Skip to main content
Sign-in rules control who is allowed into your app. Keep sign-up open to everyone, or approve a list of email addresses and domains so only those people can create an account and sign in.
Sign-in Rules tab showing sign-up access options and a table of approved domains

Where do I find sign-in rules?

Click Users & AccessSign-in Rules in your app sidebar. Sign-in rules are available on apps using Hercules Auth 2.0. If your app was created before Hercules Auth 2.0, upgrade it first. Editing rules requires a Business plan or higher.

Who can sign up?

Pick one of two options:
  • Allow everyone: anyone who reaches your sign-in page can create an account. This is the default.
  • Only people I approve: only people matching your rules can create an account or sign in.
Your choice takes effect right away. Switching back to Allow everyone keeps your rules saved, they just stop being enforced.

How do I approve an email address or domain?

  1. Choose email addresses or domains.
  2. Paste the values into the box, one per line.
  3. Add a reason if you want a note about why they are approved (optional).
  4. Click Add sign-in rule.
Rules save as soon as you add them. Approve a domain like acme-corp.com to let in everyone with an email at that domain, or approve jane@acme-corp.com to let in one person.

How do I remove a rule?

Click the three dots at the end of the rule’s row, then click Remove rule and confirm. Removing a rule can immediately change who is allowed in. Anyone who no longer matches is signed out the next time they try to sign in.

What do blocked users see?

They see: “This app is limited to approved email addresses. Contact the app owner to request access.” The message never reveals which rules exist or whether the address already has an account.
Yes. Rules are checked when an account is created and again on every sign-in after that. Users who already have an account but do not match your rules are signed out at their next sign-in.
Matching is not case sensitive. A domain rule matches everything after the @ in the user’s email address, and it has to match in full. Approving acme-corp.com does not let in jane@eng.acme-corp.com, so add each subdomain you want to approve. If an address matches both a block rule and an allow rule, the block wins.
No. Those accounts have no real email address to match, so they cannot sign in while Only people I approve is on. Use an email based sign-in method instead, or keep sign-up open to everyone.
Up to 1,000 rules, with each email address or domain up to 255 characters.
Rules you already saved keep being enforced, so your app’s door stays shut rather than opening to everyone. You can still see the list, but you need a Business plan or higher to edit it.

What’s next?

Manage Users

Manage users, roles, and permissions

Customize Login & Sign up

Customize login methods, branding, and domains