Wappler documentation
Security and login
Set up authentication, protect pages and server actions, and manage user sessions.
Use this hub when you are setting up identity and access. Start with the security provider, then move into login, page restriction, account flows, and protected server logic.
Start here
Setting up Site Security SettingsUnderstand Wappler Security Providers, provider types, and the shared settings that power login and access control across a project.Create a working login formThe complete connection between a Security Provider, a login action and the page’s success/error states.Security: Restricting Access to Your PageUse the App Root security properties to understand shared layout protection, page-specific access rules, and the inspector fields that control login and permission redirects.Applying Security to your NodeJS pagesYou can apply security to your pages and redirect users who are not logged in or have no permissions to view a specific page. Security Protection with NodeJS Security Provider setup with NodeJS is simSecurity Provider fundamentalsSee how Security Providers drive login sessions, action restrictions, and protected page flows across a Wappler project.
Complete account flows
Register a user and sign in after successA registration action with validation, password hashing, a fixed initial role and login after insertion.Logout - Create a Working User Logout ButtonWappler makes Logging out users a simple step by step process In order to log users out you need to create a server action and link it to a Log Out button, when your button is clicked it performs all Role-Based Redirects After LoginUse provider permissions and route decisions to send different Wappler users to the right post-login destination.Logged-In User ContextUse session-backed identity in Wappler pages and actions so the app can show the current user safely and consistently.Current User: Page Data BindingUse Demo Projects HQ to load /api/auth/current_user with a page-level dmx-serverconnect component and bind it safely in App Connect.Password reset request designThe decisions involved in validating a reset request and issuing a reset token.Password reset completion designThe decisions involved in validating a reset token, saving the new password and ending the reset flow.How Google OAuth login fits into your appThe relationship between Google identity, local accounts and a Wappler login session.
Server-side enforcement and context
Security - Secure your Server-Side dataWappler knows how important and sensitive server data can be and provides simple setup to ensure it can not be accessed by unauthorised users Using the security provider tools you can secure your servUsing Globals in Server ConnectUse Globals in Server Connect to manage shared project settings such as database connections, security providers, mailer settings, and other reusable server-side configuration.Server Connect Actions: Session & Cookie inputsUnderstand session vs cookie data, how they relate to login/auth, and how to use them as inputs in actions.Demo walkthrough: User update (routing + session + security)Use the real users/update.json action in Demo Projects HQ to connect route params, session context, permissions, and a secure database update.