A spec compliant, secure by default PHP OAuth 2.0 Server
Go to file
2013-09-25 16:59:45 +02:00
sql Added cascading relationship between oauth_sessions_authcodes and oauth_sessions 2013-05-10 17:32:39 -07:00
src/League/OAuth2/Server Fixed issues with returns and columns 2013-09-25 16:59:45 +02:00
tests Normalizing headers to a Ucfirst-With-Dashes format. 2013-08-20 11:40:02 -04:00
.gitattributes Added a .gitattributes file 2012-09-19 19:48:32 +01:00
.gitignore Cleaned up .gitignore 2013-03-06 17:04:31 +00:00
.travis.yml update travis 2013-07-27 06:47:10 +07:00
build.xml Don't remove composer.json and vendor dir 2012-08-06 16:13:27 +01:00
CHANGELOG.md Updated changelog 2013-06-02 13:54:54 +01:00
composer.json Added Nyan printer for the lolz 2013-07-30 10:10:59 +01:00
license.txt Updated License 2013-05-08 19:04:40 -07:00
phpunit.xml Removed all code coverage output except text to stdout 2013-09-06 10:39:08 +01:00
phpunit.xml.dist Removed printer [ci skip] 2013-07-30 10:13:47 +01:00
README.md Added badges [ci skip] 2013-07-26 11:08:24 +01:00

The League of Extraordinary Packages presents: PHP OAuth 2.0 Server

The goal of this project is to develop a standards compliant OAuth 2.0 authorization server and resource server.

Package Installation

The framework is provided as a Composer package which can be installed by adding the package to your composer.json file:

{
	"require": {
		"league/oauth2-server": "2.*"
	}
}

Master branch

Latest stable version - Latest Stable Version
Code coverage - Coverage Status
Downloads - Total Downloads

Develop branch

Latest unstable version - Latest Unstable Version
Code coverage - Coverage Status


The library features 100% unit test code coverage. To run the tests yourself run phpunit from the project root.

Current Features

Authorization Server

The authorization server is a flexible class and the following core specification grants are implemented:

An overview of the different OAuth 2.0 grants can be found in the wiki https://github.com/php-loep/oauth2-server/wiki/Which-OAuth-2.0-grant-should-I-use%3F.

Resource Server

The resource server allows you to secure your API endpoints by checking for a valid OAuth access token in the request and ensuring the token has the correct scope(s) (i.e. permissions) to access resources.

Custom grants

Custom grants can be created easily by implementing an interface. Check out a guide here https://github.com/php-loep/oauth2-server/wiki/Creating-custom-grants.

PDO driver

If you are using MySQL and want to very quickly implement the library then all of the storage interfaces have been implemented with PDO classes. Check out the guide here https://github.com/php-loep/oauth2-server/wiki/Using-the-PDO-storage-classes.

Tutorials and documentation

The wiki has lots of guides on how to use this library, check it out - https://github.com/php-loep/oauth2-server/wiki.

A tutorial on how to use the authorization server can be found on the wiki - (https://github.com/php-loep/oauth2-server/wiki/Developing-an-OAuth-2.0-authorization-server)[https://github.com/php-loep/oauth2-server/wiki/Developing-an-OAuth-2.0-authorization-server].

A tutorial on how to use the resource server to secure an API server can be found at https://github.com/php-loep/oauth2-server/wiki/Securing-your-API-with-OAuth-2.0.

Future Goals

Authorization Server


The initial code was developed as part of the Linkey project which was funded by JISC under the Access and Identity Management programme.

This code is principally developed and maintained by @alexbilbie.

A list of contributors can be found at https://github.com/php-loep/oauth2-server/contributors.