laranail/env-kit-webui is not published to Packagist, so there is no registry-version badge to show: see Install.
A framework-agnostic web companion for
laranail/env-kit— a JSON CRUD API and a themed HTML panel that drive the engine, never re-implement it. Disabled by default, auth-gated, and production-write-blocked.
Requires PHP ^8.4.1, Laravel ^13, and laranail/env-kit.
composer require laranail/env-kit-webui
php artisan vendor:publish --tag=laranail::env-kit-webui-configENV_KIT_WEBUI_ENABLED=true # turn it on deliberately-
The API routes are auth-gated with
['api', 'auth:sanctum']by default. Adjustroute.middlewarein the published config to match your auth stack (Sanctum, session, a custom guard). -
Optionally set a shared secret, which the API then requires in the
X-EnvKit-Tokenheader:ENV_KIT_WEBUI_TOKEN=
# Read one key through the JSON API (secret-shaped values come back masked)
curl -H "Authorization: Bearer $SANCTUM_TOKEN" -H "Accept: application/json" \
https://acme.test/api/v1/env-kit/keys/APP_NAME
# Write one; the engine commits it atomically, with a backup and an audit entry
curl -X PUT -H "Authorization: Bearer $SANCTUM_TOKEN" -H "Accept: application/json" \
-H "Content-Type: application/json" -d '{"value":"smtp.acme.test"}' \
https://acme.test/api/v1/env-kit/keys/MAIL_HOSTRoute names are laranail-env-kit-webui.keys.* and laranail-env-kit-webui.panel, the API
limiter is laranail-env-kit-webui.api, the Livewire panel is laranail-env-kit-webui.panel,
and the Filament page slug is laranail-env-kit-webui. The older bare names (env-kit.*
routes, the env-kit limiter, the env-kit-panel component and the env-kit page slug) are
deprecated aliases that still work, each announcing its replacement once.
The full walkthrough is in JSON API; everything else is in the documentation index.
Full documentation is at opensource.simtabi.com/documentation/laranail/env-kit-webui — what you get, enabling + auth-gating, the JSON API, the HTML panel + themes, and configuration.
Issues and PRs are welcome — see CONTRIBUTING.md. Report vulnerabilities per SECURITY.md (opensource@simtabi.com); participation follows the Code of Conduct.
MIT © Simtabi LLC. See LICENSE.