Skip to main content
View as Markdown

Registration Control

Declaring a strategy says how someone authenticates. It does not say whether a stranger may create an account in the first place. auth.allowSignUp is that second decision, and it is independent of which strategies you enabled.

app.yaml
auth:
  allowSignUp: false
  strategies:
    - type: emailAndPassword
Value Behavior
true (default) Anyone can self-register via the enabled strategies.
false Self-registration is disabled. Only admins create users via POST /api/auth/admin/create-user or invitations.

The default is true because it is the right answer for a public product. It is the wrong answer for most internal tools and every customer portal — in those, an account is something you are given, and leaving self-registration on means anyone who finds the URL is one form away from a session.

Gating with Invitations

With self-registration off, you still need a way to onboard real people that does not involve an admin inventing and transmitting a password. Invitations are that path: an admin issues a single-use token, Sovrium emails a link, and the invitee sets their own password.

app.yaml
auth:
  allowSignUp: false
  strategies:
    - type: emailAndPassword
  invitationTokenExpiry: 7d
Property Description
invitationTokenExpiry Lifetime of tokens from POST /api/auth/admin/invite-user. Duration string (72h, 7d) or milliseconds. Defaults to 72h.

A duration string is <positive integer><unit> with unit one of s, m, h, d30s, 15m, 72h, 7d. A bare number is read as milliseconds. Anything else fails validation.

Shorter expiries suit high-security customer portals; the 72h default suits B2B onboarding, where an invitee may not check email the same day. Tokens are single-use either way, consumed on first successful accept.

Which Path to Use

You want Set
A public product anyone can join allowSignUp: true (or omit it).
A closed app, users onboarded by email allowSignUp: false + invitations.
A closed app, accounts provisioned by a script allowSignUp: false + POST /api/auth/admin/create-user.
Federated-only access, no local accounts allowSignUp: false + an oauth strategy.

Last updated September 1, 2026

This documentation was written with AI, so errors or outdated content are possible. Sovrium is in beta. Contributions and corrections are welcome.

Built with Sovrium