Auth0 Actions run your code during authentication flows. The Pre User Registration trigger runs before a user is created in a database or passwordless connection, which is exactly where a work-email check belongs.
1. Store the key as a secret
In the Action editor, add a secret named IBE_API_KEY with your ibe_live_… key. Never hard-code it.
2. The Action
Create an Action on the Pre User Registration trigger:
exports.onExecutePreUserRegistration = async (event, api) => {
const email = event.user.email;
if (!email) return;
let verdict;
try {
const res = await fetch('https://api.isbusinessemail.com/v1/check', {
method: 'POST',
headers: {
Authorization: `Bearer ${event.secrets.IBE_API_KEY}`,
'Content-Type': 'application/json',
},
body: JSON.stringify({ email, policy: 'b2b' }),
signal: AbortSignal.timeout(2500),
});
if (!res.ok) return; // fail open: never block signups on our errors
verdict = await res.json();
} catch {
return; // timeout or network error: fail open
}
if (verdict.recommendation === 'block') {
const hint = verdict.did_you_mean ? ` Did you mean ${verdict.did_you_mean}?` : '';
api.access.deny('work_email_required', `Please sign up with your work email.${hint}`);
return;
}
api.user.setUserMetadata('email_category', verdict.category);
api.user.setUserMetadata('google_workspace', verdict.workspace?.google_workspace?.detected ?? false);
api.user.setUserMetadata('microsoft_365', verdict.workspace?.microsoft_365?.detected ?? false);
};
Deploy it and add it to the Pre User Registration flow.
- The second argument to
api.access.denyis the message the user sees; keep it friendly. - Metadata lets your app read the verdict later (for example to pre-select a Microsoft or Google connector).
3. Social connections
Pre User Registration doesn’t run for social connections such as “Sign in with Google”. For those, classify on the first login with a Post Login Action (for example when it’s the user’s first login) and either deny access or flag the account. Remember that a Google social login can be a personal @gmail.com account.
Tips
- Use
policy: 'strict'if your product needs a company tenant from day one;unknownand role accounts are then blocked too. - Actions have execution time limits. Keep the timeout around 2–3 s and fail open.
- Test with
personal@test.isbusinessemail.com(denied) andbusiness@test.isbusinessemail.com(allowed).
Official docs: Auth0 documentation (see Actions and the Pre User Registration trigger). See also: Categories and policies.