Search

Laravel Cloud Tightens Access: Database Users, Scoped API Tokens and Pre-Deploy Checks

Laravel Cloud Tightens Access: Database Users, Scoped API Tokens and Pre-Deploy Checks

Laravel has been pitching Cloud as infrastructure for "Artisans and agents", and that changes the security question. It's no longer only about who on your team can do what, but also what your CI pipeline, reporting tool or AI coding agent is allowed to touch. Three late-summer updates answer it.

Also Read: GPT-6.1 Sol: Pricing, Benchmarks and Is It Worth Switching? - News

1. Managed database users (3 September)

Until now, everyone and everything connected to a Cloud database with the same default credentials. You can now create extra users per database cluster:

  • Choose read-only or read-write access.
  • Limit each user to specific databases.
  • Cloud generates a secure password and keeps the credentials in the cluster panel.
  • Change access or delete a user whenever you like.

Available for Laravel MySQL, RDS MySQL and RDS Postgres clusters.

Typical uses: a read-only login for Metabase or a BI tool, a separate user for a Python or Go service sharing the database, or a contractor who only needs one schema.

2. Scoped API tokens (27 August)

The Laravel Cloud API (which moved out of early access in March 2026) and the CLI let you script deployments, environments, databases, caches, buckets and scaling. Until August, an organisation token meant full organisation access.

Now tokens can be:

  • Limited to specific permissions
  • Restricted to one application or individual environments
  • Created only by organisation admins

Existing tokens keep working. To reduce a token's reach, create a new scoped one and revoke the old one.

Give your AI coding agent a token that can deploy the staging environment of one app, and nothing else.

3. Pre-deploy package checks (27 August)

A small quality-of-life feature that prevents a lot of failed deploys. When you enable something that needs a package, such as Octane, Inertia SSR, Nightwatch or a storage bucket, Cloud shows the install command right next to the setting. Managed queues and scheduled tasks are covered too, including the minimum framework versions they need.

Also Read: DevDay 2026 for Developers: Codex Cloud, Agents API and More

Cloud reads your composer.lock on every push, so the notice disappears as soon as you push the fix. The notices only apply to features you've enabled, and they never block a save or deploy.

The bigger access-control picture

These build on earlier 2026 releases:

DateFeature
2 MarFull Cloud API, new CLI, Google SSO
18 MarSign in with GitHub
7 MayRoles & permissions (advanced RBAC on Business/Enterprise)
13 MayHTTP basic auth for environments (Growth and above)
11 JunProvision Cloud from the Stripe CLI via Stripe Projects
16 JulSecrets Manager
24 JulStaged changes: review a full diff before deploying config changes

FAQ

Can I create a read-only database user on Laravel Cloud? Yes, for Laravel MySQL, RDS MySQL and RDS Postgres clusters.

Can Laravel Cloud API tokens be limited to one environment? Yes. Since August 2026 tokens can be scoped to specific permissions, applications or environments.

Who can create scoped API tokens? Only organisation admins.

Related on The Web Tier

Sources: Laravel Cloud changelog: Managed Database Users; Scoped API Tokens; Pre-Deploy Package Checks; Laravel Cloud API; Roles & Permissions · Laravel August product updates

TWT Staff

TWT Staff

Writes about Programming, tech news, discuss programming topics for web developers (and Web designers), and talks about SEO tools and techniques

Your experience on this site will be improved by allowing cookies Cookie Policy