I'm building a registry for self-hosted Laravel Cloud apps and ran into a verification problem: how do you prove an app is actually running without requiring API tokens or credentials?
The problem: Launch directories go stale. People list apps that die months later. Nobody removes their own listing. Visitors click through to dead projects.
What I tried: 1. API token verification — Asked users to paste a Laravel Cloud API token. Stored encrypted, used to inspect environments. Worked but nobody wanted to share tokens. I wouldn't either.
-
URL-based verification — Now I just ask for the *.laravel.cloud URL and run a daily probe:
- DNS resolution check (refuse non-public addresses)
- Slug consistency check (compare Cloud slug against hostname)
- Origin probe (HEAD request, no cookies, no credentials)
- Refuse off-origin redirects
-
Auto-hide on failure — If the daily probe fails, the listing goes private. No auto-republish. I'd rather the page disappear than show a dead app.
The tradeoff: Token verification proved ownership. URL verification proves liveness. I chose liveness because: – Lower friction for users – No secret storage liability – Actually solves the stale listing problem
What I'm stuck on: – Edge cases where a URL could be pointed at someone else's app (slug guessing) – Whether 64KB body cap on GET fallback is enough – How to handle apps behind authentication walls
Tech stack: – Laravel backend – Next.js frontend – Daily cron job for probes – SQLite for state The registry is live at larashipped.laravel.cloud
Questions for the community: 1. How do you handle verification in your self-hosted projects? 2. What edge cases should I watch for with URL-based verification? 3. Is there a better approach I'm missing? Happy to share the probe implementation details if anyone's interested.
Source: r/PHP · by /u/IncomeFair5966