hryvinskyi / composer-multi-auth
Composer plugin for per-package HTTP basic auth on a single repository domain
Package info
github.com/hryvinskyi/composer-multi-auth
Type:composer-plugin
pkg:composer/hryvinskyi/composer-multi-auth
Requires
- php: ^8.1
- composer-plugin-api: ^2.0
Requires (Dev)
- composer/composer: ^2.0
README
Composer plugin that enables per-package HTTP basic authentication on a single repository domain.
Problem
Composer resolves HTTP basic auth by domain — one credential pair per domain in auth.json. When a single repository hosts packages from different vendors requiring different API keys, there's no native way to use per-package credentials.
How It Works
The plugin reads auth-multi.json from your project root and:
- Overrides default auth with the first rule's credentials during repository metadata discovery (so the provider listing includes all packages you need).
- Intercepts each download via Composer's
PRE_FILE_DOWNLOADevent and applies the correct credentials based on package name glob patterns. - Restores default credentials for packages that don't match any specific rule.
First matching rule wins. Use * as a catch-all.
Requirements
- PHP 8.1+
- Composer 2.x
Installation
composer require hryvinskyi/composer-multi-auth
Add to allow-plugins in your composer.json if prompted:
{
"config": {
"allow-plugins": {
"hryvinskyi/composer-multi-auth": true
}
}
}
Setup
On first activation the plugin automatically:
- Creates
auth-multi.json.samplein the project root - Adds
auth-multi.jsonto.gitignore
Then create your config:
- Copy the sample and fill in your keys:
cp auth-multi.json.sample auth-multi.json
- Edit
auth-multi.json:
{
"http-basic": {
"private.repo.example.com": {
"rules": [
{
"patterns": ["acme/*"],
"username": "acme-public-key",
"password": "acme-private-key"
},
{
"patterns": ["*"],
"username": "your-default-public-key",
"password": "your-default-private-key"
}
]
}
}
}
Configuration
auth-multi.json
{
"http-basic": {
"<domain>": {
"rules": [
{
"patterns": ["<glob-pattern>", ...],
"username": "<public-key>",
"password": "<private-key>"
}
]
}
}
}
| Field | Description |
|---|---|
http-basic |
Top-level key (matches Composer's auth.json structure) |
<domain> |
Repository domain |
rules |
Ordered array of rules — first match wins |
patterns |
Array of glob patterns matched via fnmatch() (e.g., vendor/*, vendor/package) |
username |
HTTP basic auth username / public key |
password |
HTTP basic auth password / private key |
Rule ordering
Rules are evaluated top-to-bottom. The first rule whose patterns match the package name is used. Always place specific rules before the catch-all * rule.
Catch-all rule
The catch-all rule ("patterns": ["*"]) should be the last rule and should contain your default auth.json credentials. This ensures packages not matching any specific rule still authenticate correctly.
Important: The first rule's credentials are used for repository metadata discovery (loading the package listing). Place the rule for the packages you need to discover first.
Verification
Run Composer with verbose output to see the plugin in action:
composer install -vvv
Look for [multi-auth] prefixed messages:
Loading plugin Hryvinskyi\ComposerMultiAuth\Plugin
[multi-auth] Loaded rules for 1 domain(s).
[multi-auth] Applying credentials for package "acme/some-package" on "private.repo.example.com".
[multi-auth] Restoring default credentials for package "other/package" on "private.repo.example.com".
License
MIT