Sanctum API Tokens vs Session Auth for Jetstream Frontends
0 reputation · 24 Jul 2024, 18:29 UTC
Laravel Jetstream provides a comprehensive authentication scaffold that supports both traditional session-based authentication for web frontends and Laravel Sanctum for API token management. When building a project that requires both a first-party web interface and a mobile application, developers must decide how to handle the authentication surface.
Enabling the API feature in Jetstream adds a dedicated UI for users to generate, name, and revoke Sanctum tokens. However, this introduces a secondary authentication mechanism alongside the standard session cookies used by the Inertia or Livewire stacks.
The primary constraint is balancing the convenience of the scaffolded token management UI against the increased security surface area and the need to define specific token abilities to prevent over-permissive access.
Technical Considerations
- Session auth relies on stateful cookies and CSRF protection.
- Sanctum tokens are stateless and require manual ability definitions for granular access control.
Should the application rely on session-based authentication for all first-party interactions and reserve Sanctum exclusively for third-party integrations, or is it more efficient to unify the authentication logic using tokens across both the web and mobile clients? What are the implications for session expiration and token revocation when both are active?