Skip to content

Instantly share code, notes, and snippets.

Last active April 26, 2024 02:46
Show Gist options
  • Save Haythamasalama/76193a3de446418b7edb7aec7d3a9fa6 to your computer and use it in GitHub Desktop.
Save Haythamasalama/76193a3de446418b7edb7aec7d3a9fa6 to your computer and use it in GitHub Desktop.
Setting Up Authentication for Laravel Single Page Applications (SPA)

Setting Up Authentication for Laravel Single Page Applications (SPA)

Suppose you have two websites that require authentication:

  1. localhost:8000 (backend)
  2. localhost:3000 (frontend)

Configuration Steps:

  1. Allow origins for https://localhost:3000/
  2. Set the session domain to http://localhost
  3. Configure Sanctum stateful domains for http://localhost:3000
Setting Value Format
FRONTEND_URL https://localhost:3000 schema://host:port without / at the end of the URL
SESSION_DOMAIN localhost host
SANCTUM_STATEFUL_DOMAINS localhost:3000 host:port

1. Update config/cors.php


return [
    'paths' => ['api/*', 'sanctum/csrf-cookie'],
    'allowed_methods' => ['*'],
    'allowed_origins' => [env('FRONTEND_URL', '')],
    'allowed_origins_patterns' => [],
    'allowed_headers' => ['*'],
    'exposed_headers' => [],
    'max_age' => 0,
    'supports_credentials' => true,

In allowed_origins, add the FRONTEND_URL in the format schema://hostname, such as https://localhost:3000.

2. Update config/session.php


    'domain' => env('SESSION_DOMAIN', null),

Set the SESSION_DOMAIN to the main host, e.g., localhost.

3. Update config/sanctum.php


    'stateful' => explode(',', env('SANCTUM_STATEFUL_DOMAINS', sprintf(
        env('APP_URL') ? ','.parse_url(env('APP_URL'), PHP_URL_HOST) : ''

Add SANCTUM_STATEFUL_DOMAINS only for the main host, e.g., localhost.

Update .env file


// etc...


  1. The domain in SANCTUM_STATEFUL_DOMAINS must be part of the same domain as SESSION_DOMAIN (e.g., localhost:3000 -> localhost).

  2. The default SESSION_LIFETIME is set to expire after 2 hours.

For more information, refer to the Laravel Sanctum SPA Authentication documentation.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment