Bird
Raised Fist0
Laravelframework~10 mins

Token management in Laravel - Step-by-Step Execution

Choose your learning style10 modes available

Start learning this pattern below

Jump into concepts and practice - no test required

or
Recommended
Test this pattern10 questions across easy, medium, and hard to know if this pattern is strong
Concept Flow - Token management
User sends login request
↓
Validate credentials
↓
Create token
↓
Send token to user
↓
User sends token with requests
↓
Validate token
↓
Allow access
This flow shows how Laravel handles token creation after login and validates tokens on user requests.
Execution Sample
Laravel
<?php
// Login controller method
public function login(Request $request) {
  $user = User::where('email', $request->email)->first();
  if (!$user || !Hash::check($request->password, $user->password)) {
    return response()->json(['error' => 'Invalid credentials'], 401);
  }
  $token = $user->createToken('auth_token')->plainTextToken;
  return response()->json(['access_token' => $token]);
}
This code checks user credentials and creates a token if valid, returning it to the user.
Execution Table
StepActionInput/ConditionResultNext Step
1Receive login requestEmail and passwordRequest data readyValidate credentials
2Check user existsUser with email found?User foundVerify password
3Verify passwordPassword matches?Password correctCreate token
4Create tokenUser authenticatedToken generatedReturn token
5Return tokenToken createdToken sent in responseUser stores token
6User sends token with requestToken included in headerToken receivedValidate token
7Validate tokenToken valid?Token validAllow access
8Allow accessToken acceptedRequest processedEnd
9If any check failsInvalid credentials or tokenError response sentEnd
💡 Execution stops when user is either granted access or receives an error due to invalid credentials or token.
Variable Tracker
VariableStartAfter Step 2After Step 3After Step 4After Step 5After Step 6After Step 7Final
$usernullUser object or nullUser objectUser objectUser objectUser objectUser objectUser object or null
$tokennullnullnullToken stringToken stringToken stringToken stringToken string or null
Request statusPendingPendingPendingPendingToken sentToken receivedValidatedAccess granted or denied
Key Moments - 3 Insights
Why does the code check both user existence and password correctness separately?
Because if the user is not found, password check is skipped. This prevents errors and improves security, as shown in steps 2 and 3 of the execution_table.
What happens if the token sent by the user is invalid or expired?
The token validation step (step 7) fails, and the user receives an error response (step 9), stopping access.
Why is the token sent back as plainTextToken instead of the token object?
Because plainTextToken is the actual string the user needs to store and send with requests. The token object contains metadata but is not sent to the client.
Visual Quiz - 3 Questions
Test your understanding
Look at the execution_table, what is the result after step 4?
AUser object is null
BError response sent
CToken generated
DPassword check skipped
💡 Hint
Check the 'Result' column for step 4 in the execution_table.
At which step does the system decide to allow access to the user?
AStep 3
BStep 8
CStep 5
DStep 9
💡 Hint
Look for the step labeled 'Allow access' in the execution_table.
If the password is incorrect, which step will the execution jump to next?
AStep 9
BStep 4
CStep 6
DStep 7
💡 Hint
Refer to the 'Next Step' column after 'Verify password' in the execution_table.
Concept Snapshot
Token management in Laravel:
- User logs in with email and password
- If valid, create a token with createToken()
- Return token string to user
- User sends token with requests
- Laravel validates token
- Access granted if token valid, else error
Full Transcript
Token management in Laravel starts when a user sends a login request with email and password. The system checks if the user exists and verifies the password. If both are correct, Laravel creates a token string using createToken() and sends it back to the user. The user stores this token and includes it in the header of future requests. Each request's token is validated by Laravel. If the token is valid, the user is allowed access. If any check fails, an error response is sent. This process ensures secure authentication and authorization using tokens.

Practice

(1/5)
1. What is the main purpose of token management in Laravel?
easy
A. To control user access securely using secret tokens
B. To store user passwords in plain text
C. To speed up database queries
D. To create user interface components

Solution

  1. Step 1: Understand token management role

    Token management is about controlling access by issuing and verifying tokens.
  2. Step 2: Identify correct purpose in Laravel context

    Laravel uses tokens to securely authenticate users without exposing passwords.
  3. Final Answer:

    To control user access securely using secret tokens -> Option A
  4. Quick Check:

    Token management = secure user access [OK]
Hint: Tokens control access, not UI or passwords [OK]
Common Mistakes:
  • Confusing tokens with passwords
  • Thinking tokens speed up queries
  • Mixing token use with UI design
2. Which Laravel method is used to create a new API token for a user?
easy
A. $user->makeToken()
B. $user->createToken('token-name')
C. $user->generatePassword()
D. $user->newApiKey()

Solution

  1. Step 1: Recall Laravel Sanctum token creation method

    Laravel Sanctum uses createToken() to generate tokens for users.
  2. Step 2: Match method names with Laravel documentation

    Only createToken() is the correct method; others are invalid or non-existent.
  3. Final Answer:

    $user->createToken('token-name') -> Option B
  4. Quick Check:

    Token creation method = createToken() [OK]
Hint: Remember: createToken() creates tokens in Laravel [OK]
Common Mistakes:
  • Using non-existent methods like makeToken()
  • Confusing token creation with password generation
  • Using wrong method names
3. Given this code snippet, what will return $user->tokens()->count(); output after creating two tokens?
$user = User::find(1);
$user->createToken('token1');
$user->createToken('token2');
return $user->tokens()->count();
medium
A. 2
B. 1
C. Error
D. 0

Solution

  1. Step 1: Understand token creation effect

    Each createToken() call adds one token record linked to the user.
  2. Step 2: Count tokens after two creations

    After two calls, the user has two tokens stored, so count() returns 2.
  3. Final Answer:

    2 -> Option A
  4. Quick Check:

    Two tokens created = count 2 [OK]
Hint: Count tokens after creation equals number created [OK]
Common Mistakes:
  • Assuming tokens() returns zero without refresh
  • Thinking createToken() replaces old tokens
  • Expecting an error due to missing save
4. What is wrong with this code snippet for deleting a user's tokens?
$user = User::find(1);
$user->tokens->delete();
medium
A. User::find(1) returns null, causing error
B. delete() method does not exist in Laravel
C. tokens relationship does not exist by default
D. tokens is a collection, so delete() cannot be called directly

Solution

  1. Step 1: Identify tokens property type

    $user->tokens returns a collection, not a query builder.
  2. Step 2: Understand collection vs query builder methods

    delete() is a query builder method; collections need each() or query to delete.
  3. Final Answer:

    tokens is a collection, so delete() cannot be called directly -> Option D
  4. Quick Check:

    Collection.delete() invalid, use query builder [OK]
Hint: Use query builder for delete, not collection [OK]
Common Mistakes:
  • Calling delete() on collection directly
  • Not checking if user exists
  • Assuming delete() is a collection method
5. How can you revoke all tokens for the currently authenticated user except the current token in Laravel Sanctum?
hard
A. $user->currentAccessToken()->delete();
B. $user->tokens()->delete();
C. $user->tokens()->where('id', '!=', $currentTokenId)->delete();
D. $user->revokeTokensExceptCurrent();

Solution

  1. Step 1: Understand token revocation requirements

    We want to delete all tokens except the current one, so we filter by token ID.
  2. Step 2: Use query builder to delete filtered tokens

    Using where('id', '!=', $currentTokenId) excludes current token, then delete() removes others.
  3. Step 3: Check other options for correctness

    $user->tokens()->delete(); deletes all tokens including current; $user->currentAccessToken()->delete(); deletes only current; $user->revokeTokensExceptCurrent(); is not a Laravel method.
  4. Final Answer:

    $user->tokens()->where('id', '!=', $currentTokenId)->delete(); -> Option C
  5. Quick Check:

    Filter tokens by ID, then delete others [OK]
Hint: Filter tokens by ID to exclude current, then delete [OK]
Common Mistakes:
  • Deleting all tokens including current
  • Trying to call non-existent methods
  • Deleting only current token instead of others