CLI tool
BinarCode/laravel-restify avatar
BinarCode/laravel-restify

Laravel Restify: JSON:API and MCP Servers From One Repository Class

Laravel API for Ai Agents and humans.

682 stars65 forksPHPMIT

At a glance

What is it?
Laravel Restify turns Eloquent models into JSON:API endpoints and MCP tool definitions from a single repository class, with Laravel policies applied to both. It suits Laravel teams whose API consumers now include AI agents.
Who is it for?
Adopt Laravel Restify if you already run Laravel and want your existing models exposed to AI agents without writing a second API surface by hand. Do not adopt it if your API must serve non-Laravel stacks or you need a framework-neutral MCP server: the whole design assumes Eloquent, Laravel policies and Sanctum.
Can I use it commercially?
Yes. MIT is a permissive licence: you can use, modify and sell software built on it, as long as you keep its copyright and licence notices.
Is it still maintained?
Yes. The repository last received commits 2 days ago.
What is it written in?
Mainly PHP, according to GitHub's language statistics.

Answers come from the project's GitHub data, last synced on September 29, 2026, and from our analysis. They are not legal advice.

Editorial analysis

The Duplicate API Surface Problem Restify Targets

Most Laravel teams already expose their models through controllers, resources and form requests. Adding an AI agent interface usually means a second surface: tool schemas, descriptions, parameter validation, and a separate authorization path that drifts from the HTTP one. Laravel Restify's answer is to make the repository class the single definition. The README states that a repository written once serves both JSON:API endpoints for humans and MCP (Model Context Protocol) servers for agents, and that authentication, authorization and policies apply to both. That last claim is the interesting one. Tool definitions are generated from the same field declarations that drive validation, so an agent calling posts-index-tool hits the same rules a browser would. The project is aimed at Laravel developers who want agent access to existing models without maintaining two contracts. If your models live outside Eloquent, or your API is consumed mainly by other languages and you have no Laravel application, the package has nothing to attach to.

How One Repository Class Produces Two Protocols

The mechanism is a repository class annotated with a model attribute. Fields declared in the fields method carry validation rules and modifiers such as matchable, and the package derives both the JSON:API response shape and the MCP input schema from those declarations. The README example shows a PostRepository with title, content, published_at and a readonly author field, and states that this single definition provides JSON:API CRUD endpoints with validation, MCP tools with the same validation, authorization policies on both interfaces, and search and filtering. The MCP side is registered separately in config/ai.php, where a RestifyServer class is bound to a web route named mcp.restify behind Sanctum middleware. The README shows GET /mcp/restify returning a tools array, with each tool carrying a name, a description and a JSON Schema inputSchema listing parameters such as page, perPage, search, sort and per-field filters. The human side is conventional JSON:API at /api/restify/posts with data, attributes and pagination links. One definition, two serializers. The trade-off is that anything the repository DSL cannot express has to be added outside it, and the README does not document an escape hatch for hand-written MCP tools.

Installing Laravel Restify and Creating a First Repository

The README gives a three-step path. Install the package with Composer, run the setup command, then generate a repository. The setup command is where migrations and configuration land, so run it against a database you can inspect afterwards.

bash
composer require binaryk/laravel-restify
php artisan restify:setup
php artisan restify:repository PostRepository --all

The --all flag is what the README uses to scaffold a full repository. After generation, the repository class lives in your application and declares fields in its fields method. A minimal version following the README's shape looks like this:

php
use Binaryk\LaravelRestify\Http\Requests\RestifyRequest;
use Binaryk\LaravelRestify\Repositories\Repository;
use Binaryk\LaravelRestify\Attributes\Model;

#[Model(Post::class)]
class PostRepository extends Repository
{
    public function fields(RestifyRequest $request): array
    {
        return [
            field('title')->rules('required', 'string', 'max:255'),
            textarea('content')->rules('required'),
            datetime('published_at')->nullable(),
        ];
    }
}

With that in place, the README states the human endpoints are GET, POST, PUT and DELETE under /api/restify/posts. Enabling the agent side is a separate registration in config/ai.php, and the README's snippet binds RestifyServer to the name mcp.restify behind auth:sanctum. Once registered, GET /mcp/restify should return the tool definitions. Two things to check on your first run: that the auth:sanctum middleware matches how your application authenticates agents, and that the generated tool names follow the pattern shown in the README, where the index tool for posts is named posts-index-tool.

Where Laravel Restify Stops Being the Right Tool

The package assumes Laravel all the way down. Repositories wrap Eloquent models through the Model attribute, authorization runs through Laravel policies, and the MCP route in the README is protected by Sanctum. If your data layer is not Eloquent, or your agents authenticate through a different mechanism, you are adapting the package rather than using it. There is a second constraint worth naming: the MCP registration depends on an external Laravel MCP package, since config/ai.php imports Laravel\Mcp\Facades\Mcp and RestifyServer in the same snippet. The README does not state the required version of that package, so compatibility is something you confirm against your lock file rather than assume. The repository ships both docs-v2 and docs-v3 directories, which suggests documentation is mid-migration; the README's examples may not match whichever version you install. Finally, the README does not document rollback for the setup command or a removal path, so treat restify:setup as a change you review before running in a shared environment.

Laravel Restify Compared With Laravel Orion and Hand-Written MCP Servers

The closest comparison in the related searches is Laravel-Orion, another package that generates REST endpoints from Eloquent models. The difference is scope. Orion targets the human API only: you get CRUD endpoints and filtering, and if you later want an agent interface you build it yourself. Restify's design goal is that the same repository definition also emits MCP tool schemas, so the agent surface is generated rather than authored. The other alternative is writing an MCP server by hand against the Laravel MCP package. That gives you full control over tool names, descriptions and schemas, and it is the right choice when your agent tools do not map cleanly onto model CRUD. What you give up is the shared validation and policy path: with a hand-written server you re-implement the rules that already exist in your form requests and policies, and the two can diverge silently. Restify's value is proportional to how closely your agent's needs resemble CRUD over existing models.

Maintenance, Versioning and Licence

The repository is not archived, and the last push was on 2026-08-03. Recent releases include 10.4.20 on 2026-07-17, 10.4.19 on 2026-07-11 and 10.4.18 on 2026-07-08, so patch releases have been arriving on a short cadence. The default branch is 10.x, which means major-version work happens on a named branch rather than main. Upgrade cost is the usual Composer one: because the package generates files into your application, the setup and repository scaffolding steps are not automatically re-run on upgrade, and the repository ships a CHANGELOG.md and RELEASE.md that are the place to check before bumping. The licence is MIT, which permits commercial use and modification; the LICENSE.md file in the repository is the authoritative text, and this article is not legal advice. The README also points to Restify Boost, a dev-only companion installed with composer require --dev binarcode/laravel-restify-boost, which exposes documentation and generation help to AI tools. That is a separate package with its own repository, so treat its maintenance separately from the core.

What to Verify Before You Commit

Three checks are worth doing on a throwaway branch. First, run restify:setup and read the generated migrations and config before merging, since the README does not describe what they contain. Second, register the MCP route exactly as the README shows and confirm GET /mcp/restify returns a tools array whose entries match your repositories, including the naming pattern where the posts index tool is posts-index-tool. Third, confirm that a policy denial on the human endpoint also blocks the corresponding agent tool, because the shared-authorization claim is the main reason to choose this package over a hand-written MCP server. If the third check fails or is hard to demonstrate, the unified-authorization argument is weaker than the README implies, and a hand-written server with explicit policy calls may be the more honest design.

Editorial conclusion

Adopt Laravel Restify if you already run Laravel and want your existing models exposed to AI agents without writing a second API surface by hand. Do not adopt it if your API must serve non-Laravel stacks or you need a framework-neutral MCP server: the whole design assumes Eloquent, Laravel policies and Sanctum. Before committing, verify the MCP wiring against your installed Laravel MCP package, confirm that restify:setup migrations match your schema, and read the docs-v3 directory in the repository, since the README examples reference config/ai.php while the repository also ships docs-v2.

Frequently asked questions

What is Laravel Restify and what does it generate?

Laravel Restify is a package that turns Eloquent models into JSON:API endpoints and MCP servers from a single repository class. The README states that one definition provides CRUD endpoints, MCP tools, shared validation and Laravel policies for both interfaces.

How do I install Laravel Restify?

Install it with composer require binaryk/laravel-restify, then run php artisan restify:setup and generate a repository with php artisan restify:repository PostRepository --all. The README gives these as the three setup steps.

Does Laravel Restify expose an MCP server for AI agents?

Yes. The README registers a RestifyServer in config/ai.php behind auth:sanctum under the route name mcp.restify, and states that GET /mcp/restify returns tool definitions for agents. That registration depends on the Laravel MCP package, which the README imports in the same snippet.

Is Laravel Restify free to use in commercial projects?

The repository licence is MIT, which permits commercial use and modification. The LICENSE.md file in the repository is the authoritative text; this answer is not legal advice.

Official sources

  1. BinarCode/laravel-restify on GitHub
  2. License: MIT
  3. Project website
  4. README
  5. Releases
Add this badge to your README

If you maintain this project, the badge below links readers to this analysis and shows its maintenance status from the daily GitHub snapshot. Paste the markdown into your README; add ?metric=license or ?metric=stars to the image URL for a different field.

Add this badge to your README

markdown
[![Hysen Labs](https://hysenlabs.com/badge/binarcode-laravel-restify.svg)](https://hysenlabs.com/projects/binarcode-laravel-restify)