PHP REST API Framework
A lightweight, zero-dependency REST API framework for PHP with expressive routing, JWT authentication, request validation, rate limiting, and structured JSON responses. Build APIs fast without the overhead of a full framework.
Overview
Building a REST API should not require pulling in an entire framework with hundreds of dependencies. This micro-framework gives you everything you need to build professional APIs in pure PHP: a fast router, middleware pipeline, request and response objects, JWT authentication, input validation, and consistent error handling.
The design follows PSR standards where practical and keeps the codebase small enough to understand completely. At under 2,000 lines of code, there is no magic or hidden behavior. Every request flows through a clear pipeline from routing to middleware to controller to response.
Key Features
- Expressive route definitions with parameters
- Support for GET, POST, PUT, PATCH, DELETE
- Route groups with shared middleware
- JWT token generation and validation
- Request body parsing (JSON, form data)
- Input validation with custom rules
- Rate limiting per API key or IP
- CORS configuration for cross-origin access
- Consistent JSON error responses
- Pagination helpers for list endpoints
- Request and response logging
- API versioning via URL prefix or header
Code Example
Define routes and handlers with a clean, expressive syntax:
JWT Authentication
The framework includes a complete JWT implementation for stateless API authentication. When a user logs in, the server generates a signed JWT containing the user ID, roles, and an expiration timestamp. Subsequent requests include this token in the Authorization header. The auth middleware verifies the signature, checks expiration, and injects the authenticated user into the request context. Refresh tokens are supported for seamless session renewal without re-entering credentials.
Rate Limiting
Protect your API from abuse with configurable rate limiting. Limits can be set per endpoint, per API key, or per IP address. The default configuration allows 60 requests per minute for authenticated users and 20 per minute for anonymous access. Rate limit headers (X-RateLimit-Limit, X-RateLimit-Remaining, X-RateLimit-Reset) are included in every response so clients can throttle themselves proactively.
Installation Steps
- Download and extract the framework files to your server
- Point your web server document root to the
public/directory - Copy
.env.exampleto.envand configure database and JWT secret - Import
database.sqlfor the users and tokens tables - Configure URL rewriting (Apache .htaccess included, Nginx config provided)
- Test with
GET /api/v1/healthto verify the installation
Server Requirements
| Requirement | Minimum | Recommended |
|---|---|---|
| PHP Version | 8.1 | 8.3+ |
| Database | MySQL 5.7 | MySQL 8.0+ / PostgreSQL 14+ |
| PHP Extensions | PDO, OpenSSL, json, mbstring | + Redis for rate limiting |
| URL Rewriting | Required | mod_rewrite or Nginx |
Error Handling
Every error response follows a consistent JSON structure with a status code, error type, human-readable message, and optional field-level validation details. This makes it easy for front-end developers to parse and display errors consistently. Unhandled exceptions are caught by a global handler that returns a safe 500 response in production while logging the full stack trace for debugging.