Jump into concepts and practice - no test required
or
Recommended
Test this pattern10 questions across easy, medium, and hard to know if this pattern is strong
API authentication with Sanctum
📖 Scenario: You are building a simple Laravel API that requires user authentication. You want to use Laravel Sanctum to protect your API routes so only authenticated users can access them.
🎯 Goal: Create a Laravel API with Sanctum authentication. You will set up the user model, configure Sanctum, create a login route to issue tokens, and protect an API route that returns user data.
📋 What You'll Learn
Create a users table with name, email, and password fields
Install and configure Laravel Sanctum
Create a login API route that issues a Sanctum token
Protect an API route to return authenticated user info
💡 Why This Matters
🌍 Real World
APIs often need secure authentication to protect user data. Laravel Sanctum provides a simple way to add token-based authentication to your API.
💼 Career
Understanding API authentication with Sanctum is essential for backend developers working with Laravel to build secure and scalable web services.
Progress0 / 4 steps
1
Create the users table migration
Create a migration file for the users table with columns id, name, email, password, and timestamps. Use Laravel's schema builder with Schema::create('users') and the appropriate column types.
Laravel
Hint
Use Schema::create('users', function (Blueprint $table) { ... }) and add the columns inside the closure.
2
Configure Sanctum in config/sanctum.php
Add the Sanctum middleware \Laravel\Sanctum\Http\Middleware\EnsureFrontendRequestsAreStateful::class to the api middleware group in app/Http/Kernel.php. Also, publish Sanctum's configuration and migration files using php artisan vendor:publish --provider="Laravel\Sanctum\SanctumServiceProvider".
Laravel
Hint
Open app/Http/Kernel.php and add the Sanctum middleware to the api group array.
Then run the vendor publish command in your terminal.
3
Create a login route that issues Sanctum tokens
In routes/api.php, create a POST route /login that accepts email and password. Use Auth::attempt() to verify credentials. If successful, return a Sanctum token created by $user->createToken('api-token')->plainTextToken. If not, return a 401 response.
Laravel
Hint
Use Route::post('/login', function (Request $request) { ... }) and inside check credentials with Auth::attempt().
If successful, create a token with $user->createToken('api-token')->plainTextToken.
4
Protect an API route to return authenticated user info
In routes/api.php, create a GET route /user protected by the auth:sanctum middleware. Return the authenticated user using $request->user().
Laravel
Hint
Use Route::middleware('auth:sanctum')->get('/user', function (Request $request) { ... }) and return the authenticated user.
Practice
(1/5)
1. What is the main purpose of Laravel Sanctum in API development?
easy
A. To handle frontend routing in Laravel apps
B. To provide simple token-based API authentication
C. To manage database migrations automatically
D. To optimize SQL queries for performance
Solution
Step 1: Understand Sanctum's role
Sanctum is designed to provide a simple way to authenticate API requests using tokens.
Step 2: Compare options
The incorrect options relate to frontend routing, database migrations, and SQL query optimization, which are other Laravel features, not Sanctum's main purpose.
Final Answer:
To provide simple token-based API authentication -> Option B
Quick Check:
Sanctum = API token authentication [OK]
Hint: Sanctum = simple API token auth [OK]
Common Mistakes:
Confusing Sanctum with database or routing features
Thinking Sanctum manages frontend or SQL optimization
2. Which of the following is the correct way to protect an API route using Sanctum middleware in Laravel?
easy
A. Route::middleware('auth:sanctum')->get('/user', function () { return auth()->user(); });
B. Route::middleware('api')->get('/user', function () { return auth()->user(); });
C. Route::middleware('sanctum')->get('/user', function () { return auth()->user(); });
D. Route::middleware('auth')->get('/user', function () { return auth()->user(); });
Solution
Step 1: Identify Sanctum middleware syntax
Sanctum uses 'auth:sanctum' middleware to protect routes requiring token authentication.
Step 2: Check each option
Route::middleware('auth:sanctum')->get('/user', function () { return auth()->user(); }); uses 'auth:sanctum' correctly; others use incorrect or incomplete middleware names.
Final Answer:
Route::middleware('auth:sanctum')->get('/user', function () { return auth()->user(); }); -> Option A
Quick Check:
Sanctum middleware = 'auth:sanctum' [OK]
Hint: Use 'auth:sanctum' middleware to protect API routes [OK]
Common Mistakes:
Using 'auth' instead of 'auth:sanctum'
Omitting middleware or using wrong names like 'sanctum' alone
Confusing 'api' middleware with Sanctum middleware
3. Given this code snippet, what will be the output when a valid token is used to access the route?
use Illuminate\Http\Request;
Route::middleware('auth:sanctum')->get('/profile', function (Request $request) {
return $request->user()->name;
});
medium
A. The name of the authenticated user
B. An error: Method user() does not exist
C. Null, because user() returns nothing
D. The user's email address
Solution
Step 1: Understand the middleware effect
The 'auth:sanctum' middleware ensures the request is authenticated and $request->user() returns the authenticated user model.
Step 2: Analyze the return statement
The code returns $request->user()->name, which outputs the authenticated user's name.
Final Answer:
The name of the authenticated user -> Option A
Quick Check:
$request->user()->name = user name [OK]
Hint: auth:sanctum gives user() object; name property outputs user name [OK]
Common Mistakes:
Assuming user() returns null or causes error
Confusing user name with email
Ignoring middleware authentication effect
4. Identify the error in this code snippet for issuing a Sanctum API token:
use App\Models\User;
$user = User::find(1);
$token = $user->createToken;
return $token->plainTextToken;
medium
A. User model does not support createToken method
B. User::find(1) returns null causing error
C. plainTextToken is not a valid property
D. Missing parentheses when calling createToken() method
Solution
Step 1: Check method call syntax
The createToken method must be called with parentheses and a token name string, e.g. createToken('token-name').
Step 2: Analyze given code
The code uses $user->createToken without parentheses, so it references the method, not calls it, causing an error.
Final Answer:
Missing parentheses when calling createToken() method -> Option D
Quick Check:
Method calls need parentheses () [OK]
Hint: Always call createToken() with parentheses and token name [OK]
Common Mistakes:
Forgetting parentheses on method calls
Not passing token name string to createToken()
Assuming plainTextToken is invalid
5. You want to issue a token for a user and restrict it to only allow access to 'orders' and 'products' API scopes. Which code snippet correctly creates this token with scopes using Laravel Sanctum?
hard
A. $token = $user->createToken('api-token', 'orders', 'products');
B. $token = $user->createToken('api-token')->scopes(['orders', 'products']);
C. $token = $user->createToken('api-token', ['orders', 'products']);
D. $token = $user->createToken(['orders', 'products']);
Solution
Step 1: Review createToken method signature
The createToken method accepts the token name as first argument and an array of scopes as second argument.
Step 2: Evaluate each option
$token = $user->createToken('api-token', ['orders', 'products']); correctly passes the token name and scopes array. $token = $user->createToken('api-token')->scopes(['orders', 'products']); incorrectly chains scopes() which does not exist. $token = $user->createToken('api-token', 'orders', 'products'); passes scopes as separate arguments, which is invalid. $token = $user->createToken(['orders', 'products']); passes scopes as first argument without token name.
Final Answer:
$token = $user->createToken('api-token', ['orders', 'products']); -> Option C
Quick Check:
createToken(name, scopes array) = correct [OK]
Hint: Pass scopes as second argument array in createToken() [OK]
Common Mistakes:
Passing scopes as separate arguments instead of array