Skip to content

Document the Block disposable email addresses sign-up policy - #824

Open
DanielRivers wants to merge 1 commit into
mainfrom
feat/block-disposable-emails
Open

DanielRivers wants to merge 1 commit into
mainfrom
feat/block-disposable-emails

Conversation

@DanielRivers

Copy link
Copy Markdown
Member

Summary

Documents the new Block disposable email addresses environment policy (Plus, Scale and Enterprise plans), which rejects sign-ups whose email domain is on a Kinde-maintained list of disposable providers.

Changes

  • New page: authenticate/custom-configurations/block-disposable-emails — overview, plan availability, how to turn it on, suffix-based matching, a coverage table of which registration paths are blocked and which are exempt (invitations, admin-created users, Management API, bulk import, SCIM, access request / subscriber conversion, existing users, phone-only and username-only sign-ups), the error message and error code 9697 a blocked person sees, and alternatives via Allowed domains or a pre-user registration workflow. The sidebar is autogenerated from the directory, so no nav config change was needed.
  • Configure attack protection: new section after Credential enumeration protection pointing to the new page. The opening sentence now scopes "always on" to brute force and enumeration protection, since disposable blocking is opt-in and plan-gated.
  • Workflow examples: the Block disposable emails entry now mentions the built-in policy and says when to use the policy (maintained list, no code) versus the workflow (own list, custom logic, or Free/Pro plan).
  • TrustPath integration: one see-also sentence after the step that enables the "Email addresses are disposable" rule.

Verification

  • astro build completes with no errors (471 pages).
  • scripts/validate-links.js reports all internal links valid, including anchor links into the access policies page.
  • No duplicate page_ids.

For reviewers

  • Screenshot needed. The new page has an MDX comment placeholder for a screenshot of the Policies page, Sign up section, showing the switch below Allowed domains. It does not render on the page but is visible via "Copy as markdown" until replaced.
  • Ungated period. The Availability section notes that the switch was briefly available on all plans, and that Free/Pro environments which turned it on will see it on but blocking does not engage until they upgrade. Please confirm this should be public-facing rather than support-only; it is a single paragraph to remove if not.
  • Refresh cadence. Deliberately not stated. The copy says "Kinde maintains the list".
  • Pricing page. The kinde.com Plus and Scale feature lists may need this added; that is outside this repo.

🤖 Generated with Claude Code

Add a new page under Auth and access > Custom configurations covering the
Block disposable email addresses environment policy: plan availability,
how to turn it on, suffix-based matching, which registration paths are
blocked and which are exempt (invitations, admin-created users, API,
import, SCIM, existing users), the error message and code 9697 a blocked
person sees, and alternatives via Allowed domains or a workflow.

Also:
- Add a short section to Configure attack protection pointing to the new
  page, and scope its opening "always on" sentence to brute force and
  enumeration protection, since disposable blocking is opt-in and plan-gated.
- Note the built-in policy on the Block disposable emails workflow example
  and say when to use the policy versus the workflow.
- Add a see-also link from the TrustPath integration guide.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
@DanielRivers
DanielRivers requested a review from a team as a code owner October 7, 2026 17:57
@coderabbitai

coderabbitai Bot commented Oct 7, 2026

Copy link
Copy Markdown
Contributor

Warning

Review limit reached

You've used all free OSS reviews for now. Wait for the free limit to reset to keep reviewing this public repository.

Next included review available in 40 minutes.

Check out review usage here.

View limit details

Limit details: You’ve used the included review currently available.

Learn how review limits work.

Review configuration:

⚙️ Run configuration
  • Configuration used: Repository UI
  • Review profile: CHILL
  • Plan: Advanced
  • Run ID: 8080c6d9-d963-411b-b635-3a400029d89c
📥 Commits

Reviewing files that changed from the base of the PR and between fa35fd0 and cc737cd.

📒 Files selected for processing (4)
  • src/content/docs/authenticate/custom-configurations/block-disposable-emails.mdx
  • src/content/docs/build/set-up-options/attack-protection.mdx
  • src/content/docs/integrate/third-party-tools/trustpath-fraud-protection.mdx
  • src/content/docs/workflows/getting-started/workflow-examples.mdx
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@cloudflare-workers-and-pages

Copy link
Copy Markdown

Deploying kinde-docs-preview with  Cloudflare Pages  Cloudflare Pages

Latest commit: cc737cd
Status: ✅  Deploy successful!
Preview URL: https://841f4b2b.kinde-docs-preview.pages.dev
Branch Preview URL: https://feat-block-disposable-emails.kinde-docs-preview.pages.dev

View logs

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants