Laravel Passport:API控制器获取用户ID始终为NULL的问题
Let's walk through the most common reasons why auth('api')->id() is returning null and how to fix them:
1. Your target route isn't using the auth:api middleware
You showed the /user route uses auth:api, but does the route where you're fetching the Formulaire collection also have this middleware applied? If not, the request won't go through authentication, so auth('api')->id() will be null.
Make sure your formulaire route looks something like this:
Route::middleware('auth:api')->get('/formulaires', [FormulaireController::class, 'index']);
2. The token isn't being sent correctly in the request
Laravel's API authentication expects the token to be included in the Authorization header with the Bearer prefix. For example:
Authorization: Bearer your-generated-token-here
Common mistakes here:
- Forgetting the
Bearerkeyword (just sending the token alone) - Putting the token in a different header like
X-API-Token(unless you've configured Laravel to look there) - Sending the token as a query parameter (not recommended, and won't work by default)
Test this by checking the request headers in your tool (Postman, curl, etc.) to ensure the Authorization header is properly formatted.
3. The token is invalid, expired, or not linked to a user
If you're using Laravel Sanctum (the default for API tokens in recent versions), check the personal_access_tokens table in your database:
- Does the token you're using exist in the
tokencolumn (note: it's stored as a hash, so you'll need to usehash_equals()to compare if you're checking manually) - Is the
revokedcolumn set to0? - Is the
expires_atvalue in the future?
If you're using the older token guard (with an api_token column on the users table), make sure the token matches the value in that column for your user.
4. Your User model is missing the required trait
For Sanctum to work, your User model must use the HasApiTokens trait:
use Laravel\Sanctum\HasApiTokens; class User extends Authenticatable { use HasApiTokens, Notifiable; // Include HasApiTokens here }
Without this trait, Sanctum can't authenticate the user via the token.
5. Your auth guard configuration is incorrect
Check config/auth.php to ensure the api guard is set up properly. For Sanctum, it should look like this:
'guards' => [ 'web' => [ 'driver' => 'session', 'provider' => 'users', ], 'api' => [ 'driver' => 'sanctum', 'provider' => 'users', ], ],
If you're using Passport instead, set the driver to passport and ensure Passport is installed and configured correctly.
Debugging Tip
Add a quick debug line in your controller to see what's happening:
public function index(Request $request) { dd($request->user('api')); // This should show the authenticated user if everything works $user = auth('api')->id(); return FormulaireResource::collection(Formulaire::where('user_id', $user)->paginate(15)); }
If $request->user('api') is null, that confirms the authentication is failing at the middleware level—go back through the steps above to find why.
Start with checking the middleware on the route and the Authorization header; those are the most common culprits!
内容的提问来源于stack exchange,提问作者Sharkerz

