Authentication
API authentication establishes an actor from trusted credentials.
What it is
API authentication establishes an actor from trusted credentials.
When to use it
Choose session or token mechanisms appropriate to the client.
Syntax
Authorization: Bearer <token>Example
// Use framework-supported token middleware when installed/configured.
// Browser session route:
Route::get("/me", fn (Request $request) =>
response()->json(["id" => $request->user()->id])
)->middleware("auth");Common mistakes
Bearer tokens need TLS and expiry/revocation handling; do not implement custom cryptography.