Field Manual PHP / Laravel reference
← HTTP / API

Authorization

API authorization restricts records and operations for the actor.

What it is

API authorization restricts records and operations for the actor.

When to use it

Check every request and tenant boundary.

Syntax

Gate::authorize("view", $account);

Example

Route::get("/accounts/{account}", function (Account $account) {
    Gate::authorize("view", $account);
    return response()->json(["id" => $account->id, "currency" => $account->currency]);
})->middleware("auth");

Common mistakes

A valid token does not grant access to every account; object IDs are not secrets.

Related topics

AuthorizationAuthentication versus authorizationAuthorization and RBAC