Concierge is pre-1.0. Minor releases may change the API until 1.0.
Skip to content

Configuration ​

Every key in config/concierge.php, with its type, default and what it does, grouped by feature.

Publish the file to change any of them:

bash
php artisan vendor:publish --tag="concierge-config"
# -> config/concierge.php

No key reads an environment variable: set values in the file itself. Local login also checks APP_ENV directly; see When It Is Available.

Features ​

KeyTypeDefaultWhat it does
features.membershipbooltrueTurns membership on. Only false turns it off. When off, Concierge registers no membership bindings, no concierge.member middleware alias and no concierge:sync-roles command, and does not run its migration.
features.tenant_invitationsboolfalseTurns tenant invitations on. Only true turns it on, and only while membership is on. When off, there is no tenant invitations migration, rate limiter or Gate definition.

Both switches are read while the package provider registers, so set them in config/concierge.php, not at runtime. Set features.tenant_invitations before publishing migrations.

Models ​

KeyTypeDefaultWhat it does
models.userclass-string or nullnullYour user model. Required for membership. It must be an Eloquent model implementing Tey\Concierge\Contracts\Member, use Spatie's HasRoles and have an incrementing integer key.
models.workspaceclass-string or nullnullYour workspace model. Required for membership. It must be an Eloquent model implementing Tey\Concierge\Contracts\Workspace, with an incrementing integer key.
models.membershipclass-stringTey\Concierge\Models\MembershipThe membership model. Swap it for a subclass.
models.ownershipclass-stringTey\Concierge\Models\OwnershipThe ownership model. Swap it for a subclass.
models.invitationclass-stringTey\Concierge\Models\InvitationThe workspace invitation model. Swap it for a subclass.
models.tenant_invitationclass-stringTey\Concierge\Models\TenantInvitationThe tenant invitation model. Swap it for a subclass.

The package migrations read models.user and models.workspace to find your tables. With either one missing or invalid, Concierge throws Tey\Concierge\Exceptions\UnsupportedConfiguration naming the key. Membership gives the setup order.

Roles ​

KeyTypeDefaultWhat it does
guardstring or nullnullThe guard name of Concierge's Spatie roles, used when concierge:sync-roles creates them and when Concierge looks them up. null is auth.defaults.guard.
rolesarray<string, array>owner, admin, presenterThe roles, keyed by name, ordered highest rank first. A member outranks another when their highest role comes earlier in this list.
roles.*.labelstring'Owner', 'Admin', 'Presenter'A display name for your app's UI. Concierge itself does not read it.
roles.*.grantable_bylist<string>see belowThe roles whose holders may grant this role. The owner role is never grantable, whatever this says.
owner_rolestring'owner'The role a workspace's owner holds. EstablishWorkspace and TransferOwnership assign it.
transfer_demotes_tostring'admin'The role the previous owner holds after TransferOwnership.
managerslist<string>['owner', 'admin']Roles whose holders may manage members: invite, resend and revoke invitations, change roles, suspend, reinstate and remove.

The default roles:

php
// config/concierge.php
'roles' => [
    'owner' => ['label' => 'Owner', 'grantable_by' => []],
    'admin' => ['label' => 'Admin', 'grantable_by' => ['owner']],
    'presenter' => ['label' => 'Presenter', 'grantable_by' => ['owner', 'admin']],
],

Each role is a global Spatie role (team null), and every assignment is scoped to a workspace. Run php artisan concierge:sync-roles after changing the list: it creates missing roles and deletes none. An action that assigns a role that does not exist throws UnsupportedConfiguration.

The rules these keys feed are listed under Who May Call Them.

Invitations ​

KeyTypeDefaultWhat it does
invitations.expires_after_daysint7Days an invitation link works, counted from when it is created or resent. Applies to workspace and tenant invitations.
invitations.resend_cooldown_secondsint60Minimum seconds between creating or resending an invitation and resending it again. Applies to workspace and tenant invitations.
invitations.deliverbooltrueWhether invitation emails are sent. Set false to create invitations without emailing them. Emails also need an invitation URL: see What Your App Provides.

Tenant Invitations ​

Read only when features.tenant_invitations is true.

KeyTypeDefaultWhat it does
tenant_invitations.abilitystring'concierge.manage-tenants'The Gate ability every changing tenant invitation action checks. Define it yourself, or let Concierge define it from platform_owners.
tenant_invitations.platform_ownerslist<string>[]Emails allowed to manage tenant invitations, compared case-insensitively. The account's email must also be verified. Used only when your app does not define the ability itself.
tenant_invitations.allow_reinvite_after_acceptboolfalseWhen true, an email whose invitation was already accepted can be invited again, and accepting creates an additional workspace. When false, InviteTenant fails validation with "That email already has a workspace."
tenant_invitations.throttle.inspectint30Requests per minute for the concierge-tenant-invitation-inspect limiter.
tenant_invitations.throttle.acceptint10Requests per minute for the concierge-tenant-invitation-accept limiter.
tenant_invitations.throttle.inviteint20Requests per minute for the concierge-tenant-invitation-invite limiter.

Tenant Invitations shows how to apply the limiters to your routes.

Recent Authentication ​

KeyTypeDefaultWhat it does
recent_authentication_secondsint or nullnullHow long after confirming their password the owner may call TransferOwnership. null is auth.password_timeout, or 10800 seconds (three hours) when that is not set.

The default check reads the auth.password_confirmed_at session value that Laravel's password confirmation sets, for the signed-in user only.

Local Login ​

KeyTypeDefaultWhat it does
local_login.enabledboolfalseTurns local login on. Only true turns it on, and only in the local environment.
local_login.account.emailstring or nullnullThe identity value of the account to sign in as. Required: local login is unavailable while it is empty.
local_login.account.namestring or nullnullThe name for an account the click creates. null derives one from the email, so dev@example.test becomes Dev.
local_login.account.attributesarray<string, mixed>[]Extra columns for an account the click creates. The identity and password columns are ignored here.
local_login.identitystring'email'The column the account is looked up and created by.
local_login.guardstring or nullnullThe guard to sign in on; it must use an Eloquent user provider. null is auth.defaults.guard.
local_login.redirectstring or nullnullWhere to go after signing in when there is no intended URL. null is /.
local_login.throttleint10Requests per minute per IP for POST /local-login.

Released under the MIT License. Created by Jasper Tey.