You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Laravel 5.4中jwt-auth登录API返回invalid_credentials错误排查

Troubleshooting "invalid_credentials" Error in Laravel 5.4 JWT-Auth Login API

Hey there, let's break down why your login API is throwing that frustrating invalid_credentials error—this is a super common issue with JWT auth in Laravel, so we'll work through the most likely fixes step by step:

1. Check if Passwords Are Properly Hashed on Registration

This is the #1 culprit 90% of the time. When you create a user via your registration API, you must hash the password before saving it to the database. Laravel's default hashing uses bcrypt, so double-check your registration code looks something like this:

// Example registration logic
$user = new User();
$user->username = $request->username;
$user->password = bcrypt($request->password); // Critical line—don't skip this!
$user->save();

If you saved plain-text passwords, JWT's attempt() method will fail because it expects to compare the incoming password against a hashed value in the database. Pop open your users table and verify the password column contains a long, random-looking string (not the plain password).

2. Configure JWT to Use username Instead of Default email

By default, JWT-auth and Laravel's auth system use email as the primary identifier. Since you're using username, you need to update your setup:

  • Update your User Model: Make sure it implements the JWTSubject interface (required for JWT-auth 1.0.x, which matches Laravel 5.4) and uses the correct identifier:
    use Illuminate\Foundation\Auth\User as Authenticatable;
    use Tymon\JWTAuth\Contracts\JWTSubject;
    
    class User extends Authenticatable implements JWTSubject
    {
        // ... existing model code
    
        // Return the user's primary key for JWT
        public function getJWTIdentifier()
        {
            return $this->getKey();
        }
    
        // Add custom claims if needed (can be empty)
        public function getJWTCustomClaims()
        {
            return [];
        }
    }
    
  • Adjust Auth Configuration: In config/auth.php, update the users provider to use username as the authentication field:
    'providers' => [
        'users' => [
            'driver' => 'eloquent',
            'model' => App\User::class,
            'username' => 'username', // Add this line to specify the login field
        ],
    ],
    
    If your JWT guard is configured here, ensure it's pointing to the correct provider.

3. Verify Credential Names Match

Double-check that:

  • The incoming request actually sends username and password fields (no typos like user_name or passwd).
  • Your users database table has a username column and a password column (case-sensitive in some environments).

4. Test Laravel's Core Auth First

Isolate whether the issue is with JWT or Laravel's underlying auth system. Add a quick debug check in your login method:

public function login(Request $request) { 
    $credentials = $request->only('username', 'password');
    
    // Temporary debug: Check if Laravel's core auth accepts the credentials
    if (!Auth::attempt($credentials)) {
        return response()->json(['error' => 'Laravel auth rejected credentials'], 401);
    }

    // If we get here, try JWT
    try {
        $token = JWTAuth::attempt($credentials);
        if (!$token) {
            return response()->json(['error' => 'invalid_credentials'], 401);
        }
    } catch (JWTException $e) {
        return response()->json(['error' => 'could_not_create_token'], 500);
    }

    return response()->json(compact('token'));
}

If Auth::attempt() fails, the problem is with Laravel's auth setup—not JWT. Focus on fixing that first (e.g., password hashing, field names).

5. Confirm JWT-Auth Version Compatibility

Laravel 5.4 requires tymon/jwt-auth version 1.0.* (the 1.x branch). Check your composer.json to ensure you're not using a newer 2.x version (which is for Laravel 5.5+):

"require": {
    // ...
    "tymon/jwt-auth": "1.0.*"
}

If you have the wrong version, run composer update tymon/jwt-auth to downgrade/upgrade to the correct one.

Start with these checks—chances are one of them will fix your invalid_credentials error. Let me know if you hit any snags!

内容的提问来源于stack exchange,提问作者Omid Nikrah

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.26 08:30:55