> For the complete documentation index, see [llms.txt](https://docs.rewst.help/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.rewst.help/rewst-documentation/documentation/apps/app-permissions-and-authentication.md).

# App permissions and authentication

Setting permissions ensures that only the right people have access to your apps and pages. It's as if you're putting up a virtual fence, allowing you to control who can view or edit your work. This document explains how permissions interact between organizations, apps, pages, and custom roles in Rewst.

## How permissions work for apps

{% hint style="info" %}
Permissions flow downward: Organization → App

* Higher-level permissions always apply to everything beneath them.
* Lower-level permissions cannot remove access granted at a higher level.
* There is no per-page access control.
  {% endhint %}

### Roles and organizations work together

Custom roles must be created in the **Settings** menu for an organization, typically the parent org where the app resides. A user may only have access an app or page if they have both a role and that role assigned within an authorized organization.

<figure><img src="https://3039672601-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2Fh0G0em3PH6aDfPoI5XpN%2Fuploads%2FR12ZZH8Yvt4ML7FgERvI%2FScreenshot%202026-09-09%20at%2010.19.52%E2%80%AFAM.png?alt=media&amp;token=87200282-0805-42b3-82c9-ba86cd2036fc" alt="" width="375"><figcaption><p>The role creation dialog in the Settings menu - note the <strong>App</strong> section</p></figcaption></figure>

&#x20;In .**.. >** **Access**, each organization grant has an **Include subtenants** option and an optional role filter. This is how child organizations get access.

<figure><img src="https://3039672601-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2Fh0G0em3PH6aDfPoI5XpN%2Fuploads%2FLcx1WiaBxsmS2dQ94vco%2FScreenshot%202026-09-21%20at%2012.04.19%E2%80%AFPM.png?alt=media&amp;token=b3e022f3-6ead-4f69-8428-d609f5e770bd" alt="" width="375"><figcaption></figcaption></figure>

## Why app authentication matters

*Authentication* is a crucial aspect of securing your app and ensuring that only authorized users can access its content. When users attempt to view live pages within your app, whether they are a Rewst user or an outside individual, authentication is required. Rewst offers two app authentication options.&#x20;

{% hint style="info" %}
Ensure that your app's authentication system aligns with your users' expectations and complies with any relevant privacy and security standards. Regularly update and review your authentication processes to stay ahead of potential security challenges.
{% endhint %}

## How authentication works

Rewst offers three access modes. To use them, navigate to  .**.. › Access.**

1. **Restricted** - Only chosen people and organizations
2. **Generated link** - Anyone with the generated link
3. **Public** - Anyone with the public app URL

### Restricted access

An app viewer can either **Sign in with Rewst** or use **Email verification**

#### Option 1: Rewst login

This option requires all who access the app to be users of Rewst.

1. When a user tries to access live pages within your app, they will be redirected to the login page with fields to enter their Rewst login credentials.
2. Once authenticated, the system performs an authorization check to ensure the user has the necessary permissions to view the requested content.
3. If the authentication and authorization checks pass, the user is granted access to the live pages.

#### Option 2: Email verification

This option allows people to access the app if they are not users of Rewst.

1. Navigate to **Apps** to view your total app list in Rewst.
2. Click **... > Access**.
3. Set the login for your app to **Restricted**.
4. Add the desired individual's email address to the access list. Add multiple email addresses if desired.
5. Click **Save**.
6. The individuals will be sent an email inviting them to look at your app with a link to access it. Note that the invite is sent only to addresses newly added from the most recent save— resaving does not resend to prior recipients who were already sent the invite.
7. When the individual clicks the link, they see an email verification screen. They enter their email address into the field, are sent a login code, then enter the code into the login screen.&#x20;
8. If the authentication and authorization checks pass, the user is granted access to the live pages.

{% columns %}
{% column %}

<figure><img src="https://3039672601-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2Fh0G0em3PH6aDfPoI5XpN%2Fuploads%2FKNPIDYQQqSEDisa0WGXX%2FScreenshot%202026-09-08%20at%203.53.18%E2%80%AFPM.png?alt=media&amp;token=b8901977-7f1b-4f7f-a6fd-ccf5b43f5294" alt=""><figcaption></figcaption></figure>

{% endcolumn %}

{% column %}

<figure><img src="https://3039672601-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2Fh0G0em3PH6aDfPoI5XpN%2Fuploads%2FnfoZqMiCejSAhLTI9hVC%2FScreenshot%202026-09-08%20at%203.16.26%E2%80%AFPM.png?alt=media&amp;token=36b83a8f-859a-4118-a318-eaa7fc427782" alt=""><figcaption></figcaption></figure>
{% endcolumn %}
{% endcolumns %}

### Generated link

1. Navigate to **Apps** to view your total app list in Rewst.
2. Click **... > Access**.
3. Set the login for your app to **Generated link**.
4. Click **Save**.

<figure><img src="https://3039672601-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2Fh0G0em3PH6aDfPoI5XpN%2Fuploads%2FjTwIgzvlAeIK4Z2lVAHH%2FScreenshot%202026-09-21%20at%201.04.32%E2%80%AFPM.png?alt=media&amp;token=9966177d-dfd2-468c-a449-c985780a4d59" alt=""><figcaption></figcaption></figure>

### Public

1. Navigate to **Apps** to view your total app list in Rewst.
2. Click **... > Access**.
3. Set the login for your app to **Public**.
4. Click **Save**.

<figure><img src="https://3039672601-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2Fh0G0em3PH6aDfPoI5XpN%2Fuploads%2FsZw0zCMah28ox5VGzizF%2FScreenshot%202026-09-21%20at%201.04.48%E2%80%AFPM.png?alt=media&amp;token=e669eb6c-f85f-4375-abcb-4cb6019384b6" alt=""><figcaption></figcaption></figure>


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://docs.rewst.help/rewst-documentation/documentation/apps/app-permissions-and-authentication.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
