# Cakephp 4: Install authentication plugin

**URL:** <https://discourse.cakephp.org/t/cakephp-4-install-authentication-plugin/8593>\
**Category:** Need Help\
**Created:** [November 8, 2020, 10:25pm UTC](https://discourse.cakephp.org/t/cakephp-4-install-authentication-plugin/8593 "2020-11-08T22:25:42Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![pwdebruyne](https://avatars.discourse-cdn.com/v4/letter/p/d6d6ee/32.png) [@pwdebruyne](https://discourse.cakephp.org/u/pwdebruyne)\
**Post date:** [November 8, 2020, 10:25pm UTC](https://discourse.cakephp.org/t/cakephp-4-install-authentication-plugin/8593/1 "2020-11-08T22:25:42Z")

</div>

Hi,

I’m following the quickstart guide ([https://book.cakephp.org/authentication/2/en/index.html](https://book.cakephp.org/authentication/2/en/index.html)).  
When installing the plugin using composer, I don’t get an error. The plugin is also mentioned in the composer.json

c omposer require cakephp/authentication  
Using version ^2.3 for cakephp/authentication  
./composer.json has been updated  
Running composer update cakephp/authentication  
Loading composer repositories with package information  
Updating dependencies  
Lock file operations: 1 install, 0 updates, 0 removals  
- Locking cakephp/authentication (2.3.0)  
Writing lock file  
Installing dependencies from lock file (including require-dev)  
Package operations: 1 install, 0 updates, 0 removals  
- Installing cakephp/authentication (2.3.0): Extracting archive  
2 package suggestions were added by new dependencies, use `composer suggest` to see details.  
Package phpunit/php-token-stream is abandoned, you should avoid using it. No replacement was suggested.  
Generating autoload files  
31 packages you are using are looking for funding.  
Use the `composer fund` command to find out more!

However… nothing is added to the plugins directory. I only find the plugin with the vendors.

```
find . -name authentication
./vendor/cakephp/authentication

```

And offcourse, when trying to configurate authentication, I get an error:  
**Error** The application is trying to load a file from the _Authenticate_ plugin.

Make sure your plugin _Authenticate_ is in the \<…\>plugins/ directory and was loaded.

What am I doing wrong? I would expect that everything is put automatically in the plugins directory?

Thanks for your help!

---

<div class="post-metadata">

**Author:** ![Zuluru](https://yyz1.discourse-cdn.com/flex029/user_avatar/discourse.cakephp.org/zuluru/32/1230_2.png) [@Zuluru](https://discourse.cakephp.org/u/Zuluru)\
**Post date:** [November 9, 2020, 12:55am UTC](https://discourse.cakephp.org/t/cakephp-4-install-authentication-plugin/8593/2 "2020-11-09T00:55:02Z")

</div>

`vendor` is the correct place for third-party plugins to go, and it’s in the right place for you. Note that the name of the plugin is “Authentication”; your error messages reference “Authenticate”.

---

<div class="post-metadata">

**Author:** ![pwdebruyne](https://avatars.discourse-cdn.com/v4/letter/p/d6d6ee/32.png) [@pwdebruyne](https://discourse.cakephp.org/u/pwdebruyne)\
**Post date:** [November 9, 2020, 8:12am UTC](https://discourse.cakephp.org/t/cakephp-4-install-authentication-plugin/8593/3 "2020-11-09T08:12:32Z")

</div>

You just made my day. The mistake was indeed the typo Authenticate vs Authentication.  
🥳 👍

---

<div class="post-metadata">

**Author:** ![makamo66](https://yyz1.discourse-cdn.com/flex029/user_avatar/discourse.cakephp.org/makamo66/32/2156_2.png) [@makamo66](https://discourse.cakephp.org/u/makamo66)\
**Post date:** [March 31, 2024, 5:46pm UTC](https://discourse.cakephp.org/t/cakephp-4-install-authentication-plugin/8593/4 "2024-03-31T17:46:39Z")

</div>

> [@Zuluru](#):
>
> `vendor` is the correct place for third-party plugins to go

I have a similar problem and I have the same authentication github download in both vendor and plugins directories but that seems counterintuitive to me. So it’s correct after all to have the same plugin in both folders?

---

<div class="post-metadata">

**Author:** ![Zuluru](https://yyz1.discourse-cdn.com/flex029/user_avatar/discourse.cakephp.org/zuluru/32/1230_2.png) [@Zuluru](https://discourse.cakephp.org/u/Zuluru)\
**Post date:** [April 1, 2024, 1:59pm UTC](https://discourse.cakephp.org/t/cakephp-4-install-authentication-plugin/8593/5 "2024-04-01T13:59:29Z")

</div>

No, third-party plugins should be in the `vendor` folder only.

---

<div class="post-metadata">

**Author:** ![makamo66](https://yyz1.discourse-cdn.com/flex029/user_avatar/discourse.cakephp.org/makamo66/32/2156_2.png) [@makamo66](https://discourse.cakephp.org/u/makamo66)\
**Post date:** [April 1, 2024, 5:32pm UTC](https://discourse.cakephp.org/t/cakephp-4-install-authentication-plugin/8593/6 "2024-04-01T17:32:13Z")

</div>

Thanks, Zuluru. So what do I put in the plugins folder then? And what does a “third-party” plugin mean? Is it the authentication code that I downloaded from github: [GitHub - cakephp/authentication: Authentication plugin for CakePHP. Can also be used in PSR7 based applications.](https://github.com/cakephp/authentication)?

---

<div class="post-metadata">

**Author:** ![Zuluru](https://yyz1.discourse-cdn.com/flex029/user_avatar/discourse.cakephp.org/zuluru/32/1230_2.png) [@Zuluru](https://discourse.cakephp.org/u/Zuluru)\
**Post date:** [April 1, 2024, 6:38pm UTC](https://discourse.cakephp.org/t/cakephp-4-install-authentication-plugin/8593/7 "2024-04-01T18:38:58Z")

</div>

Third-party plugin is a plugin written by somebody else. What goes in your plugins folder would be plugins that _you_ write.
