# Sign-up and access

> Who can create an account in the community, guest access, how sign-up and sign-in work, the invite link, the temporary password, password recovery and the security emails.

In **Settings › General**, the **Access Control** block decides how people get into the community.

## What it's for

| Community | How people should get in |
|---|---|
| A podcast's open community | Open sign-up; guests see what is public |
| Online school | Open sign-up, but content only for paying members |
| A company's HR | Closed sign-up; only people the company invites |
| Coworking space | Closed sign-up; residents are invited when they sign the contract |

## How it works

### The toggles

| Toggle | What it does |
|---|---|
| **Allow New Sign-ups** | *"Allow new members to create accounts in your community"*. When on, **Sign Up** appears. When off, only invited people get in |
| **Guest Access** | *"Allow visitors to view public content"*: people who aren't signed in see the **Public** sections and spaces |
| **Allow free user registration?** | *"When disabled, only users with paid subscription can sign up"* |

> [!SOON]
> The **Allow free user registration?** toggle is saved, but it doesn't restrict sign-up yet. Until it does, for a paying-members-only community, keep your content in **Subscribers** spaces or in spaces that are **Private** by plan: whoever signs up without paying gets in, but only sees what is for members.

### Who can change them

The **owner** and **admins**.

### Sign-up

With sign-up open, anyone who opens the community's address sees **Sign Up** (*"Join … and connect with your community"*):

1. **Name**, **email** and a **password** (at least 8 characters, with an uppercase letter, a lowercase letter and a number).
2. **Create account**.
3. The person joins right away as a **Member** and receives the welcome email.

Anyone who already has a Memberfy account (from another community) signs in with the same login.

### Sign-in

**Sign in** (*"Sign in to …"*): email and password. With wrong details: *"Invalid email or password"*. A session lasts 7 days; after that, *"Your session has expired. Please log in again."*

### Setting the password from the invite

Someone invited without an account receives the email with **Set my password**. The link opens the community's **Set your password** page, is valid for **7 days** and can only be used once. The person types the password twice, clicks **Set password** and signs in with their email and the new password. See [Invite members](/membros/convidar-membros#the-link-to-set-the-password).

### Temporary password

Anyone who receives a temporary password (the owner of a new community, someone recovering their password) is asked to change it on first sign-in: *"You are using a temporary password. For security, change it now!"* (Temporary password, New password, Confirm new password, **Change password**).

### Changing the password

Signed in, in **My Account › Security**: **Current password**, **New password**, **Confirm the new password** and **Change password**, with the same rule as sign-up. A wrong current password is flagged in the form itself, without signing the person out. See [Account and profile](/conceitos/conta-e-perfil#change-the-password).

### Forgot password

1. In the sign-in window, **Forgot password?**.
2. Type your email and click **Recover Password**.
3. *"If the email exists, you will receive instructions to recover your password"*: the email arrives with the way to sign in and change the password.

The message is the same whether or not the account exists, so nobody can find out who is a member.

### Security emails

The platform sends an email when there is a **new sign-in** and when the **password is changed**. Anyone who gets a notice they don't recognize should change their password.

## Step by step: close sign-up

*Role: owner or admin.*

1. **Settings › General › Access Control**.
2. Turn off **Allow New Sign-ups**.
3. Save. **Sign Up** disappears; new members only by invite. See [Invite members](/membros/convidar-membros).

## Examples

**A school with an open storefront.** Open sign-up, **Guest Access** on, a public **Start here** section and a **Student area** that is private by plan. A guest reads the storefront, creates an account and subscribes to get into the student area.

**A company's HR.** Closed sign-up, guests off, every space set to **Members**. The team invites the employees.

## Common errors and how to fix them

| Message | What to do |
|---|---|
| *Email is already registered* | The person already has an account: use **Sign in** or **Forgot password?** |
| *Invalid email or password* | Check the details, or recover the password |
| *Password must be at least 8 characters* (and the other rules) | Follow the password rules |
| *Your session has expired. Please log in again.* | Sign in again |
| **Sign Up** doesn't appear | **Allow New Sign-ups** is off |

## Frequently asked questions

**Can I approve each sign-up first?**
There is no sign-up approval. To control who gets in, close sign-up and invite people.

**Does someone who signs up pay anything?**
No. Signing up is free; paying means subscribing to a plan.

**Can people sign in with Google?**
No. Sign-in is by email and password.

## In the API

`POST /api/auth/register`, `POST /api/auth/login`, `POST /api/auth/recovery-password`, `PUT /api/auth/change-password`; the toggles in `PATCH /api/communities/{id}/settings`. See [Auth](/api/referencia/auth) and [Authentication](/api/autenticacao).

## Related

- [Invite members](/membros/convidar-membros)
- [Visibility and access](/conceitos/visibilidade-e-acesso)
- [Platform emails](/notificacoes/emails-da-plataforma)
