hryvinskyi/composer-multi-auth

Composer plugin for per-package HTTP basic auth on a single repository domain

Maintainers

Package info

github.com/hryvinskyi/composer-multi-auth

Type:composer-plugin

pkg:composer/hryvinskyi/composer-multi-auth

Statistics

Installs: 3

Dependents: 0

Suggesters: 0

Stars: 0

Open Issues: 0

1.0.2 2026-03-04 09:54 UTC

This package is auto-updated.

Last update: 2026-03-04 09:54:41 UTC


README

Composer plugin that enables per-package HTTP basic authentication on a single repository domain.

Problem

Composer resolves HTTP basic auth by domain — one credential pair per domain in auth.json. When a single repository hosts packages from different vendors requiring different API keys, there's no native way to use per-package credentials.

How It Works

The plugin reads auth-multi.json from your project root and:

  1. Overrides default auth with the first rule's credentials during repository metadata discovery (so the provider listing includes all packages you need).
  2. Intercepts each download via Composer's PRE_FILE_DOWNLOAD event and applies the correct credentials based on package name glob patterns.
  3. Restores default credentials for packages that don't match any specific rule.

First matching rule wins. Use * as a catch-all.

Requirements

  • PHP 8.1+
  • Composer 2.x

Installation

composer require hryvinskyi/composer-multi-auth

Add to allow-plugins in your composer.json if prompted:

{
    "config": {
        "allow-plugins": {
            "hryvinskyi/composer-multi-auth": true
        }
    }
}

Setup

On first activation the plugin automatically:

  • Creates auth-multi.json.sample in the project root
  • Adds auth-multi.json to .gitignore

Then create your config:

  1. Copy the sample and fill in your keys:
cp auth-multi.json.sample auth-multi.json
  1. Edit auth-multi.json:
{
    "http-basic": {
        "private.repo.example.com": {
            "rules": [
                {
                    "patterns": ["acme/*"],
                    "username": "acme-public-key",
                    "password": "acme-private-key"
                },
                {
                    "patterns": ["*"],
                    "username": "your-default-public-key",
                    "password": "your-default-private-key"
                }
            ]
        }
    }
}

Configuration

auth-multi.json

{
    "http-basic": {
        "<domain>": {
            "rules": [
                {
                    "patterns": ["<glob-pattern>", ...],
                    "username": "<public-key>",
                    "password": "<private-key>"
                }
            ]
        }
    }
}
Field Description
http-basic Top-level key (matches Composer's auth.json structure)
<domain> Repository domain
rules Ordered array of rules — first match wins
patterns Array of glob patterns matched via fnmatch() (e.g., vendor/*, vendor/package)
username HTTP basic auth username / public key
password HTTP basic auth password / private key

Rule ordering

Rules are evaluated top-to-bottom. The first rule whose patterns match the package name is used. Always place specific rules before the catch-all * rule.

Catch-all rule

The catch-all rule ("patterns": ["*"]) should be the last rule and should contain your default auth.json credentials. This ensures packages not matching any specific rule still authenticate correctly.

Important: The first rule's credentials are used for repository metadata discovery (loading the package listing). Place the rule for the packages you need to discover first.

Verification

Run Composer with verbose output to see the plugin in action:

composer install -vvv

Look for [multi-auth] prefixed messages:

Loading plugin Hryvinskyi\ComposerMultiAuth\Plugin
[multi-auth] Loaded rules for 1 domain(s).
[multi-auth] Applying credentials for package "acme/some-package" on "private.repo.example.com".
[multi-auth] Restoring default credentials for package "other/package" on "private.repo.example.com".

License

MIT