Rule to force email verification only for some applications on the Auth0 dashboard
function (user, context, callback) {
// Bypass this rule for a particular app
if(context.clientName === 'NameOfTheAppToBypass'){
return callback(null, user, context);
// Access should only be granted to verified users otherwise.
if (! || !user.email_verified) {
return callback(new UnauthorizedError('Access denied.'));
callback(null, user, context);
