# Use an invite code to bypass new user approval?

**URL:** https://meta.discourse.org/t/use-an-invite-code-to-bypass-new-user-approval/101923
**Category:** Feature
**Created:** [13.Ноябрь.2018 09:42:33 UTC](https://meta.discourse.org/t/use-an-invite-code-to-bypass-new-user-approval/101923 "2018-11-13T09:42:33Z")
**Posts on this page:** 20
**Page:** 1

<div class="post-metadata">

### Author: ![Pad\_Pors](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/pad_pors/32/52016_2.png) [@Pad\_Pors](https://meta.discourse.org/u/Pad_Pors)
#### Post date: [13.Ноябрь.2018 09:42:33 UTC](https://meta.discourse.org/t/use-an-invite-code-to-bypass-new-user-approval/101923/1 "2018-11-13T09:42:33Z")

</div>

currently users can invite others by adding their email directly in the invitation box.

it would be great and much simpler if one can use a simple invitation-name (e.g. the username of invitee) to join the forum. since this way people can even use the invitation credit out of the web (in real events e.g.).

imagine I’ve attended a workshop where I find lot’s of people related to our discussion forum, and I’d like to invite them. I need to get lot’s of emails and after the workshop I need to invite them one by one.

but this way I can easily give them my username and ask them to join the forum adding this name in the invitee field, so that they can start from a higher level.

what’s your idea?

---

<div class="post-metadata">

### Author: ![Stephen](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/stephen/32/95011_2.png) [@Stephen](https://meta.discourse.org/u/Stephen)
#### Post date: [13.Ноябрь.2018 14:40:28 UTC](https://meta.discourse.org/t/use-an-invite-code-to-bypass-new-user-approval/101923/2 "2018-11-13T14:40:28Z")

</div>

You can also invite users by sharing the link in this dialog, have you tried that?

 ![32%20AM](https://global.discourse-cdn.com/meta/original/3X/d/7/d73acb3da0a50026b0e6e74a0f1a450dd519e474.png)

---

<div class="post-metadata">

### Author: ![Pad\_Pors](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/pad_pors/32/52016_2.png) [@Pad\_Pors](https://meta.discourse.org/u/Pad_Pors)
#### Post date: [13.Ноябрь.2018 16:07:32 UTC](https://meta.discourse.org/t/use-an-invite-code-to-bypass-new-user-approval/101923/3 "2018-11-13T16:07:32Z")

</div>

how will you do that if you don’t have my email?

steps are:

1. you ask for my email,
2. I pass it to you,
3. you start the app,
4. invite me using one of the invite buttons,
5. I proceed with the sign up process.

while there can be less steps:

1. you give me a name (Stephan),
2. I start the app,
3. I go to the signup panel and add your name there,

of course the second process is what happens most of the time, and only the link between people and the credit is missed.

---

<div class="post-metadata">

### Author: ![Stephen](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/stephen/32/95011_2.png) [@Stephen](https://meta.discourse.org/u/Stephen)
#### Post date: [13.Ноябрь.2018 16:21:42 UTC](https://meta.discourse.org/t/use-an-invite-code-to-bypass-new-user-approval/101923/4 "2018-11-13T16:21:42Z")

</div>

So what’s the benefit of adding a username at signup? If the user is able to find the community and register, what do they gain by populating that extra field? Are you just looking to collect a list of people you’ve referred in? What’s the benefit to **them**?

Invites typically serve the following purposes:

1. Bring a person to your community and direct them to a specific topic - just entering your username wouldn’t achieve that
2. Bring a person to your private community and grant them access - this would defeat the security of private communities
3. Bring a person to your public community and automatically add them to a group to see other things - see (2)

In those cases they receive an email that once they click the link gives them a frictionless sign-in, the email address is **already verified** so they either use the suggested username, or pick their own, then move on.

You significantly oversimplified what will be required of users in your example, they’re going to need to remember lots of additional information and complete several additional steps:

- **Where** to browse
- **What** to look for when they get there
- **Who** referred them

Then they’ll need to manually register and validate their email address. If there are any groups or privacy involved there’s also additional administration steps on top.

They don’t just “start the app” - there is no app which magically routes users to particular discourse instances based on referrer username, usernames aren’t unique between instances. Adding an app at this stage just complicates matters - if it’s a site-specific app they’ll need to also know what it’s called and install it, if it isn’t and you’re just referring to the Discourse Hub they will still need to install that and provide a URL.

That doesn’t sound _particularly_ user-friendly.

With the invite link you avoid a couple of those pain-points, the **where** , **what** and **who** is contained. If you don’t like the length and complexity of that URL and plan to re-use a single invite there are a ton of URL shortening options out there. I’ve done this a number of times myself, putting links in presentation decks, on hand-outs and other materials.

The above suggests you’ve not thought this through at all. Consider the benefits to the other party and how realistic it really is.

---

<div class="post-metadata">

### Author: ![Pad\_Pors](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/pad_pors/32/52016_2.png) [@Pad\_Pors](https://meta.discourse.org/u/Pad_Pors)
#### Post date: [13.Ноябрь.2018 16:40:45 UTC](https://meta.discourse.org/t/use-an-invite-code-to-bypass-new-user-approval/101923/5 "2018-11-13T16:40:45Z")

</div>

> [@Stephen](#):
>
> What’s the benefit to **them**?

the benefit would be for them as well as invitee: **some credit** which results in their trust level (i.e. gamification).

this can only be meaningful if one can use his trust level somehow (to have extra access in the forum).

> [@Stephen](#):
>
> In those cases they receive an email that once they click the link gives them a frictionless sign-in, the email address is **already verified** so they either use the suggested username, or pick their own, then move on.

👍 this is great, and can happen in the new scenario as well: once you give your invitation-name to me, if I use it in the sign up box, then **I can skip the email verification step; because of your credit.**

---

<div class="post-metadata">

### Author: ![Stephen](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/stephen/32/95011_2.png) [@Stephen](https://meta.discourse.org/u/Stephen)
#### Post date: [13.Ноябрь.2018 16:43:01 UTC](https://meta.discourse.org/t/use-an-invite-code-to-bypass-new-user-approval/101923/6 "2018-11-13T16:43:01Z")

</div>

But that’s not verification, forum usernames are **public**. It will take seconds for spambots to realise that they can bypass the email verification field were that ever implemented.

Do you understand why email addresses need to be verified? If mail carriers such as Mailgun see many email bounces or receive spam reports for messages they will terminate the mail accounts of communities, cutting off email entirely. All because you don’t want to send or share an invite URL.

---

<div class="post-metadata">

### Author: ![Pad\_Pors](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/pad_pors/32/52016_2.png) [@Pad\_Pors](https://meta.discourse.org/u/Pad_Pors)
#### Post date: [13.Ноябрь.2018 16:57:49 UTC](https://meta.discourse.org/t/use-an-invite-code-to-bypass-new-user-approval/101923/7 "2018-11-13T16:57:49Z")

</div>

> [@Stephen](#):
>
> forum usernames are **public**

the invitation-key doesn’t need to be the username, it was just an example!

it can be a simple name which is unique per user.

> [@Stephen](#):
>
> All because you don’t want to send or share an invite URL.

you may have internet access all the time and you may know the email for all of your real world friends/colleague, not applicable to everywhere in the world.

---

<div class="post-metadata">

### Author: ![Stephen](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/stephen/32/95011_2.png) [@Stephen](https://meta.discourse.org/u/Stephen)
#### Post date: [13.Ноябрь.2018 17:00:22 UTC](https://meta.discourse.org/t/use-an-invite-code-to-bypass-new-user-approval/101923/8 "2018-11-13T17:00:22Z")

</div>

> [@Pad\_Pors](#):
>
> the invitation-key doesn’t need to be the username, it was just an example!

So now it’s a fourth thing they need to remember?

You’re making remembering invite URLs sound easy in comparison 😁

---

<div class="post-metadata">

### Author: ![Pad\_Pors](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/pad_pors/32/52016_2.png) [@Pad\_Pors](https://meta.discourse.org/u/Pad_Pors)
#### Post date: [13.Ноябрь.2018 17:03:36 UTC](https://meta.discourse.org/t/use-an-invite-code-to-bypass-new-user-approval/101923/9 "2018-11-13T17:03:36Z")

</div>

you can think of some variation of the invitee email which would be hard for spam-bots to guess. e.g. if your email is [stephan.tester@gmail.com](mailto:stephan.tester@gmail.com), then the invite code can be simply stephan.tester123!

everyone know their own email. don’t they?

---

<div class="post-metadata">

### Author: ![Stephen](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/stephen/32/95011_2.png) [@Stephen](https://meta.discourse.org/u/Stephen)
#### Post date: [13.Ноябрь.2018 17:06:19 UTC](https://meta.discourse.org/t/use-an-invite-code-to-bypass-new-user-approval/101923/10 "2018-11-13T17:06:19Z")

</div>

Creating unique codes per-invite would require you to have internet access, no? If not then it’s something you can brute force.

It wouldn’t bypass the need to verify email, there is no substitute to sending an email to a mailbox and having the recipient follow a link or enter a received code, that’s why it’s still done everywhere.

---

<div class="post-metadata">

### Author: ![Pad\_Pors](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/pad_pors/32/52016_2.png) [@Pad\_Pors](https://meta.discourse.org/u/Pad_Pors)
#### Post date: [13.Ноябрь.2018 17:08:46 UTC](https://meta.discourse.org/t/use-an-invite-code-to-bypass-new-user-approval/101923/11 "2018-11-13T17:08:46Z")

</div>

a unique code per user name is enough, not per invite.

yes, I can see the problem with the verification email. the main idea was about being able to gamify the invites and use the credit, bypassing the email was just a suggestion coming up from the fruitful discussion, which is really not applicable.

---

<div class="post-metadata">

### Author: ![Mittineague](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/mittineague/32/114259_2.png) [@Mittineague](https://meta.discourse.org/u/Mittineague)
#### Post date: [13.Ноябрь.2018 22:52:54 UTC](https://meta.discourse.org/t/use-an-invite-code-to-bypass-new-user-approval/101923/12 "2018-11-13T22:52:54Z")

</div>

I think what is misleading is the term “invite”.

All accounts need a username and a valid email address. Typically a member supplies these when they register.

It sounds like what you have in mind is more like a “pre-registration” where you supply the username and email address and they follow a link to activate the account.

I guess this could be done but I don’t know how things could be worked out to give you “invite” credit.

---

<div class="post-metadata">

### Author: ![codinghorror](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/codinghorror/32/110067_2.png) [@codinghorror](https://meta.discourse.org/u/codinghorror)
#### Post date: [13.Ноябрь.2018 23:11:31 UTC](https://meta.discourse.org/t/use-an-invite-code-to-bypass-new-user-approval/101923/13 "2018-11-13T23:11:31Z")

</div>

> [@Mittineague](#):
>
> It sounds like what you have in mind is more like a “pre-registration” where you supply the username and email address and they follow a link to activate the account.

Isn’t this possible with bulk invites plugin @techAPJ?

---

<div class="post-metadata">

### Author: ![techAPJ](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/techapj/32/342990_2.png) [@techAPJ](https://meta.discourse.org/u/techAPJ)
#### Post date: [14.Ноябрь.2018 01:58:06 UTC](https://meta.discourse.org/t/use-an-invite-code-to-bypass-new-user-approval/101923/14 "2018-11-14T01:58:06Z")

</div>

> [@codinghorror](#):
>
> Isn’t this possible with bulk invites plugin

Yes, that is correct.

@Pad_Pors I think this is closest to what you are looking for?

> [@Generating lots of Invite Tokens](https://meta.discourse.org/t/generating-lots-of-invite-tokens/17563):
>
> warning This plugin is deprecated in favour of our core invite system. Summary: Generate multiple invite tokens link GitHub: [https://github.com/discourse/discourse-invite-tokens](https://github.com/discourse/discourse-invite-tokens)arrow_right Install: Follow the [plugin installation guide](https://meta.discourse.org/t/install-a-plugin/19157). Configuration Enable plugin After installing plugin enable site setting invite tokens enabled. Clone Discourse API Gem If you already have Git and Ruby installed on your system, you can install Discourse API by running following command from consol…

> [@Pad\_Pors](#):
>
> imagine I’ve attended a workshop where I find lot’s of people related to our discussion forum, and I’d like to invite them. I need to get lot’s of emails and after the workshop I need to invite them one by one.

Using the above plugin you can simple hand out invite tokens to the people without needing to invite them manually.

---

<div class="post-metadata">

### Author: ![Pad\_Pors](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/pad_pors/32/52016_2.png) [@Pad\_Pors](https://meta.discourse.org/u/Pad_Pors)
#### Post date: [14.Ноябрь.2018 10:02:13 UTC](https://meta.discourse.org/t/use-an-invite-code-to-bypass-new-user-approval/101923/15 "2018-11-14T10:02:13Z")

</div>

cool thanks 👍 , just to understand it clearly: using the plugin:

- admins can create several invitation-keys for users.
- each key works for a particular email.

is it working like that?

though not necessary, I think one can think on a simpler routine where trusted-users can invite others and **get the credit**.

I agree with @Stephen that the invitation buttons are great, but at least in our community (which is still young) people prefer to use word of mouth rather than a button!

> hey! there is a community here you will enjoy being part of!

now imagine this dialogue:

> hey! there is a community here you will enjoy being part of. if you come, tell Samuel has introduced me! this way you’ll be trusted simpler from the beginning.

---

<div class="post-metadata">

### Author: ![techAPJ](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/techapj/32/342990_2.png) [@techAPJ](https://meta.discourse.org/u/techAPJ)
#### Post date: [14.Ноябрь.2018 10:28:53 UTC](https://meta.discourse.org/t/use-an-invite-code-to-bypass-new-user-approval/101923/16 "2018-11-14T10:28:53Z")

</div>

> [@Pad\_Pors](#):
>
> admins can create several invitation-keys for users.

Yes, admin can create (generate) several invitation-keys (invite tokens).

> [@Pad\_Pors](#):
>
> each key works for a particular email.

No invite tokens are not linked/restricted to an email. While redeeming/accepting the invitation user has ability to provide email and choose username.

---

<div class="post-metadata">

### Author: ![Pad\_Pors](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/pad_pors/32/52016_2.png) [@Pad\_Pors](https://meta.discourse.org/u/Pad_Pors)
#### Post date: [15.Ноябрь.2018 12:13:19 UTC](https://meta.discourse.org/t/use-an-invite-code-to-bypass-new-user-approval/101923/17 "2018-11-15T12:13:19Z")

</div>

I followed the plugin discussion, and seems to me the plugin is not doing much in the favor of a simpler invitation process to be used in conference cases:

> [@Generating lots of Invite Tokens](https://meta.discourse.org/t/generating-lots-of-invite-tokens/17563/14):
>
> I realize that they are somewhat long and complicated for distributing them on paper (e.g. `0fcf1e297a34b45768efe6ca594ce93c` ). I don’t want anyone to have to type this, especially since people are bound to get certain letters wrong or mistake a 0 for an O or whatever. So I wonder if there would be any way of creating either pronounceable tokens or (probably easier), much shorter ones, perhaps 8 or 12 characters divided into three blocks of 4, separated by a dash: `0FCF-1E29-7A34` ?

> [@Generating lots of Invite Tokens](https://meta.discourse.org/t/generating-lots-of-invite-tokens/17563/16):
>
> but the problem is: since I don’t have the email-address, it doesn’t help much to create a QR code because people still need to manually add their email.

---

<div class="post-metadata">

### Author: ![pfaffman](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/pfaffman/32/120154_2.png) [@pfaffman](https://meta.discourse.org/u/pfaffman)
#### Post date: [15.Ноябрь.2018 13:36:49 UTC](https://meta.discourse.org/t/use-an-invite-code-to-bypass-new-user-approval/101923/18 "2018-11-15T13:36:49Z")

</div>

What this particular use case is reusable invites perhaps with a limited time frame. Then you could flash your url on a slide and people could copy it and do what you want.

The other solution is to allow users to request accounts, but that won’t give users credit for the invites.

---

<div class="post-metadata">

### Author: ![sam](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/sam/32/102149_2.png) [@sam](https://meta.discourse.org/u/sam)
#### Post date: [15.Март.2020 02:38:30 UTC](https://meta.discourse.org/t/use-an-invite-code-to-bypass-new-user-approval/101923/20 "2020-03-15T02:38:30Z")

</div>

О боже, @codinghorror, мне это сегодня так нужно.

Мне нужно пригласить 50 человек на форум, **у меня нет их адресов электронной почты** , я просто хочу поделиться кодом в группе WhatsApp, чтобы все присоединились.

На данный момент абсолютно нет чистого способа сделать это. Поскольку для меня это довольно срочно, сегодня я напишу какое-то примитивное решение.

Я думаю о следующем:

`requires_approval`: true  
`auto_approve_code`: по умолчанию пусто; если при регистрации введён какой-либо код, пользователю предлагается ввести код одобрения; если он совпадает, пользователь автоматически одобряется.

Это значит, что я могу сообщить в своей группе WhatsApp, что код одобрения для форума — `12345abc`, и люди смогут передавать его внутри круга. Как только форум будет заполнен достаточным количеством пользователей, можно будет перейти к более безопасному и контролируемому режиму.

Для меня дело не в заслугах, а скорее в возможности быстро и с определённой степенью безопасности заселить форум большим количеством пользователей из другого источника.

---

<div class="post-metadata">

### Author: ![codinghorror](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/codinghorror/32/110067_2.png) [@codinghorror](https://meta.discourse.org/u/codinghorror)
#### Post date: [15.Март.2020 06:03:40 UTC](https://meta.discourse.org/t/use-an-invite-code-to-bypass-new-user-approval/101923/21 "2020-03-15T06:03:40Z")

</div>

Итак, речь идет о сайтах только по приглашению / **все пользователи должны быть одобрены сотрудниками**? Если так, то заголовок этой темы составлен очень плохо, позвольте мне исправить это прямо сейчас.

У меня нет возражений против этого в плане обхода приглашений/одобрений.

[Следующая страница](https://meta.discourse.org/t/use-an-invite-code-to-bypass-new-user-approval/101923.md?page=2)
