Be part of JetBrains PHPverse 2026 on June 9 – a free online event bringing PHP devs worldwide together.

hcastillo's avatar

Why not use API token with SPA's ?

Hi, i was reading the docs (sanctum) and found this:

You should not use API tokens to authenticate your own first-party SPA. Instead, use Sanctum's built-in SPA authentication features.

there is a why not?

0 likes
1 reply
jlrdw's avatar
jlrdw
Best Answer
Level 75

Probably because the SPA is not a native mobile app. Uses session / cookie Authentication. Not token.

2 likes

Please or to participate in this conversation.