Bird
Raised Fist0
Laravelframework~5 mins

Token management in Laravel - Cheat Sheet & Quick Revision

Choose your learning style10 modes available

Start learning this pattern below

Jump into concepts and practice - no test required

or
Recommended
Test this pattern10 questions across easy, medium, and hard to know if this pattern is strong
Recall & Review
beginner
What is token management in Laravel?
Token management in Laravel is the process of creating, storing, and validating tokens that help secure user authentication and API access.
Click to reveal answer
intermediate
How does Laravel Sanctum help with token management?
Laravel Sanctum provides a simple way to issue API tokens to users without OAuth complexity, allowing token creation, expiration, and revocation.
Click to reveal answer
intermediate
What is the purpose of the 'personal_access_tokens' table in Laravel Sanctum?
It stores the tokens issued to users, including token name, abilities, expiration, and the user it belongs to, enabling token validation and management.
Click to reveal answer
intermediate
How can you revoke a token in Laravel?
You can revoke a token by deleting it from the database or using the delete method on the token model, which prevents further use of that token.
Click to reveal answer
beginner
Why is it important to set token abilities or scopes in Laravel?
Setting abilities limits what actions a token can perform, improving security by restricting token permissions to only what is necessary.
Click to reveal answer
Which Laravel package is commonly used for simple API token management?
ALaravel Sanctum
BLaravel Passport
CLaravel Breeze
DLaravel Jetstream
Where are Laravel Sanctum tokens stored by default?
AIn the users table
BIn the personal_access_tokens table
CIn the sessions table
DIn cache memory
What method would you use to create a new token for a user in Laravel Sanctum?
AcreateToken()
BmakeToken()
CgenerateToken()
DnewToken()
How can you limit what a token can do in Laravel Sanctum?
ABy deleting the user
BBy changing the user password
CBy setting token abilities/scopes
DBy modifying the session timeout
What happens if you delete a token from the database in Laravel Sanctum?
ANothing, the token still works
BThe token automatically renews
CThe user is logged out from all devices
DThe token becomes invalid and cannot be used
Explain how Laravel Sanctum manages API tokens and why it is useful for token management.
Think about how Sanctum helps avoid complex OAuth setups.
You got /4 concepts.
    Describe the steps to revoke a token in Laravel and why revoking tokens is important.
    Consider what happens if a token is lost or compromised.
    You got /4 concepts.

      Practice

      (1/5)
      1. What is the main purpose of token management in Laravel?
      easy
      A. To control user access securely using secret tokens
      B. To store user passwords in plain text
      C. To speed up database queries
      D. To create user interface components

      Solution

      1. Step 1: Understand token management role

        Token management is about controlling access by issuing and verifying tokens.
      2. Step 2: Identify correct purpose in Laravel context

        Laravel uses tokens to securely authenticate users without exposing passwords.
      3. Final Answer:

        To control user access securely using secret tokens -> Option A
      4. Quick Check:

        Token management = secure user access [OK]
      Hint: Tokens control access, not UI or passwords [OK]
      Common Mistakes:
      • Confusing tokens with passwords
      • Thinking tokens speed up queries
      • Mixing token use with UI design
      2. Which Laravel method is used to create a new API token for a user?
      easy
      A. $user->makeToken()
      B. $user->createToken('token-name')
      C. $user->generatePassword()
      D. $user->newApiKey()

      Solution

      1. Step 1: Recall Laravel Sanctum token creation method

        Laravel Sanctum uses createToken() to generate tokens for users.
      2. Step 2: Match method names with Laravel documentation

        Only createToken() is the correct method; others are invalid or non-existent.
      3. Final Answer:

        $user->createToken('token-name') -> Option B
      4. Quick Check:

        Token creation method = createToken() [OK]
      Hint: Remember: createToken() creates tokens in Laravel [OK]
      Common Mistakes:
      • Using non-existent methods like makeToken()
      • Confusing token creation with password generation
      • Using wrong method names
      3. Given this code snippet, what will return $user->tokens()->count(); output after creating two tokens?
      $user = User::find(1);
      $user->createToken('token1');
      $user->createToken('token2');
      return $user->tokens()->count();
      medium
      A. 2
      B. 1
      C. Error
      D. 0

      Solution

      1. Step 1: Understand token creation effect

        Each createToken() call adds one token record linked to the user.
      2. Step 2: Count tokens after two creations

        After two calls, the user has two tokens stored, so count() returns 2.
      3. Final Answer:

        2 -> Option A
      4. Quick Check:

        Two tokens created = count 2 [OK]
      Hint: Count tokens after creation equals number created [OK]
      Common Mistakes:
      • Assuming tokens() returns zero without refresh
      • Thinking createToken() replaces old tokens
      • Expecting an error due to missing save
      4. What is wrong with this code snippet for deleting a user's tokens?
      $user = User::find(1);
      $user->tokens->delete();
      medium
      A. User::find(1) returns null, causing error
      B. delete() method does not exist in Laravel
      C. tokens relationship does not exist by default
      D. tokens is a collection, so delete() cannot be called directly

      Solution

      1. Step 1: Identify tokens property type

        $user->tokens returns a collection, not a query builder.
      2. Step 2: Understand collection vs query builder methods

        delete() is a query builder method; collections need each() or query to delete.
      3. Final Answer:

        tokens is a collection, so delete() cannot be called directly -> Option D
      4. Quick Check:

        Collection.delete() invalid, use query builder [OK]
      Hint: Use query builder for delete, not collection [OK]
      Common Mistakes:
      • Calling delete() on collection directly
      • Not checking if user exists
      • Assuming delete() is a collection method
      5. How can you revoke all tokens for the currently authenticated user except the current token in Laravel Sanctum?
      hard
      A. $user->currentAccessToken()->delete();
      B. $user->tokens()->delete();
      C. $user->tokens()->where('id', '!=', $currentTokenId)->delete();
      D. $user->revokeTokensExceptCurrent();

      Solution

      1. Step 1: Understand token revocation requirements

        We want to delete all tokens except the current one, so we filter by token ID.
      2. Step 2: Use query builder to delete filtered tokens

        Using where('id', '!=', $currentTokenId) excludes current token, then delete() removes others.
      3. Step 3: Check other options for correctness

        $user->tokens()->delete(); deletes all tokens including current; $user->currentAccessToken()->delete(); deletes only current; $user->revokeTokensExceptCurrent(); is not a Laravel method.
      4. Final Answer:

        $user->tokens()->where('id', '!=', $currentTokenId)->delete(); -> Option C
      5. Quick Check:

        Filter tokens by ID, then delete others [OK]
      Hint: Filter tokens by ID to exclude current, then delete [OK]
      Common Mistakes:
      • Deleting all tokens including current
      • Trying to call non-existent methods
      • Deleting only current token instead of others