# Authentication gate

Require respondents to sign in or enter a password before submitting.

## Authentication gate

Control who can access your form. Require sign-in to tie responses to verified identities, or add a password to limit access to people who have the code.

> ℹ️ **Public links only**
> <p>
>     Both gates apply to the public share link. A <a href="/requests/creating-requests">request</a> is addressed to one recipient and opens
>     from a signed link, so it skips them.
>   </p>

<h2 id="require-authentication">Require authentication</h2>

In **Form settings → Access**, toggle **Require authentication**. Respondents must sign in before they can view or fill out the form.

<h3 id="whats-enforced">What's enforced</h3>

- The respondent must sign in — the only two methods are Google and an email magic link (they enter their email and receive a sign-in link)
- Their identity is recorded with the submission
- Drafts are tied to the account, not a browser cookie — so they can resume from any device
- Without authentication, duplicate-submission blocking is per-browser only. With authentication, it's per-account across all devices

<h3 id="internal-forms">Internal forms</h3>

With authentication enabled, anyone who opens the form must sign in first. Their email address is recorded with each submission, so you can verify respondents belong to your company domain — no single sign-on setup needed. Share the link with your team and you're done.

<h3 id="when-to-use-it">When to use it</h3>

- **Internal forms** — share the link internally and require sign-in so every response has a verified company email attached
- **Member-only flows** — only existing customers should respond
- **Anti-fraud** — financial or high-value forms where anonymous submissions are too risky

<h3 id="when-not-to-use-it">When NOT to use it</h3>

Public-facing forms like newsletter signups, contact forms, and lead-gen pages tend to lose conversions when sign-in is required. For those, [CAPTCHA](/building-forms/captcha-bot-protection) is usually a better fit.

> ℹ️ **One response per user**
> <p>
>     When authentication is enabled and <strong>Allow another response</strong> (in Form settings → Submissions) is off — the default — each
>     signed-in user can only submit once. Further attempts from the same account are blocked on every device. To cap the total number of
>     respondents as well, add a <a href="/sharing-publishing/response-limits">response limit</a> to the share link.
>   </p>

<p>
  Looking to verify an email <em>answer</em> instead of who opens the form? The gate verifies the person signing in.{' '}
  <a href="/building-forms/email-verification">Respondent email verification</a> confirms the address typed into an Email question with a
  one-time code — no sign-in needed.
</p>

<h2 id="password-protect">Password protect</h2>

Turn on **Password protect** in **Form settings → Access** and type a password. The form stays publicly reachable by URL, but respondents see "Password required" until they enter it.

<h3 id="how-it-works">How it works</h3>

- The password is checked on the server against a salted hash. The form's questions are never sent to the browser before it matches
- A wrong entry shows "Incorrect password" and nothing else is revealed
- Share the password through whichever channel you trust: email, internal docs, a payment receipt
- Anyone with the password can submit

> ⚠️ **Enable the toggle and set a password together**
> <p>
>     If you publish with the toggle on but no password saved, formbase warns you and turns the gate off rather than locking everyone out.
>     Check the publish dialog if you expected a gate and respondents get straight in.
>   </p>

<h3 id="rotating-the-password">Rotating the password</h3>

You can change the password at any time. Respondents who are already filling the form keep their session, because their access key was
minted before the change. New visitors need the updated password.

> ℹ️ **Pair with response limits**
> <p>
>     For paid content, combine the password with a response limit on the share link so a single password isn't shared and reused infinitely.
>     You can also set the limit to 1 to make a link single-use.
>   </p>

<h2 id="next-steps">Next steps</h2>
<div class="not-prose grid gap-3 sm:grid-cols-2">
  - [CAPTCHA / bot protection](/building-forms/captcha-bot-protection) — Block automated submissions on public forms
  - [Scheduled close](/sharing-publishing/scheduled-close) — Auto-close forms immediately or on a set date
  - [Response limits](/sharing-publishing/response-limits) — Cap submissions per share link
</div>
