Sanctum 2,988 authenticates your clients. OAuth2 lets a third-party app ask your users for delegated access ("Allow ShelfSync to read your orders?") without ever seeing a password. Passport 3,418 (https://github.com/laravel/passport 3,418 ) 13.8.0 is a full OAuth2 server on league/oauth2-server 6,667 , installed with php artisan install:api --passport. It supports the authorization code grant with PKCE, client credentials, device authorization, and refresh tokens. The password and implicit grants are off unless enabled, and its documentation no longer recommends either.
| Need | Sanctum 4.3 | Passport 13.8 |
|---|---|---|
| Your own SPA or mobile app | Cookie or personal token | Works, but heavy |
| Third-party developer apps | No | Yes, with consent screen |
| Service to service | Personal token | Client credentials |
| Access token | Opaque, SHA-256 stored | Signed JWT |
Laravel 2,157 's own advice: Passport only when the application absolutely needs OAuth2, such as a public developer program; Sanctum for everything else.