Laravel Sanctum vs Passport: Which One to Choose?

One of the most common questions when building an API with Laravel is: Sanctum or Passport? Both are official Laravel packages for API authentication, but they have different purpo...

Laravel Sanctum vs Passport: Which One to Choose?
Advertisement

One of the most common questions when building an API with Laravel is: Sanctum or Passport? Both are official Laravel packages for API authentication, but they have different purposes and ways of working. Choosing the wrong one can make development more complicated than it needs to be. This article will help you understand the differences in depth.

What Is Laravel Sanctum?

Laravel Sanctum is a lightweight, simple authentication system. Sanctum is designed for two main use cases:

  • SPA (Single Page Application) — such as Vue.js or React communicating with a Laravel backend.
  • Mobile apps / simple token-based APIs — tokens are stored in a database table.

Sanctum uses cookie-based sessions for SPAs and personal access tokens for mobile/simple APIs. There is no OAuth2 implementation here.

Advertisement

What Is Laravel Passport?

Laravel Passport is a full OAuth2 server implementation for Laravel. Passport uses the league/oauth2-server library under the hood. Passport is a good fit for:

  • APIs accessed by third-party clients.
  • Scenarios that require OAuth2 grant types: authorization code, client credentials, password grant, and so on.
  • Large platforms that need granular OAuth2 token management.

Comparing the Key Features

  • Complexity: Sanctum is very lightweight; Passport is more complex because of its full OAuth2 implementation.
  • Token Storage: Sanctum stores tokens in the personal_access_tokens table; Passport uses several OAuth2 tables.
  • Scope/Permission: Both support token scopes/abilities, but Passport is more complete.
  • Refresh Token: Only Passport supports refresh tokens natively.
  • Third-party OAuth: Only Passport can act as an OAuth2 provider for external applications.

When to Use Sanctum?

Use Sanctum if:

  1. You're building an SPA (Vue/React) that consumes your own Laravel API.
  2. You're building a mobile app that only needs login and a simple token.
  3. You don't need to be an OAuth2 provider for third parties.
  4. You want a fast, lightweight setup.

Installing and Configuring Sanctum

composer require laravel/sanctum
php artisan vendor:publish --provider="Laravel\Sanctum\SanctumServiceProvider"
php artisan migrate

Add the HasApiTokens trait to the User model:

<?php

namespace App\Models;

use Laravel\Sanctum\HasApiTokens;
use Illuminate\Foundation\Auth\User as Authenticatable;

class User extends Authenticatable
{
    use HasApiTokens;
    // ...
}

Example of login and issuing a token with Sanctum:

Advertisement
// routes/api.php
Route::post('/login', function (Request $request) {
    $request->validate([
        'email'    => 'required|email',
        'password' => 'required',
    ]);

    $user = User::where('email', $request->email)->first();

    if (! $user || ! Hash::check($request->password, $user->password)) {
        return response()->json(['message' => 'Invalid credentials'], 401);
    }

    $token = $user->createToken('api-token')->plainTextToken;

    return response()->json(['token' => $token]);
});

// Protect routes
Route::middleware('auth:sanctum')->get('/user', function (Request $request) {
    return $request->user();
});

When to Use Passport?

Use Passport if:

  1. Your API will be accessed by third-party applications you don't control.
  2. You need an authorization code flow (such as "Login with YourApp").
  3. You need automatic refresh tokens.
  4. You're building an enterprise-scale platform with OAuth2 client management.

Installing and Configuring Passport

composer require laravel/passport
php artisan migrate
php artisan passport:install

Add Passport's HasApiTokens trait to the User model:

<?php

namespace App\Models;

use Laravel\Passport\HasApiTokens;
use Illuminate\Foundation\Auth\User as Authenticatable;

class User extends Authenticatable
{
    use HasApiTokens;
    // ...
}

Register Passport in AuthServiceProvider (Laravel 10 and below):

use Laravel\Passport\Passport;

public function boot(): void
{
    Passport::tokensExpireIn(now()->addDays(15));
    Passport::refreshTokensExpireIn(now()->addDays(30));
}

Update the guard in config/auth.php:

'guards' => [
    'api' => [
        'driver'   => 'passport',
        'provider' => 'users',
    ],
],

Comparison Summary

  • Sanctum: Lightweight, ideal for your own SPA & mobile app, fast setup, no OAuth2 needed.
  • Passport: Full-featured, ideal as an OAuth2 provider, third-party integration, supports refresh tokens.

Conclusion

For most modern Laravel projects — especially an SPA or mobile app that consumes your own Laravel API — Sanctum is the right choice. Choose Passport only if you genuinely need full OAuth2 features, such as acting as a provider for third-party applications. Don't over-engineer: use the simplest tool that meets your needs.

Advertisement
laravel sanctum laravel passport autentikasi api laravel sanctum vs passport laravel token api oauth2 laravel
Share this article
Back to Blog
🚀 Partner Recommendation

Need Premium Source Code & Business Apps?

Access Laravel applications, POS systems, School Management, Clinic Software, ERP solutions, and ready-to-use premium source code at GudangCode.

GudangCode
  • ✔ Premium Source Code
  • ✔ Ready-to-Use Systems
  • ✔ Lifetime Updates
  • ✔ Lifetime Membership
  • ✔ Daily App Updates
Join Membership →
Advertisement
Advertisement