Level 75
Probably because the SPA is not a native mobile app. Uses session / cookie Authentication. Not token.
2 likes
Be part of JetBrains PHPverse 2026 on June 9 – a free online event bringing PHP devs worldwide together.
Hi, i was reading the docs (sanctum) and found this:
You should not use API tokens to authenticate your own first-party SPA. Instead, use Sanctum's built-in SPA authentication features.
there is a why not?
Probably because the SPA is not a native mobile app. Uses session / cookie Authentication. Not token.
Please or to participate in this conversation.