Authentication is one of the first architectural decisions you make in any Laravel application. Two of the most popular first-party packages — Sanctum and Passport — solve the problem in fundamentally different ways. Choosing the wrong one early can mean a painful refactor later.
Sanctum provides a featherweight authentication system for SPAs, mobile applications, and simple token-based APIs. It issues plain API tokens stored in your database and, for SPA auth, uses Laravel’s built-in session cookies with CSRF protection.
// Install
composer require laravel/sanctum
php artisan vendor:publish --provider="Laravel\Sanctum\SanctumServiceProvider"
php artisan migrate
// Issue a token
$token = $user->createToken('mobile-app')->plainTextToken;
// Protect routes
Route::middleware('auth:sanctum')->get('/user', fn (Request $r) => $r->user());
Passport is a full OAuth 2.0 server implementation built on top of the League OAuth2 server. It supports Authorization Code grants, Client Credentials, Password grants, and Refresh Tokens.
| Feature | Sanctum | Passport |
|---|---|---|
| Setup complexity | Low | High |
| OAuth2 support | No | Yes (full) |
| SPA cookie auth | Yes | No |
| Third-party clients | No | Yes |
| Token scopes | Basic | Advanced |
| Refresh tokens | No | Yes |
Choose Sanctum for 90% of projects — first-party SPAs, mobile apps, and internal APIs. It’s simpler, faster, and easier to reason about. Choose Passport only when you genuinely need OAuth2 — i.e., when external developers will integrate with your platform using their own client credentials.
The most common mistake is reaching for Passport because it sounds more “enterprise” — only to spend days configuring OAuth2 flows that add no real value to a closed first-party application.