I am developing a very big "xyz.com" application. application will have multiple subdomains hosted in multiple servers like "abc.xyz.com" & "def.xyz.com", etc. All of the servers are driven by "laravel-package-development". "xyz" frontend will be SPA and backend will be API-driven. I guess there will 10-20 laravel-packages-developed. and all laravel-pacakages-developed may have their own auth-system. I have doubt in which "package" to use for API-authentication. My considerations for auth-packages are as follows: a. Laravel/Passport or b. Laravel/Sanctum or c. Jwt-Auth.(Sean Tymon) My concerns are as follows:
- Scalability & Support of library for newer php versions like php v8.
- Security.
- multi-domains access of APIs via token. and multi-domains cookie-session-management.
- "Package" repos should have fewer issues.
- mostly i will not need oAuth2.
- package development. I have worked on all a, b, c "packages" from laravel v5.5 to v8.x. Since entire "xyz" application is very very big, i would like to be very sure regarding what "package" i should use. Anyone with experience, please suggest which "package" to use. I vote for "sanctum". ANY SUGGESTION IS HIGHLY APPRECIATED