Passport and OAuth2

Passport and When OAuth2 Is Warranted

Sanctum 2,988 authenticates your clients. OAuth2 lets a third-party app ask your users for delegated access ("Allow ShelfSync to read your orders?") without ever seeing a password. Passport 3,418 (https://github.com/laravel/passport 3,418 ) 13.8.0 is a full OAuth2 server on league/oauth2-server 6,667 , installed with php artisan install:api --passport. It supports the authorization code grant with PKCE, client credentials, device authorization, and refresh tokens. The password and implicit grants are off unless enabled, and its documentation no longer recommends either.

Choosing between Sanctum and Passport
Need Sanctum 4.3 Passport 13.8
Your own SPA or mobile app Cookie or personal token Works, but heavy
Third-party developer apps No Yes, with consent screen
Service to service Personal token Client credentials
Access token Opaque, SHA-256 stored Signed JWT

Laravel 2,157 's own advice: Passport only when the application absolutely needs OAuth2, such as a public developer program; Sanctum for everything else.