Loading

E-mail Address as Username

Use E-mail Address as Username ships on. With it off, users can have a username separate from their e-mail address.

Where to find it

Architect Panel → Configuration:

  • Site Settings — Use E-mail Address as Username, and Login Page Mode

Why the default is on

  • Nothing extra to remember. People know their e-mail address; they forget usernames.
  • Uniqueness for free. No two people share an address, so there is nothing to arbitrate.
  • One identifier for sign-in, recovery and contact.

For most applications this is straightforwardly right.

When a separate username helps

  • Shared or role addresses. Several people using one mailbox cannot each have an account keyed on it.
  • Users without an address, or without one you should hold.
  • An existing convention — a staff number, a member number — that people already use and expect.
  • Public display. If the identifier is ever shown to other users, a username avoids publishing e-mail addresses.

What you take on by separating them

A second identifier to manage. Usernames must be allocated, cannot be changed casually once referenced, and get forgotten — which turns "I cannot sign in" into two possible problems rather than one.

You also need to decide what happens when somebody's e-mail changes, and whether the username follows.

Recovery still runs on the e-mail address

Whatever you choose for sign-in, password reset needs an address to send to. So the address is required regardless — a separate username does not remove the need for one, it adds an identifier alongside it.

It interacts with the login page mode

E-mail check mode asks for an address first and adapts. That fits naturally when the address is the username, and less naturally when it is not — the page is asking for one thing to decide about another.

Consider the two settings together rather than separately.

Changing your mind is awkward

Turning this off after accounts exist means every user needs a username. Turning it on means resolving anybody whose address is missing, shared or duplicated. Neither is impossible and both are work — decide early.

Duplicate addresses

With the setting on, an address can belong to one account. That prevents duplicates, and it also means somebody who legitimately needs two accounts — a staff member who is also a customer — needs two addresses or a different arrangement. Worth thinking about if your populations overlap.

Worked example

A customer portal keeps the default, so customers sign in with their e-mail address and nothing else to remember. A separate internal system uses staff numbers, because those are already on everybody's badge and several field staff share a depot mailbox — with a personal address held for password reset.

Recommendations

  • Keep the default unless you have a specific reason.
  • Hold an e-mail address regardless — recovery needs one.
  • Decide alongside the login page mode.
  • Settle it early — changing later is real work.