cboxdk/laravel-id is a Laravel-native auth and identity framework. Central login,
enterprise SSO, directory sync, RBAC, billing-driven entitlements and a tamper-evident audit
trail: all interface-driven, deny-by-default, and verified (tests + PHPStan level max +
composer audit) before it ships.
UI-free and domain-free: every capability sits behind a contract you bind, mock, extend or replace.
composer require cboxdk/laravel-id
php -r "echo base64_encode(random_bytes(32)).PHP_EOL;" # set as CBOX_ID_CRYPTO_KEY
php artisan migrateuse Cbox\Id\Organization\Contracts\Organizations;
use Cbox\Id\Organization\ValueObjects\NewOrganization;
use Cbox\Id\Identity\Contracts\Subjects;
$org = app(Organizations::class)->create(new NewOrganization('Northwind', 'northwind'));
$user = app(Subjects::class)->create('ida@northwind.test', 'Ida', password: 's3cret');Environments first.
Organization,Userand the other domain models are environment-owned and deny-by-default — the calls above need an environment in context (a request resolves one from its host, or setcbox-id.environments.default; the deployable app creates the first one from its operator console). See Environments & the isolation model.
| Layer | Modules |
|---|---|
| Kernels | Tenancy · Crypto · Audit · Events · Authorization |
| Domain | Organization · Identity · AccessControl · Directory (SCIM) · Federation (SSO) · OAuthServer (OAuth 2.0 / OIDC provider) · Webhooks · AuditQuery |
| HTTP & ops | Api (OAuth/OIDC/SCIM endpoints) · Platform (operators + the self-serve account/project/billing plane) · Console (cbox-id:install / cbox-id:doctor) |
Full docs live in docs/:
- Requirements · Installation · Quickstart
- Architecture & patterns
- Cookbook
- Extending & customizing
- Testing
- Security ·
SECURITY.md - Standards & conformance — RFCs implemented (OAuth/OIDC/SCIM/SAML/MCP)
- Compliance mapping — SOC 2 / ISO 27001 / NIS2 / GDPR / HIPAA / PCI-DSS · Threat model
MIT. Published on Packagist as a pre-1.0 (0.x) release — installable via composer require cboxdk/laravel-id; the API may still shift before 1.0.