Skip to main content
Version: 1.28 (Current)

User/Password Validation

Audience: Low-code Engineers

Skill Prerequisites: Actions, Tokens, Conditions

Checks whether a username and password are correct, without logging the user in. It saves True or False in a token. You can also require the user to be in one of the selected roles.

Typical Use Cases​

  • Ask a logged-in user to confirm their password before a sensitive change, such as deleting their account
  • Check an approver's credentials on a sign-off form
  • Check credentials sent to an API before running the rest of the actions

Don't use it to​

Action NameDescription
User LoginLogs the user in.
Unlock UserUnlocks an account locked by too many failed attempts.
Send User Reset Password EmailSends a password reset link.
Throw ExceptionStops with an error when the check fails.

Input Parameter Reference​

ParameterDescriptionSupports TokensDefaultRequired
UsernameThe username to check, for example [Email] or [User:Username]. Only usernames are looked up, not user IDs. An email address works only when it's the username.Yesempty stringYes
PasswordThe password to check, for example [Password].Yesempty stringYes
Validate user roleThe roles to require. If you select any, the user must be in at least one of them. Leave all unchecked to skip the role check.Nonone selectedNo
Output TokenThe name of the token that receives the result, without brackets, for example IsValid. If it's empty, the action does nothing.Noempty stringNo

Output Parameters Reference​

TokenDescription
[<Output Token>]True if the username and password are correct and the role check passes, otherwise False. The values start with a capital letter.

How the check works​

The action returns False as soon as one of these checks fails:

  1. No user has that username.
  2. Roles are selected, and the user isn't in any of them.
  3. The site's login check doesn't succeed. The password must be correct, and the account must be able to log in. For example, a locked-out or unapproved account returns False even with the right password.

Superusers who pass the login check return True.

Considerations​

  • Failed attempts count as failed logins. The check uses the site's login check, which records wrong passwords. With the site's default membership settings, too many wrong passwords in a short time lock the account. After that, the action returns False until the lockout ends or someone uses Unlock User.
  • The action doesn't limit attempts itself. On a public form or API, anyone can keep trying passwords until the account locks. Consider a CAPTCHA, and don't show whether the username or the password was wrong.
  • It doesn't stop on failure. Add a condition to the next actions, for example [IsValid] == "False" on a Throw Exception.
  • Use HTTPS. The password is sent to the server as it was typed. Only use this action on sites served over HTTPS.
  • Keep the password out of logs. Don't write the Password token to a log or an email.

Examples​

tip

To understand how to use the below examples, please see Running Examples.

1. Confirm the current user's password​

This action checks the password typed in the ConfirmPassword field against the current user's username, and saves the result in IsValid.

{
"Title": "User/Password Validation",
"ActionType": "UserPasswordValidation",
"Description": "Confirm the current user's password",
"Parameters": {
"Username": "[User:Username]",
"Password": "[ConfirmPassword]",
"Roles": {},
"OutputToken": "IsValid"
}
}

The next action stops the submission when the password is wrong:

{
"Title": "Throw Exception",
"ActionType": "ThrowException",
"Description": "Stop if the password is wrong",
"Condition": "[IsValid] == \"False\"",
"Parameters": {
"AdminMessage": "Password confirmation failed for [User:Username].",
"FriendlyMessage": "The password you entered is incorrect."
}
}

Revised 09/28/2026