Skip to main content
proofage/laravel-client adds Laravel wiring to the PHP SDK: a service provider with auto-discovery, the ProofAge facade, webhook signature middleware, and a command that checks your setup. It supports Laravel 12 and 13 on PHP 8.2 or newer, and sends every request through Laravel’s Http facade, so Http::fake() works in your tests.

Install

.env
Check everything, from the keys to the webhook route:
It checks the configuration, the connection to your workspace, that the workspace has a webhook URL, and that a POST route exists for it, protected by the signature middleware.

Create a verification

Read results

Receive webhooks

In routes/web.php instead, exclude the path from CSRF protection in bootstrap/app.php, or every webhook is rejected with 419 before the middleware runs:
The middleware checks the headers, that X-Auth-Client is your public key, that the timestamp is within 300 seconds (webhook_tolerance), and the signature. A request that fails is answered 401 with a code such as INVALID_SIGNATURE; your controller only sees verified webhooks. Configure the workspace’s active secret key: webhooks are signed with it.

Several workspaces

A marketplace verifying buyers and sellers differently runs two workspaces. Add the second set of keys to your config, create a client for it, and name its config prefix on the webhook route:
See the marketplace recipe.

Errors

Retries follow the PHP SDK: a POST is never retried after a 5xx or a timeout.