Email sign-in

Players enter their email address on the hosted login page and type the six-digit code they receive. There is no password to store, reset or leak.

Turn it on

New projects have email codes turned on. To check or change that:

  1. Open the project in the console and go to its sign-in methods page.
  2. Under Sign-up and guest accounts, tick or clear Email verification codes.
  3. Turn off Allow new players to sign up if only existing players should be able to sign in.
  4. Select Save sign-in policy.

Email sign-in runs on the hosted login page, so browser applications get it with no extra code. Start the flow with the browser SDK.

What players see

  1. The player enters an email address. The page always responds the same way, whether or not the address has an account, so it can't be used to find out who has signed up.
  2. auth4.dev sends a six-digit code. It expires after ten minutes.
  3. The player can ask for a new code after 60 seconds. A new code replaces the earlier one.
  4. After at most five wrong guesses the code stops working and the player must request a new one.
  5. On success, the player sees the scopes your application requests and approves them.

The first verified sign-in with a new address creates a player account. With sign-up turned off, unknown addresses get the same "invalid code" response as a wrong code, and no account is created.

Rate limits

Sending is limited to protect your players and the email service:

LimitValue
Per sign-in attempt and address1 email per 60 seconds
Per address in a project5 emails per hour
Per IP address10 emails and 20 code guesses per hour
Per project500 emails per hour

When a limit is hit the hosted page shows a "try again later" message. Your application doesn't need to handle it.

What is stored

Codes are stored only as keyed hashes in short-lived state and are never logged. The message payload is encrypted until delivery, then cleared. Delivery-status records are kept for the audit retention period. See Retention and deletion.