Laravel Impersonate is a plugin that allows you to authenticate as your users.
Latest commit 8a801ae Feb 23, 2017 @MarceauKa MarceauKa committed on GitHub Restrict laravel dependency to 5.4

Laravel Impersonate

Build Status Scrutinizer Code Quality

Laravel Impersonate makes it easy to authenticate as your users. Add a simple trait to your user model and impersonate as one of your users in one click.


  • Laravel >= 5.4
  • PHP >= 5.6


  • Require it with Composer:
composer require lab404/laravel-impersonate
  • Add the service provider at the end of your config/app.php:
'providers' => [
    // ...
  • Add the trait Lab404\Impersonate\Models\Impersonate to your User model.

Simple usage

Impersonate an user:

// You're now logged as the $other_user

Leave impersonation:

// You're now logged as your original user.

Using the built-in controller

In your routes file you must call the impersonate route macro.

// Where $id is the ID of the user you want impersonate
route('impersonate', $id)

// Generate an URL to leave current impersonation

Advanced Usage

Defining impersonation authorization

By default all users can impersonate an user.
You need to add the method canImpersonate() to your user model:

     * @return bool
    public function canImpersonate()
        // For example
        return $this->is_admin == 1;

By default all users can be impersonated.
You need to add the method canBeImpersonated() to your user model to extend this behavior:

     * @return bool
    public function canBeImpersonated()
        // For example
        return $this->can_be_impersonate == 1;

Using your own strategy

  • Getting the manager:
// With the app helper
// Dependency Injection
public function impersonate(ImpersonateManager $manager, $user_id) { /* ... */ }
  • Working with the manager:
$manager = app('impersonate');

// Find an user by its ID

// TRUE if your are impersonating an user.

// Impersonate an user. Pass the original user and the user you want to impersonate
$manager->take($from, $to);

// Leave current impersonation

// Get the impersonator ID


Protect From Impersonation

You can use the middleware impersonate.protect to protect your routes against user impersonation.
This middleware can be useful when you want to protect specific pages like users subscriptions, users credit cards, ...

Router::get('/my-credit-card', function() {
    echo "Can't be accessed by an impersonator";


There are two events available that can be used to improve your workflow:

  • TakeImpersonation is fired when an impersonation is taken.
  • LeaveImpersonation is fired when an impersonation is leaved.

Each events returns two properties $event->impersonator and $event->impersonated containing User model isntance.


The package comes with a configuration file.

Publish it with the following command:

php artisan vendor:publish --tag=impersonate

Available options:

    // The session key used to store the original user id.
    'session_key' => 'impersonated_by',
    // The URI to redirect after taking an impersonation.
    // Only used in the built-in controller.
    'take_redirect_to' => '/',
    // The URI to redirect after leaving an impersonation.
    // Only used in the built-in controller.
    'leave_redirect_to' => '/'


There is two Blade directives available.

When the user can impersonate

    <a href="{{ route('impersonate', $user->id) }}">Impersonate this user</a>

When the user is impersonated

    <a href="{{ route('impersonate.leave') }}">Leave impersonation</a>