User/Password Validation
Audience:
Low-code EngineersSkill Prerequisites:
Actions,Tokens,Conditions
Checks whether a username and password are correct, without logging the user in. It saves True or False in a token. You can also require the user to be in one of the selected roles.
Typical Use Cases
- Ask a logged-in user to confirm their password before a sensitive change, such as deleting their account
- Check an approver's credentials on a sign-off form
- Check credentials sent to an API before running the rest of the actions
Don't use it to
- Log the user in. Use User Login instead.
- Check a password reset link. Use Validate User Reset Password instead.
Related Actions
| Action Name | Description |
|---|---|
| User Login | Logs the user in. |
| Unlock User | Unlocks an account locked by too many failed attempts. |
| Send User Reset Password Email | Sends a password reset link. |
| Throw Exception | Stops with an error when the check fails. |
Input Parameter Reference
| Parameter | Description | Supports Tokens | Default | Required |
|---|---|---|---|---|
| Username | The username to check, for example [Email] or [User:Username]. Only usernames are looked up, not user IDs. An email address works only when it's the username. | Yes | empty string | Yes |
| Password | The password to check, for example [Password]. | Yes | empty string | Yes |
| Validate user role | The roles to require. If you select any, the user must be in at least one of them. Leave all unchecked to skip the role check. | No | none selected | No |
| Output Token | The name of the token that receives the result, without brackets, for example IsValid. If it's empty, the action does nothing. | No | empty string | No |
Output Parameters Reference
| Token | Description |
|---|---|
[<Output Token>] | True if the username and password are correct and the role check passes, otherwise False. The values start with a capital letter. |
How the check works
The action returns False as soon as one of these checks fails:
- No user has that username.
- Roles are selected, and the user isn't in any of them.
- The site's login check doesn't succeed. The password must be correct, and the account must be able to log in. For example, a locked-out or unapproved account returns
Falseeven with the right password.
Superusers who pass the login check return True.
Considerations
- Failed attempts count as failed logins. The check uses the site's login check, which records wrong passwords. With the site's default membership settings, too many wrong passwords in a short time lock the account. After that, the action returns
Falseuntil the lockout ends or someone uses Unlock User. - The action doesn't limit attempts itself. On a public form or API, anyone can keep trying passwords until the account locks. Consider a CAPTCHA, and don't show whether the username or the password was wrong.
- It doesn't stop on failure. Add a condition to the next actions, for example
[IsValid] == "False"on a Throw Exception. - Use HTTPS. The password is sent to the server as it was typed. Only use this action on sites served over HTTPS.
- Keep the password out of logs. Don't write the
Passwordtoken to a log or an email.
Examples
tip
To understand how to use the below examples, please see Running Examples.
1. Confirm the current user's password
This action checks the password typed in the ConfirmPassword field against the current user's username, and saves the result in IsValid.
{
"Title": "User/Password Validation",
"ActionType": "UserPasswordValidation",
"Description": "Confirm the current user's password",
"Parameters": {
"Username": "[User:Username]",
"Password": "[ConfirmPassword]",
"Roles": {},
"OutputToken": "IsValid"
}
}
The next action stops the submission when the password is wrong:
{
"Title": "Throw Exception",
"ActionType": "ThrowException",
"Description": "Stop if the password is wrong",
"Condition": "[IsValid] == \"False\"",
"Parameters": {
"AdminMessage": "Password confirmation failed for [User:Username].",
"FriendlyMessage": "The password you entered is incorrect."
}
}
Revised 09/28/2026