Authentication
Leaf Auth
Leaf Auth gives you login, registration, sessions, JWT, password hashing, user management, protected routes, and database-backed identity with a small API you can understand and extend.
Auth covers
User identity
Register, login, logout, and access the authenticated user.
Route protection
Protect pages, dashboards, APIs, and role-aware workflows.
AI-friendly setup
Auth commands and config give assistants a clear path for secure user flows.
Using Leaf MVC?
Use the MVC auth guide when you want controllers, routes, config files, and app structure.
Setting up
You can install Leaf Auth using the Leaf CLI:
leaf install authcomposer require leafs/authThe next step is to link your database and start signing users in.
Connecting to a database
To do any kind of authentication, you need to connect to some kind of database which will store your users' data. If you are already using Leaf DB or Leaf MVC, then your database connection will automatically be used by Leaf Auth, so you don't need to connect to your database again.
If you are NOT using Leaf DB or Leaf MVC, you can connect to your database manually:
auth()->connect([
'dbtype' => '...',
'charset' => '...',
'port' => '...',
'host' => '...',
'dbname' => '...',
'user' => '...',
'password' => '...'
]);$db = new PDO('mysql:dbname=test;host=127.0.0.1', 'root', '');
auth()->dbConnection($db);
// you can use leaf auth the same way you always haveDatabase Considerations
Leaf Auth doesn't give you any structure for your database, with that, you can structure your database in any way you prefer. However, there are some things you should note:
By default, Leaf Auth assumes that your database primary key is
id. If you have a database where you are using another field, sayadmin_idas the primary key, you will need to tell Leaf the name of your primary key. You can do this using theid.keyconfig:phpauth()->config('id.key', 'admin_id');php'id.key' => 'admin_id'Leaf Auth assumes that you will save your users in a database table named
users, this might however not be the case for your application. If you want to use a different table, you can configure Leaf Auth usingdb.table:phpauth()->config('db.table', 'admins');php'db.table' => 'admins'
