Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

iTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more

For a custom Laravel frontend, use Fortify for headless authentication flows, choose guards and providers to match the identities and requests your application supports, and decide separately how API clients authenticate. Laravel’s guidance points to Sanctum for many first-party SPA and browser-session cases; Passport is for applications that need OAuth2 features. A JWT is not a default requirement just because an app has an API.

What each Laravel authentication component does

Laravel separates the work of authenticating a request from the work of finding the user. Its authentication documentation puts it simply: “Guards define how users are authenticated for each request.” A provider retrieves the authenticatable user from persistent storage. A route can name a guard, and a custom guard can be registered when the built-in options do not fit. Laravel authentication documentation

Component Job What it does not decide
Guard Defines how a request is authenticated; route middleware can select one. Which persistent user store to query—that is the provider’s job.
Provider Retrieves an authenticatable user from the intended storage. How a request proves its identity.
Fortify Provides backend authentication routes and flows for a custom UI, including features such as registration, password reset, email verification and two-factor authentication. A custom frontend, or a default JWT issuance system.
Sanctum Supports first-party session-cookie authentication and API-token authentication. OAuth2 protocol features.
Passport Provides OAuth2 functionality when an application needs those protocol features. A universal replacement for every browser session or first-party API token.
Custom guard Extends Laravel’s authentication manager for an application-specific request-authentication method. A prescribed token format or lifecycle policy.

These components can coexist because they address different layers. Your design still needs explicit boundaries: which user population a route serves, which provider loads that identity, which guard authenticates the request, and which mechanism a client uses to carry its authentication.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Map multiple guards to identities and routes

Start by identifying distinct populations—such as customers and administrators—only if they genuinely need separate authentication boundaries. For each population, choose a provider that retrieves the right users, then configure a guard to authenticate the relevant request type. Apply the named guard to the routes it protects. A guard that points at the wrong provider can authenticate the wrong population or fail to find the expected user.

#1 Best Overall
Yubico - Security Key C NFC - Basic Compatibility - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-C or NFC, FIDO Certified
  • POWERFUL SECURITY KEY: The Security Key C NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
  • WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key C NFC secures 100 of your favorite accounts, including email, password managers, and more.
  • FAST & CONVENIENT LOGIN: Plug in your Security Key C NFC via USB-C and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
  • TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
  • BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
  • List the identities your application supports and where their records are stored.
  • Decide which routes each identity may reach, and name the intended guard on those routes.
  • Check that each guard uses the provider for that identity store.
  • Choose the guard Fortify will use with care: Fortify’s configured guard must implement IlluminateContractsAuthStatefulGuard.

Laravel documents custom guards as an extension point: register a driver with the Auth manager and return an implementation of Laravel’s guard contract. Its JWT example demonstrates that extension pattern; it does not select a JWT package or establish a token-expiry, revocation or client-storage policy. Laravel authentication documentation

Use Fortify behind a custom frontend

Fortify is a headless backend, not a frontend kit. Your interface makes requests to its authentication routes, and Fortify supplies the backend flows. Laravel’s Fortify documentation describes the arrangement this way: “If you choose to install Fortify, your user interface will make requests to Fortify’s authentication routes that are detailed in this documentation in order to authenticate and register users.” Laravel Fortify documentation

Rank #2
Yubico - YubiKey 5C NFC - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-C or NFC, FIDO Certified - Protect Your Online Accounts
  • POWERFUL SECURITY KEY: The YubiKey 5C NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
  • WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5C NFC secures 100+ of your favorite accounts, including email, password managers, and more
  • FAST & CONVENIENT LOGIN: Plug in your YubiKey 5C NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
  • MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
  • PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts

For SPA authentication, Laravel documents using Fortify with the web guard and Sanctum. This keeps the browser-facing flow centered on Laravel’s session cookie rather than requiring you to invent a JWT session. If Fortify is configured to use another guard, verify that it is compatible with Fortify’s stateful-guard requirement and with the intended identity provider. The exact configuration and route behavior should be checked against the Fortify version installed in your application.

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Choose session cookies, API tokens, OAuth2 or JWT deliberately

“API” describes how a client communicates; it does not by itself determine the authentication protocol. Choose based on who the client is, how it should authenticate, and what integrations must work.

Rank #3
Yubico - YubiKey 5 NFC - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-A or NFC, FIDO Certified - Protect Your Online Accounts
  • POWERFUL SECURITY KEY: The YubiKey 5 NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
  • WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5 NFC secures 100+ of your favorite accounts, including email, password managers, and more
  • FAST & CONVENIENT LOGIN: Plug in your YubiKey 5 NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
  • MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
  • PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts
Need Likely fit Decision to make
Your own browser SPA using Laravel authentication Sanctum with the web guard and session-cookie flow Confirm the frontend is first-party and design the browser flow around the Laravel session.
Mobile or API clients that need application-issued tokens Sanctum may fit many first-party and API-token cases Set token lifecycle and client-handling rules for the application’s needs.
Third-party clients that need OAuth2 grants or interoperability Passport Identify the OAuth2 protocol features and client relationships the integration requires.
A requirement that specifically calls for JWT behavior A custom guard or separately selected token implementation Define the token format, expiry, revocation, storage and validation policy; Laravel’s custom-guard example does not settle these choices.

Laravel’s authentication guidance describes Sanctum as the simpler fit for many first-party SPA, browser, mobile and API-token cases, and Passport as the option when OAuth2 features are required. They can coexist with browser authentication where the application has more than one client relationship. Do not add JWT machinery merely because an endpoint returns JSON. Laravel authentication documentation

Implement Fortify two-factor authentication as a login flow

The detailed flow described in Laravel 11.x Fortify documentation uses TOTP: an authenticator app generates a six-digit numeric code. The user enables two-factor authentication, scans a QR code, and confirms setup with a valid code when confirmation is configured. With confirmation enabled, enrollment is not complete until the user successfully confirms it. Recovery codes provide an alternative when the authenticator device is unavailable, so the frontend should also provide a way to view or regenerate them. By default, Fortify requires password confirmation before changing two-factor settings. Check the details against the Fortify version installed in your application. Laravel 11.x Fortify documentation

Rank #4
Yubico - Security Key NFC - Basic Compatibility - Multi-Factor Authentication (MFA) Key, Connect via USB-A or NFC, FIDO Certified
  • POWERFUL SECURITY KEY: The Security Key NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
  • WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key NFC secures 100 of your favorite accounts, including email, password managers, and more.
  • FAST & CONVENIENT LOGIN: Plug in your Security Key NFC via USB-A and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
  • TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
  • BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.

Build the UI around the challenge state

A successful password check may lead to a two-factor challenge rather than a completed login. Treat that response as a distinct state in the frontend: show a code prompt, submit the authenticator code or recovery code to the challenge endpoint, and complete the authenticated UI only after the challenge succeeds. For XHR interfaces, the Fortify documentation describes dedicated endpoints for fetching the QR code and recovery codes, and an endpoint for posting a code or recovery code to the challenge. Use the route names and payloads for your installed Fortify version rather than assuming they are identical across releases. Laravel 11.x Fortify documentation

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

The documented feature is TOTP with recovery codes. Do not present it as an SMS or email second-factor flow.

Best Value
Yubico - Security Key C NFC - Basic Compatibility - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-C or NFC, FIDO Certified (Pack of 2)
  • The information below is per-pack only
  • POWERFUL SECURITY KEY: The Security Key C NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
  • WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key C NFC secures 100 of your favorite accounts, including email, password managers, and more.
  • FAST & CONVENIENT LOGIN: Plug in your Security Key C NFC via USB-C and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
  • TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Add passkeys with WebAuthn

Laravel 13.x Fortify documentation describes passkey registration and login through WebAuthn. A passkey may use a platform authenticator—such as Face ID, Touch ID or Windows Hello—or a hardware security key; no particular authenticator is mandatory. Passkeys are public-key credentials, not passwords stored by the application. Laravel 13.x Fortify documentation

Wire the browser and server ceremony together

  1. Configure the relying-party ID, allowed origins, user-handle secret and operation timeout for the deployment.
  2. Make the user model implement Fortify’s PasskeyUser contract and use PasskeyAuthenticatable.
  3. For registration or login, request the appropriate options from the backend.
  4. Use the official @laravel/passkeys JavaScript package to perform the browser credential operation in your custom UI.
  5. Submit the serialized browser result to the backend for verification.

The relying-party ID and allowed origins must correspond to the deployed domain and origins. A mismatch can prevent the ceremony from working, so configure and verify those values for each environment. Fortify applies rate limiting to passkey routes. Laravel 13.x Fortify documentation

Choose an architecture before adding token machinery

Before implementation, write down the client relationship and the authentication boundary each client needs. Then decide how state moves between requests: session cookie, Sanctum API token, OAuth2 access flow or an explicitly justified custom JWT design. Separate customer and administrator identities only where their stores or access boundaries warrant it, and match each route’s guard to the right provider. Finally, plan the account-assurance flow: TOTP enrollment and recovery, or passkey enrollment with correct origins and a fallback path.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

These choices have different operational costs. Token designs need a policy for expiry, revocation and client storage; custom guards need ongoing maintenance; WebAuthn needs correct domain/origin configuration; and authentication and recovery paths need appropriate rate limits. Laravel’s package guidance helps distinguish Sanctum from Passport, but the target clients, threat model and integration requirements determine the right design for a particular application.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.