auth

Work-email checks with FusionAuth

Classify FusionAuth users with isBusinessEmail from a user-creation webhook, optionally blocking the registration, plus a pre-check for your own form.

isBusinessEmail for FusionAuth

FusionAuth sends webhooks for events such as a user being created or registered. Point one at a small endpoint of yours that calls isBusinessEmail. FusionAuth also lets you configure how event transactions behave, so a failing webhook can stop the operation. Check FusionAuth’s webhook documentation for which events and settings support that in your version.

The webhook endpoint (Express)

import express from 'express';

const app = express();
app.use(express.json());

async function checkWorkEmail(email) {
  try {
    const res = await fetch('https://api.isbusinessemail.com/v1/check', {
      method: 'POST',
      headers: {
        Authorization: `Bearer ${process.env.IBE_API_KEY}`,
        'Content-Type': 'application/json',
      },
      body: JSON.stringify({ email }),
      signal: AbortSignal.timeout(2500),
    });
    return res.ok ? await res.json() : { recommendation: 'allow', failOpen: true };
  } catch {
    return { recommendation: 'allow', failOpen: true };
  }
}

app.post('/webhooks/fusionauth', async (req, res) => {
  // Authenticate the webhook first (shared secret header or signature; see FusionAuth docs).
  const event = req.body?.event;
  const email = event?.user?.email;
  if (!email) return res.sendStatus(200);

  const verdict = await checkWorkEmail(email);
  await saveVerdict(event.user.id, verdict); // your DB, or user.data via the FusionAuth API

  // If this webhook is configured to block the transaction, a non-2xx response stops it.
  if (verdict.recommendation === 'block') return res.status(422).send('work email required');
  return res.sendStatus(200);
});

app.listen(3000);

Blocking vs flagging

  • Flag (simplest, safest): always return 200, store the verdict, and let your app restrict accounts with block or review.
  • Block: with a transaction-blocking webhook, return non-2xx on block. Make sure every failure on our side still returns 200, which is why checkWorkEmail fails open.

Your own sign-up form

If you render your own sign-up page and call FusionAuth’s registration API from your server, check the address first and show the error inline, the friendlier option. See the signup form guide.

Tips

  • Store email_category and Microsoft 365 / Google Workspace detection in the user’s data so your app can route onboarding without another call.
  • Test with disposable@test.isbusinessemail.com and m365@test.isbusinessemail.com.

Official docs: FusionAuth documentation (see Webhooks and Events). See also: Response fields.