Self-hosted WorkOS-compatible OAuth server using Laravel Passport - starter kit.
inmanturbo/homework-starter-kit is a Laravel package for self-hosted workos-compatible oauth server using laravel passport - starter kit..
It currently has 1 GitHub stars and 0 downloads on Packagist (latest version v0.0.1).
Install it with composer require inmanturbo/homework-starter-kit.
Discover more Laravel packages by inmanturbo
or browse all Laravel packages to compare alternatives.
Last updated
A ready-to-use Laravel application that provides a self-hosted, WorkOS-compatible OAuth server using Laravel Passport. This starter kit gives you a complete authentication server that can replace WorkOS while maintaining full API compatibility.
# Create a new project using Herd
herd new my-oauth-server --using="inmanturbo/homework-starter-kit"
# Navigate to your project
cd my-oauth-server
# Your OAuth server is now available at https://my-oauth-server.test
# Install Laravel installer if you haven't already
composer global require laravel/installer
# Create a new project using this starter kit
laravel new my-oauth-server --using="inmanturbo/homework-starter-kit"
# Navigate to your project
cd my-oauth-server
Clone this repository and install dependencies:
git clone https://github.com/inmanturbo/homework-starter-kit.git my-oauth-server
cd my-oauth-server
composer install
npm install && npm run build
cp .env.example .env
php artisan key:generate
Configure your database in .env:
DB_CONNECTION=mysql
DB_HOST=127.0.0.1
DB_PORT=3306
DB_DATABASE=workos_passport
DB_USERNAME=your_username
DB_PASSWORD=your_password
php artisan migrate
Create a first-party client (auto-approves authorization):
php artisan passport:client --public
Save the Client ID - you'll need this for your client applications.
php artisan serve --port=8000
Your WorkOS-compatible OAuth server is now running at http://localhost:8000!
The starter kit provides these WorkOS-compatible endpoints:
GET /user_management/authorize - OAuth authorization endpointPOST /user_management/authenticate - Token exchange endpointPOST /user_management/authenticate_with_refresh_token - Refresh token endpointGET /user_management/users/{userId} - Get user informationGET /sso/jwks/{clientId} - JWKS endpoint for token verificationConfigure your client application to use your OAuth server:
Option 1: Configuration-Based (Recommended)
Add to your config/services.php:
'workos' => [
'client_id' => env('WORKOS_CLIENT_ID'),
'secret' => env('WORKOS_API_KEY'),
'redirect_url' => env('WORKOS_REDIRECT_URL'),
'base_url' => env('WORKOS_BASE_URL', 'https://api.workos.com/'),
],
In your .env:
WORKOS_CLIENT_ID=your_oauth_client_id
WORKOS_API_KEY=your_oauth_client_secret
WORKOS_REDIRECT_URL=http://your-app.test/authenticate
WORKOS_BASE_URL=http://localhost:8000/
In your AppServiceProvider:
use WorkOS\WorkOS;
public function boot()
{
$baseUrl = config('services.workos.base_url');
if ($baseUrl && $baseUrl !== 'https://api.workos.com/') {
WorkOS::setApiBaseUrl($baseUrl);
}
}
Option 2: Environment-Based
// In AppServiceProvider
public function boot()
{
if (app()->environment('local')) {
WorkOS::setApiBaseUrl('http://localhost:8000/');
}
}
The starter kit comes pre-configured with sensible defaults in app/Providers/PassportServiceProvider.php:
// Token lifetimes
Passport::tokensExpireIn(CarbonInterval::days(15));
Passport::refreshTokensExpireIn(CarbonInterval::days(30));
Passport::personalAccessTokensExpireIn(CarbonInterval::months(6));
// Default scopes
Passport::tokensCan([
'read' => 'Read user information',
'write' => 'Modify user information',
]);
Passport::setDefaultScope(['read']);
The starter kit uses Laravel's built-in ULID support for user IDs, providing:
The User model includes the HasUlids trait:
use Illuminate\Database\Eloquent\Concerns\HasUlids;
class User extends Authenticatable
{
use HasApiTokens, HasFactory, HasUlids, Notifiable, TwoFactorAuthenticatable;
// ...
}
User IDs will be ULIDs like: 01ARZ3NDEKTSV4RRFFQ69G5FAV
If you use a custom user model, ensure it includes the HasUlids trait and update config/auth.php:
'providers' => [
'users' => [
'driver' => 'eloquent',
'model' => App\Models\CustomUser::class, // Your custom model
],
],
Test your OAuth flow:
# Test authorization endpoint
curl -I "http://localhost:8000/oauth/authorize?client_id=your_client_id&redirect_uri=http://your-app.test/authenticate&state=test_state"
# Test token exchange (after getting authorization code)
curl -X POST "http://localhost:8000/user_management/authenticate" \
-H "Content-Type: application/json" \
-d '{
"grant_type": "authorization_code",
"client_id": "your_client_id",
"code": "authorization_code_here"
}'
.env# Install dependencies
composer install --optimize-autoloader --no-dev
# Clear and cache config
php artisan config:cache
php artisan route:cache
php artisan view:cache
# Run migrations
php artisan migrate --force
This starter kit uses the inmanturbo/homework package to provide WorkOS compatibility. The package:
To migrate from WorkOS to this self-hosted solution:
MIT License. See LICENSE for details.
Contributions are welcome! Please feel free to submit a Pull Request.
Self-hosted • Secure • WorkOS Compatible