User accounts and sign-in in your app
In shortEvery MonstarX app can have sign-up, sign-in and password reset built in — ask for them and they work. Everyone who signs up appears under Backend → Users, where you can ban or delete them. The Admin tab does more — roles, password resets and signing people out. After a build with sign-in, MonstarX makes a demo account so you can try it straight away.
Most apps need to know who is using them: a customer who wants to see their past orders, a member who books classes, a cook who posts recipes. That takes user accounts — sign-up, sign-in and sign-out. Every MonstarX app has them built in, stored in the app’s own database, with nothing to set up.
These are accounts for the people who use your app. They are separate from your own MonstarX account.
How do I add sign-up and sign-in to my app?
Section titled “How do I add sign-up and sign-in to my app?”Ask for it in your own words, in your first message or later:
People can sign up with their email and a password, and only signed-in members can book a class.
MonstarX builds the sign-up and sign-in pages, protects the pages that need an account, and keeps each person’s things (their bookings, their posts) linked to them.
How accounts work:
- People sign up with a name, an email address and a password of at least 8 characters.
- Once signed in, people stay signed in for 7 days on that browser.
- People do not have to confirm their email address before they can use the app.
- There is no “Sign in with Google” in the built-in accounts. If you need it, see Firebase, which brings your own Firebase sign-in.
- Your app’s accounts work on your free address and on any custom domain with no extra setup.
How do I try signing in myself?
Section titled “How do I try signing in myself?”After a build that adds email-and-password sign-in, MonstarX creates a demo account for you and posts it in the chat as Demo account ready, with the Username (email) and Password and a copy button for each. Use it to sign in to your app in the preview straight away. The demo user is called Demo User and appears in your app’s list of users.
You can also sign up in the preview like any visitor would. Accounts made in the preview are real accounts in your app’s database.
Where do I see who signed up?
Section titled “Where do I see who signed up?”Open BackendUsers. You see how many people have signed up, and for each one their Email, Name, Status and the day they Joined.
The Status says:
| Status | What it means |
|---|---|
| Active | The account works. |
| Active · verified | The account works and its email address is confirmed. |
| Banned | The person cannot sign in. If you gave a reason, it shows as Banned · reason. |
How do I block or remove someone?
Section titled “How do I block or remove someone?”- Ban stops a person signing in. MonstarX asks for a reason (optional) first. Click Unban to let them back in.
- The bin button deletes the person and signs them out everywhere. MonstarX asks you to confirm first. This cannot be undone.
For more control, click Manage users in Admin. The Admin tab’s Users page lets you search and filter people, see when they were last active and on how many devices they are signed in, ban someone for a day, a week, a month or for good, and delete a person together with what they own in your app. See Your app’s admin panel.
How do I make someone an admin of my app?
Section titled “How do I make someone an admin of my app?”Open the person in the Admin tab’s Users and click Make app admin. An app admin can open your app’s own admin pages, if it has any — a staff area or an orders board, for example. Being an app admin gives them nothing in MonstarX itself; they cannot see your project.
If your app has no admin pages yet, ask for them: “only app admins can open the orders board and mark orders ready”.
How do password resets work?
Section titled “How do password resets work?”Your app’s password reset sends an email with a link to choose a new password. The link works for one hour. The email comes from your app’s own address — see Email from your app.
- Forgot password in your app. If your app does not have a “Forgot password” link yet, ask: “add Forgot password to the sign-in page”. MonstarX adds the page where people enter their email and the page where they choose a new password.
- You send it. In the Admin tab, open the person and click Send password reset. It sends the same email your app’s “Forgot password” page sends. If the app has no page to choose a new password on yet, the Admin tab offers Ask MonstarX to add it.
What are the extra users I did not create?
Section titled “What are the extra users I did not create?”- Demo User — the demo account MonstarX made for you (see above).
- Test accounts from QA. When QA tests your app in a real browser, it signs up with test accounts of its own. MonstarX removes them, and what they made, once the QA run is over.
Frequently asked questions
Section titled “Frequently asked questions”Are my app's users the same as MonstarX users?
No. The people who sign up to your app have accounts in your app only. They never get a MonstarX account and cannot see your project.
Do people who signed up in the preview exist in the live app?
Yes. The preview and the published app share one database, so an account made in either works in both.
Can people sign in with Google or Apple?
Not with the built-in accounts, which use email and password. Connect your own Firebase project if you need other ways to sign in.
Can I see people's passwords?
No. Passwords are stored scrambled so nobody can read them, not even you. If someone forgets theirs, send a password reset.
Someone says sign-in does not work in the preview. What should I check?
Try the demo account first. If signing in works in a new tab but not inside the workspace, the browser may be blocking third-party cookies. Tell MonstarX in the chat what you see — see Troubleshooting.