Laravel 5.4中jwt-auth登录API返回invalid_credentials错误排查
Hey there, let's break down why your login API is throwing that frustrating invalid_credentials error—this is a super common issue with JWT auth in Laravel, so we'll work through the most likely fixes step by step:
1. Check if Passwords Are Properly Hashed on Registration
This is the #1 culprit 90% of the time. When you create a user via your registration API, you must hash the password before saving it to the database. Laravel's default hashing uses bcrypt, so double-check your registration code looks something like this:
// Example registration logic $user = new User(); $user->username = $request->username; $user->password = bcrypt($request->password); // Critical line—don't skip this! $user->save();
If you saved plain-text passwords, JWT's attempt() method will fail because it expects to compare the incoming password against a hashed value in the database. Pop open your users table and verify the password column contains a long, random-looking string (not the plain password).
2. Configure JWT to Use username Instead of Default email
By default, JWT-auth and Laravel's auth system use email as the primary identifier. Since you're using username, you need to update your setup:
- Update your User Model: Make sure it implements the
JWTSubjectinterface (required for JWT-auth 1.0.x, which matches Laravel 5.4) and uses the correct identifier:use Illuminate\Foundation\Auth\User as Authenticatable; use Tymon\JWTAuth\Contracts\JWTSubject; class User extends Authenticatable implements JWTSubject { // ... existing model code // Return the user's primary key for JWT public function getJWTIdentifier() { return $this->getKey(); } // Add custom claims if needed (can be empty) public function getJWTCustomClaims() { return []; } } - Adjust Auth Configuration: In
config/auth.php, update theusersprovider to useusernameas the authentication field:
If your JWT guard is configured here, ensure it's pointing to the correct provider.'providers' => [ 'users' => [ 'driver' => 'eloquent', 'model' => App\User::class, 'username' => 'username', // Add this line to specify the login field ], ],
3. Verify Credential Names Match
Double-check that:
- The incoming request actually sends
usernameandpasswordfields (no typos likeuser_nameorpasswd). - Your
usersdatabase table has ausernamecolumn and apasswordcolumn (case-sensitive in some environments).
4. Test Laravel's Core Auth First
Isolate whether the issue is with JWT or Laravel's underlying auth system. Add a quick debug check in your login method:
public function login(Request $request) { $credentials = $request->only('username', 'password'); // Temporary debug: Check if Laravel's core auth accepts the credentials if (!Auth::attempt($credentials)) { return response()->json(['error' => 'Laravel auth rejected credentials'], 401); } // If we get here, try JWT try { $token = JWTAuth::attempt($credentials); if (!$token) { return response()->json(['error' => 'invalid_credentials'], 401); } } catch (JWTException $e) { return response()->json(['error' => 'could_not_create_token'], 500); } return response()->json(compact('token')); }
If Auth::attempt() fails, the problem is with Laravel's auth setup—not JWT. Focus on fixing that first (e.g., password hashing, field names).
5. Confirm JWT-Auth Version Compatibility
Laravel 5.4 requires tymon/jwt-auth version 1.0.* (the 1.x branch). Check your composer.json to ensure you're not using a newer 2.x version (which is for Laravel 5.5+):
"require": { // ... "tymon/jwt-auth": "1.0.*" }
If you have the wrong version, run composer update tymon/jwt-auth to downgrade/upgrade to the correct one.
Start with these checks—chances are one of them will fix your invalid_credentials error. Let me know if you hit any snags!
内容的提问来源于stack exchange,提问作者Omid Nikrah

