// the find
1EdTech/lti-1-3-php-library
A PHP library for building LTI 1.3 tool providers. It covers the OIDC login flow, launch validation, deep linking responses, and the Assignments and Grades and Names and Roles services. It is for PHP teams that need to act as an LTI tool and would rather not hand-roll the JWT and OIDC plumbing.
The scope is tight: it implements LTI 1.3 and the Advantage specs and says it will decline vendor-specific changes, which keeps the API from sprawling. The Database interface leaves registration storage to the caller, so the library works with whatever schema or ORM you already have. Launch validation is split by type, with separate validators for resource, deep linking, and submission review launches, so the rules for each don't get tangled together. JWKS generation works from either a registration or a raw KID-to-key map, which covers key rotation without extra code.
The last push was August 2024. For a security-sensitive protocol library, two years without commits is a fair question about who maintains it. The README examples don't run as written. The line `$launch_id = $launch->get_launch_id().` ends in a stray period, which is a PHP parse error. The snippets also call `LTI_OIDC_Login::new` and `LTI_Message_Launch::from_cache` unqualified after `use \IMSGlobal\LTI;`, which doesn't resolve. Composer installs from `dev-master` through a VCS repository entry, and the example pins no tagged release, so each `composer update` can pull in whatever is on master. The visible tree has no tests directory (the listing is truncated), and correctness here depends on signature and claim checks, so I would want to see tests before adopting it.