Authorize User
Audience:
Low-code EngineersSkill Prerequisites:
Actions,User management
Authorizes users, so they can log in. It's the same as checking Authorized for a user in the Users admin page.
It works on the current user and on every user in the context's list of users. In a form, the current user is usually the logged-in user. Use Load User or Load Users from SQL to pick other users.
Users who are already authorized stay authorized.
Typical Use Cases
- Authorize a user after they confirm their email address
- Let an approver authorize a user picked in a Listing
- Authorize a group of users loaded with Load Users from SQL, for example in a scheduled job
Don't use it to
- Create a user. Use User Registration instead. It can authorize the new user itself.
- Unlock a user who's locked out after too many failed logins. Use Unlock User instead.
- Give a user access to a page or feature. Use Grant User Role instead.
Related Actions
| Action Name | Description |
|---|---|
| Unauthorize User | Stops the current user and every user in the list from logging in. |
| Load User | Loads users into the list and makes the last one the current user. |
| Load Users from SQL | Adds the users returned by a SQL query to the list. |
| Change User | Changes the current user without adding it to the list. |
| User Registration | Creates a user, authorized or not. |
| Delete User | Deletes every user in the list. |
Input Parameter Reference
This action has no parameters of its own. It only has the common parameters of all actions.
Output Parameters Reference
This action has no output parameters.
Considerations
- There's no permission check in the action. Anyone who can run it can authorize the users in context. Only put it where you control who runs it.
- Load the right user first. Users who aren't authorized can't log in, so they're rarely the current user. Load them with Load User first, for example by the email in a confirmation link, and check that the right user was found.
- Check who's in the list. Every loaded user is authorized, plus the current user. Users loaded earlier in the same run are still in the list.
- Nothing to do, no error. If there's no current user and the list is empty, for example in a public form, nothing happens.
Examples
To understand how to use the below examples, please see Running Examples.
1. Authorize the user from a confirmation link
These actions load the user whose email is in the Email token, then authorize that user. The condition makes sure the user was found.
{
"Title": "Load User",
"ActionType": "LoadUser",
"Description": "Load the user to authorize",
"Parameters": {
"Id": "[Email]",
"Portal": ""
}
}
{
"Title": "Authorize User",
"ActionType": "AuthorizeUser",
"Description": "Authorize the loaded user",
"Condition": "\"[User:Email]\" == \"[Email]\"",
"Parameters": {}
}
Revised 09/28/2026