5 Laravel API conventions that save you a week on every project
Every client project I take on used to start the same way: a day wiring up auth, another day on roles and validation, a third day arguing with myself about response shapes. After the third project I extracted the patterns into a starter kit and stopped paying that tax. Here are the five conventions that did the most work.
1. One auth controller, kept boring
All authentication lives in a single Api/AuthController with exactly four methods: register, login, logout, me. Tokens come from Laravel Sanctum — createToken('auth-token')->plainTextToken — and that's it. No Passport, no OAuth dance, no JWT package to maintain.
The auth layer is isolated in one controller, so if you ever outgrow Sanctum you're swapping one file, not rewiring the app. (Honest note: there's no password reset or email verification wired up yet — the User model has the MustVerifyEmail import stubbed and commented, ready for you to enable when you need it.)
2. Validation lives in FormRequest classes, never in controllers
Every endpoint validates through a dedicated FormRequest. Controllers stay thin and readable. One place per endpoint where the rules live. When the frontend team asks "what does this endpoint accept?", the answer is a single file, not a hunt through controller logic.
3. API Resources shape every response
No endpoint ever returns a raw model. A UserResource decides exactly what the client sees — id, name, email, role, timestamps. This is the difference between "it works" and "it's safe" — no password hashes or remember tokens ever leaking because someone returned $user directly.
4. Roles without the ceremony
A role string column on the users table (default 'user') plus one tiny middleware covers 90% of SaaS needs. Aliased as 'role', used like Route::middleware(['auth:sanctum', 'role:admin']). And one detail that matters: registration hardcodes 'role' => 'user' — the role can never be self-assigned through the public endpoint. I didn't pull in a full permissions package on day one. That's a week-two problem, and bolting it on later is easy when the middleware pattern is already there.
5. Routes grouped by who can touch them
routes/api.php reads like an access-control document: public auth endpoints, authenticated endpoints, admin-only endpoints. Three groups. A new developer can see the entire security model of the API in thirty seconds.
None of this is exotic. That's the point — these are the unglamorous decisions that turn "week zero" from five days into an afternoon. I packaged all of them, plus a React dashboard frontend wired to this API, into a starter kit because I was tired of rebuilding it on every project:
Laravel + React SaaS Starter Kit — $19, one-time: https://kamranofficial.gumroad.com/l/mhekoig
Questions about any of these conventions? Drop a comment — happy to dig in.
Top comments (0)