Bird
Raised Fist0
Laravelframework~20 mins

API authentication with Sanctum in Laravel - Practice Problems & Coding Challenges

Choose your learning style10 modes available

Start learning this pattern below

Jump into concepts and practice - no test required

or
Recommended
Test this pattern10 questions across easy, medium, and hard to know if this pattern is strong
Challenge - 5 Problems
🎖️
Sanctum Mastery
Get all challenges correct to earn this badge!
Test your skills under time pressure!
❓ component_behavior
intermediate
2:00remaining
What is the output of this Sanctum token creation code?
Consider this Laravel controller method using Sanctum to create a token for a user. What will be the output JSON response?
Laravel
public function login(Request $request) {
    $user = User::where('email', $request->email)->first();
    if (! $user || ! Hash::check($request->password, $user->password)) {
        return response()->json(['message' => 'Invalid credentials'], 401);
    }
    $token = $user->createToken('api-token')->plainTextToken;
    return response()->json(['token' => $token]);
}
A500 Internal Server Error
B{"token": null}
C{"message": "Invalid credentials"}
D{"token": "<a long string token>"}
Attempts:
2 left
💡 Hint
The createToken method returns a token object with a plainTextToken property.
❓ lifecycle
intermediate
1:30remaining
Which middleware is required to protect Sanctum API routes?
You want to protect your API routes so only authenticated users with valid Sanctum tokens can access them. Which middleware should you apply to these routes?
Aauth:sanctum
Bauth:api
Cguest
Dweb
Attempts:
2 left
💡 Hint
Sanctum uses a specific guard for API token authentication.
🔧 Debug
advanced
2:30remaining
Why does this Sanctum token authentication fail with 401 Unauthorized?
This API route uses 'auth:sanctum' middleware but always returns 401 Unauthorized even with a valid token sent in the Authorization header. What is the most likely cause?
Laravel
Route::middleware('auth:sanctum')->get('/user', function (Request $request) {
    return $request->user();
});

// Client sends header: Authorization: Bearer <valid_token>
AThe Authorization header is misspelled or missing the 'Bearer' prefix.
BThe token was created with 'createToken' but not saved to the database.
CThe user model does not use the 'HasApiTokens' trait.
DThe 'EnsureFrontendRequestsAreStateful' middleware is missing from the middleware group.
Attempts:
2 left
💡 Hint
Check if the user model supports Sanctum tokens.
📝 Syntax
advanced
1:30remaining
Which code snippet correctly revokes all Sanctum tokens for the authenticated user?
You want to log out a user by deleting all their API tokens. Which code snippet correctly does this?
A$request->user()->tokens()->delete();
B$request->user()->token()->delete();
CAuth::user()->revokeTokens();
D$request->user()->deleteTokens();
Attempts:
2 left
💡 Hint
The tokens() method returns a relationship to all tokens.
🧠 Conceptual
expert
3:00remaining
What is the main difference between Sanctum's SPA authentication and API token authentication?
Sanctum supports two main authentication methods: SPA authentication using cookies and API token authentication using tokens. What is the key difference in how they authenticate users?
ASPA authentication requires OAuth2, while API token authentication uses simple API keys.
BSPA authentication uses session cookies and CSRF protection, while API token authentication uses bearer tokens in headers without sessions.
CSPA authentication only works with mobile apps, API token authentication only with web browsers.
DSPA authentication stores tokens in localStorage, API token authentication stores tokens in cookies.
Attempts:
2 left
💡 Hint
Think about how browsers handle cookies and headers differently.

Practice

(1/5)
1. What is the main purpose of Laravel Sanctum in API development?
easy
A. To handle frontend routing in Laravel apps
B. To provide simple token-based API authentication
C. To manage database migrations automatically
D. To optimize SQL queries for performance

Solution

  1. Step 1: Understand Sanctum's role

    Sanctum is designed to provide a simple way to authenticate API requests using tokens.
  2. Step 2: Compare options

    The incorrect options relate to frontend routing, database migrations, and SQL query optimization, which are other Laravel features, not Sanctum's main purpose.
  3. Final Answer:

    To provide simple token-based API authentication -> Option B
  4. Quick Check:

    Sanctum = API token authentication [OK]
Hint: Sanctum = simple API token auth [OK]
Common Mistakes:
  • Confusing Sanctum with database or routing features
  • Thinking Sanctum manages frontend or SQL optimization
2. Which of the following is the correct way to protect an API route using Sanctum middleware in Laravel?
easy
A. Route::middleware('auth:sanctum')->get('/user', function () { return auth()->user(); });
B. Route::middleware('api')->get('/user', function () { return auth()->user(); });
C. Route::middleware('sanctum')->get('/user', function () { return auth()->user(); });
D. Route::middleware('auth')->get('/user', function () { return auth()->user(); });

Solution

  1. Step 1: Identify Sanctum middleware syntax

    Sanctum uses 'auth:sanctum' middleware to protect routes requiring token authentication.
  2. Step 2: Check each option

    Route::middleware('auth:sanctum')->get('/user', function () { return auth()->user(); }); uses 'auth:sanctum' correctly; others use incorrect or incomplete middleware names.
  3. Final Answer:

    Route::middleware('auth:sanctum')->get('/user', function () { return auth()->user(); }); -> Option A
  4. Quick Check:

    Sanctum middleware = 'auth:sanctum' [OK]
Hint: Use 'auth:sanctum' middleware to protect API routes [OK]
Common Mistakes:
  • Using 'auth' instead of 'auth:sanctum'
  • Omitting middleware or using wrong names like 'sanctum' alone
  • Confusing 'api' middleware with Sanctum middleware
3. Given this code snippet, what will be the output when a valid token is used to access the route?
use Illuminate\Http\Request;

Route::middleware('auth:sanctum')->get('/profile', function (Request $request) {
    return $request->user()->name;
});
medium
A. The name of the authenticated user
B. An error: Method user() does not exist
C. Null, because user() returns nothing
D. The user's email address

Solution

  1. Step 1: Understand the middleware effect

    The 'auth:sanctum' middleware ensures the request is authenticated and $request->user() returns the authenticated user model.
  2. Step 2: Analyze the return statement

    The code returns $request->user()->name, which outputs the authenticated user's name.
  3. Final Answer:

    The name of the authenticated user -> Option A
  4. Quick Check:

    $request->user()->name = user name [OK]
Hint: auth:sanctum gives user() object; name property outputs user name [OK]
Common Mistakes:
  • Assuming user() returns null or causes error
  • Confusing user name with email
  • Ignoring middleware authentication effect
4. Identify the error in this code snippet for issuing a Sanctum API token:
use App\Models\User;

$user = User::find(1);
$token = $user->createToken;
return $token->plainTextToken;
medium
A. User model does not support createToken method
B. User::find(1) returns null causing error
C. plainTextToken is not a valid property
D. Missing parentheses when calling createToken() method

Solution

  1. Step 1: Check method call syntax

    The createToken method must be called with parentheses and a token name string, e.g. createToken('token-name').
  2. Step 2: Analyze given code

    The code uses $user->createToken without parentheses, so it references the method, not calls it, causing an error.
  3. Final Answer:

    Missing parentheses when calling createToken() method -> Option D
  4. Quick Check:

    Method calls need parentheses () [OK]
Hint: Always call createToken() with parentheses and token name [OK]
Common Mistakes:
  • Forgetting parentheses on method calls
  • Not passing token name string to createToken()
  • Assuming plainTextToken is invalid
5. You want to issue a token for a user and restrict it to only allow access to 'orders' and 'products' API scopes. Which code snippet correctly creates this token with scopes using Laravel Sanctum?
hard
A. $token = $user->createToken('api-token', 'orders', 'products');
B. $token = $user->createToken('api-token')->scopes(['orders', 'products']);
C. $token = $user->createToken('api-token', ['orders', 'products']);
D. $token = $user->createToken(['orders', 'products']);

Solution

  1. Step 1: Review createToken method signature

    The createToken method accepts the token name as first argument and an array of scopes as second argument.
  2. Step 2: Evaluate each option

    $token = $user->createToken('api-token', ['orders', 'products']); correctly passes the token name and scopes array. $token = $user->createToken('api-token')->scopes(['orders', 'products']); incorrectly chains scopes() which does not exist. $token = $user->createToken('api-token', 'orders', 'products'); passes scopes as separate arguments, which is invalid. $token = $user->createToken(['orders', 'products']); passes scopes as first argument without token name.
  3. Final Answer:

    $token = $user->createToken('api-token', ['orders', 'products']); -> Option C
  4. Quick Check:

    createToken(name, scopes array) = correct [OK]
Hint: Pass scopes as second argument array in createToken() [OK]
Common Mistakes:
  • Passing scopes as separate arguments instead of array
  • Trying to chain scopes() method
  • Omitting token name argument