable 2-Step Verification in your routes and controllers via the following middleware:
twostep
Example to start recording page views using middlware in web.php:
Route::group(['middleware' => ['twostep']], function () {
Route::get('/home', 'HomeController@index')->name('home');
});
Two step verification is supported on your application's default guard, which is Laravel's session based web guard unless you changed it. The twostep middleware needs a session, since it stores where the user was headed, so it belongs on routes in the web group.
If you protect web group routes with another guard, for example ['auth:sanctum', 'twostep'], an unverified user is still blocked, because Laravel's middleware priority runs auth ahead of this package's middleware. That user cannot complete verification though: /verification/needed authenticates on the default guard, so they are sent to your login route instead of the verification form.
Routes
/verification/needed/verification/verify/verification/resend
Testing
The package ships with a Pest suite that runs against an in memory SQLite database, so it never touches a real database.
composer install
composer test
Running the suite needs PHP 8.2 or higher, because Pest and Pint do not run on anything older. That is a requirement for working on the package, not for using it: the package itself still installs on PHP 7.3 and up.
Code style is checked with Laravel Pint:
composer lint
GitHub Actions runs on every pull request, on pushes to master, and again every Monday so a new Laravel release cannot break the package quietly:
| Job | What it covers |
|---|---|
| Tests | Laravel 12 on PHP 8.2 to 8.5, Laravel 13 on PHP 8.3 to 8.5 |
| Lowest dependencies | The oldest dependency versions that resolve against Laravel 12 |
| Code style | composer validate --strict and pint --test |
| Security audit | composer audit against known advisories |
Laravel 11 and below are still supported by the composer constraints, but they cannot be installed on a clean runner anymore, because composer blocks the framework releases that carry published security advisories.
Screenshots

File Tree
└── laravel2step
├── .gitattributes
├── .github
│ ├── dependabot.yml
│ ├── FUNDING.yml
│ └── workflows
│ └── tests.yml
├── .gitignore
├── .scrutinizer.yml
├── art
│ ├── banner-dark.svg
│ └── banner-light.svg
├── composer.json
├── LICENSE
├── phpunit.xml
├── pint.json
├── README.md
├── src
│ ├── .env.example
│ ├── App
│ │ ├── Http
│ │ │ ├── Controllers
│ │ │ │ └── TwoStepController.php
│ │ │ └── Middleware
│ │ │ └── Laravel2step.php
│ │ ├── Models
│ │ │ └── TwoStepAuth.php
│ │ ├── Notifications
│ │ │ └── SendVerificationCodeEmail.php
│ │ └── Traits
│ │ └── Laravel2StepTrait.php
│ ├── config
│ │ └── laravel2step.php
│ ├── database
│ │ └── migrations
│ │ └── 2017_12_09_070937_create_two_step_auth_table.php
│ ├── Laravel2stepFacade.php
│ ├── Laravel2stepServiceProvider.php
│ ├── public
│ │ └── css
│ │ ├── app.css
│ │ └── app.min.css
│ ├── resources
│ │ ├── assets
│ │ │ └── scss
│ │ │ ├── _animations.scss
│ │ │ ├── _mixins.scss
│ │ │ ├── _modals.scss
│ │ │ ├── _variables.scss
│ │ │ ├── _verification.scss
│ │ │ └── app.scss
│ │ ├── lang
│ │ │ └── en
│ │ │ └── laravel-verification.php
│ │ └── views
│ │ ├── layouts
│ │ │ └── app.blade.php
│ │ ├── scripts
│ │ │ └── input-parsing-auto-stepper.blade.php
│ │ └── twostep
│ │ ├── exceeded.blade.php
│ │ └── verification.blade.php
│ └── routes
│ └── web.php
└── tests
├── Feature
│ ├── MiddlewareTest.php
│ ├── SendVerificationCodeEmailTest.php
│ └── TwoStepControllerTest.php
├── Models
│ └── User.php
├── Pest.php
├── Support
│ ├── RouteSpy.php
│ └── TwoStepTester.php
├── TestCase.php
└── Unit
├── ConfigTest.php
├── Laravel2StepTraitTest.php
├── ServiceProviderTest.php
└── TwoStepAuthModelTest.php
- Tree command can be installed using brew:
brew install tree - File tree generated using command
tree -a -I '.git|node_modules|vendor|storage|composer.lock'
Future
- Its own HTML email template.
- Add in additional notifications for SMS or ???.
- Add in capture IP Address.
- Change to incremental tables and logic accordingly
- Create Artisan command and job to prune said entries.
Opening an Issue
Before opening an issue there are a couple of considerations:
- You are all awesome!
- Read the instructions and make sure all steps were followed correctly.
- Check that the issue is not specific to your development environment setup.
- Provide duplication steps.
- Attempt to look into the issue, and if you have a solution, make a pull request.
- Show that you have made an attempt to look into the issue.
- Check to see if the issue you are reporting is a duplicate of a previous reported issue.
- Following these instructions show me that you have tried.
- If you have a questions send me an email to jeremykenedy@gmail.com
- Need some help, I can do my best on Slack: https://opensourcehelpgroup.slack.com
- Please be considerate that this is an open source project that I provide to the community for FREE when openeing an issue.
Open source projects are a the community’s responsibility to use, contribute, and debug.
License
Laravel 2-Step Verification is licensed under the MIT license. Enjoy!
Related Packages
Rinvex Authy is a simple wrapper for Authy TOTP, the best rated Two-Factor Authe...
A simple way to authenticate a user using a verification code.

