Email sign-in
Players enter their email address on the hosted login page and type the six-digit code they receive. There is no password to store, reset or leak.
Turn it on
New projects have email codes turned on. To check or change that:
- Open the project in the console and go to its sign-in methods page.
- Under Sign-up and guest accounts, tick or clear Email verification codes.
- Turn off Allow new players to sign up if only existing players should be able to sign in.
- Select Save sign-in policy.
Email sign-in runs on the hosted login page, so browser applications get it with no extra code. Start the flow with the browser SDK.
What players see
- The player enters an email address. The page always responds the same way, whether or not the address has an account, so it can't be used to find out who has signed up.
- auth4.dev sends a six-digit code. It expires after ten minutes.
- The player can ask for a new code after 60 seconds. A new code replaces the earlier one.
- After at most five wrong guesses the code stops working and the player must request a new one.
- On success, the player sees the scopes your application requests and approves them.
The first verified sign-in with a new address creates a player account. With sign-up turned off, unknown addresses get the same "invalid code" response as a wrong code, and no account is created.
Rate limits
Sending is limited to protect your players and the email service:
| Limit | Value |
|---|---|
| Per sign-in attempt and address | 1 email per 60 seconds |
| Per address in a project | 5 emails per hour |
| Per IP address | 10 emails and 20 code guesses per hour |
| Per project | 500 emails per hour |
When a limit is hit the hosted page shows a "try again later" message. Your application doesn't need to handle it.
What is stored
Codes are stored only as keyed hashes in short-lived state and are never logged. The message payload is encrypted until delivery, then cleared. Delivery-status records are kept for the audit retention period. See Retention and deletion.