Customer Approval

Customer account approval for Magento 2 (Luma and Hyvä) for B2B, wholesale and trade-only shops: new registrations wait for admin approval, with auto-approve rules, admin and customer emails, and REST/GraphQL login blocking.

  • Version 1.2.2
$89

One-off payment, with 12 months of updates.

What is included

  • 12 months of new versions and fixes; the versions released in that time stay yours
  • Install with Composer, or download a zip from your account
  • Licence for one production domain, staging and development copies included
  • 30-day money-back guarantee, refund policy

No subscription or automatic renewal. Keep using the versions included in your update period. Update and licence details

Key features

  • Approval for all new accounts or selected customer groups
  • Auto-approve customer groups and email domains
  • Sign-in blocked until approved, on every sign-in path
See all features

Composer package softaware/module-customer-approval

  • Trade and B2B shops

    Only the customers you approve can sign in, see their account and order. Everyone else gets a clear message.

  • No back doors

    Pending and rejected customers are refused on the sign-in page, at checkout, through REST and GraphQL tokens and through password-less sign-ins.

  • Less manual work

    Auto-approve your own groups and trusted email domains, and approve the rest from one queue or in bulk.

All features

What is included

Approval rules

  • All new accounts or selected customer groups
  • Auto-approve customer groups
  • Auto-approve email domains, with *.domain for sub-domains
  • Accounts created by an admin, admin API or CLI approved
  • Existing customers approved on installation

Storefront

  • Sign-in blocked on Luma and Hyvä and at checkout
  • REST and GraphQL customer tokens refused
  • Social login, confirmation links and Login as Customer refused
  • Approval message after registration, login page or CMS page
  • Optional notice on the registration form

Admin

  • Approval Queue with the pending count in the menu
  • Approval Status column, filter and mass actions in Customers
  • Approve and Reject buttons with an optional reason
  • Notice bar message while accounts are waiting
  • Separate ACL permissions for approving and for settings

Emails and integrations

  • Email to the shop team for each waiting account
  • Approved and not approved emails to the customer
  • Rejecting signs the customer out and revokes tokens
  • Admin REST API and CLI command
  • Event softaware_customer_approval_status_changed

Feature tour

Everything your shoppers and your team see

01 / 06

Tell shoppers before they register

An optional notice above the registration form explains that accounts are reviewed. After registering, the customer is not signed in and sees your approval message.

02 / 06

A clear message instead of an account

A pending or rejected customer who tries to sign in sees your message for that status. The texts can be changed per store view.

03 / 06

Native Hyvä template

The registration notice has its own Hyvä template, picked automatically. Sign-in messages appear in Hyvä's own message area.

04 / 06

Every waiting account in one grid

Pending and rejected accounts with keyword search, filters and status badges. Approve or reject in bulk; the menu shows how many are waiting.

05 / 06

Approve or Reject on the customer page

A notice shows the status, and the Reject button asks for an optional reason that can be included in the email to the customer.

06 / 06

Rules per website

Choose who needs approval, which groups and email domains are approved straight away, the storefront messages and the emails.

Live demo

Try it before you install it

A full Magento store with the module installed, on Luma and on Hyvä. The admin demo signs you in with one click.

Compatibility

Requirements and compatibility

Compatibility of Customer Approval
Latest version 1.2.2 · 9 Oct 2026
composer.json requires php ~8.2.0||~8.3.0||~8.4.0||~8.5.0 magento/framework ~103.0.7 softaware/module-core ^1.0 magento/module-authorization * magento/module-backend * magento/module-cms * magento/module-config * magento/module-customer * magento/module-eav * magento/module-email * magento/module-integration * magento/module-store * magento/module-ui *

Installation

Up and running in minutes

After you buy, create a Composer key in your account. Then, in the root of your Magento project:

  1. 01Add the repository and your key (once per project)

    composer config repositories.softaware composer https://repo.softawarecommerce.com
    composer config --auth http-basic.repo.softawarecommerce.com PUBLIC_KEY PRIVATE_KEY
  2. 02Install the module

    composer require softaware/module-customer-approval
  3. 03Enable it

    bin/magento setup:upgrade
    bin/magento setup:di:compile
    bin/magento setup:static-content:deploy
    bin/magento cache:flush

    The last three are only needed in production mode.

Prefer a zip? Every version you are entitled to can be downloaded from My modules. More about Composer access

User guide

How to set up and use Customer Approval

For version 1.2.2. The same guide comes with the module, in docs/user-guide.md.

New customer accounts wait for approval by your team before they can sign in. You decide which accounts need approval, approve or reject them in the admin, and the module emails your team and your customers. This guide covers installation, every setting and day-to-day use.

On the public demo storefront approval is switched off, so visitors can register and try the other modules. The admin demo shows the Approval Queue, the customer page buttons and the settings.

Sign-in refused for an account waiting for approval
Sign-in refused for an account waiting for approval

1. Requirements

MagentoMagento Open Source or Adobe Commerce 2.4.7 to 2.4.9
PHP8.2 to 8.5
ThemesLuma, Blank and themes based on them; Hyvä 1.3 or later
Othersoftaware/module-core (installed automatically)

2. Installation

Install with Composer from repo.softawarecommerce.com. Your access keys and the full set-up are described at https://softawarecommerce.com/shop/composer-access/.

composer config repositories.softaware composer https://repo.softawarecommerce.com
composer config --auth http-basic.repo.softawarecommerce.com PUBLIC_KEY PRIVATE_KEY
composer require softaware/module-customer-approval
bin/magento setup:upgrade
bin/magento setup:di:compile            # production mode only
bin/magento setup:static-content:deploy # production mode only
bin/magento indexer:reindex customer_grid
bin/magento cache:flush

The reindex adds the "Approval Status" column to the customer grid. All customers that exist at installation are marked as approved. On Hyvä, run your usual Tailwind build after installing so the registration notice is styled (the module registers itself for Hyvä's Tailwind source scanning).

To update later: composer update softaware/module-customer-approval, then the same bin/magento commands.

3. Quick start

  1. Go to Stores > Configuration > Softaware > Customer Approval (also under Softaware > Customer Approval > Settings) and choose the website in the scope switcher.
  2. Approval Rules > Enabled = Yes. By default every new account then needs approval.
  3. Enter your team's address under Email to Shop Team > Recipients, so someone hears about new accounts.
  4. Save. Register a test account on the storefront: you are not signed in and see the approval message.
  5. Open Softaware > Customer Approval > Approval Queue, approve the account, and sign in with it.

4. Settings

Approval rules and the shop team email are set per website; storefront messages and customer emails per store view. Every field shows its default in the comment and has "Use system value".

Customer Approval settings
Customer Approval settings

Approval Rules

SettingWhat it does
EnabledWhen No, new accounts are not held for approval and pending or rejected customers can sign in again. Default: No.
Require Approval ForAll new accounts or Selected customer groups. Accounts created by an admin, through the admin API or from the command line are always approved. Default: All new accounts.
Customer Groups That Need ApprovalWith "Selected customer groups": the groups whose new accounts need approval. This is the group the new account is assigned to (by default "Default Group" under Customers > Customer Configuration > Create New Account Options). If none is selected, no account needs approval.
Auto-approve These Customer GroupsWith "All new accounts": new accounts in these groups are approved straight away. Default: none.
Auto-approve Email DomainsOne domain per line or comma-separated, for example yourcompany.co.uk. Use *.example.com to include sub-domains. Default: empty.

Storefront Messages

SettingWhat it does
Show Notice on Registration FormShows the notice below above the "Create New Customer Account" form. Default: Yes.
Registration Form NoticeTells visitors before they register that accounts are reviewed.
Message After RegistrationShown instead of signing the customer in when the new account needs approval.
Sign-in Message: PendingShown on the login form and the checkout login when a pending customer tries to sign in.
Sign-in Message: RejectedShown on the login form when a rejected customer tries to sign in.
After Registration, Go ToThe login page, or a CMS page that explains your approval process. Default: Login page.

Email to Shop Team

SettingWhat it does
Email on New Account Waiting for ApprovalEmails the recipients when a new account is waiting for approval. Default: Yes.
RecipientsComma-separated email addresses, for example sales@example.com. No email is sent while this is empty.
Email TemplateThe template for this email.

Emails to Customers

SettingWhat it does
Email SenderThe store email identity used for all emails of the module, including the one to the shop team. Default: General Contact.
Send "Account Approved" EmailTells the customer they can now sign in. Default: Yes.
"Account Approved" TemplateThe template for this email.
Send "Account Not Approved" EmailTells the customer the account was not approved. Default: Yes.
"Account Not Approved" TemplateThe template for this email.
Include Rejection Reason in EmailAdds the reason entered when rejecting. Default: No.

To change the wording of an email, create a template from the module's template under Marketing > Communications > Email Templates and select it in the setting.

5. What your customers see

Before registering. With "Show Notice on Registration Form" on, a notice above the registration form explains that new accounts are reviewed. Luma and Hyvä each have their own template.

LumaHyvä
Registration notice on LumaRegistration notice on Hyvä

After registering. If the account needs approval, the customer is not signed in. "Thank you for registering" is replaced by your "Message After Registration", and the customer is sent to the login page or your CMS page. This also applies to accounts created at checkout or through a social login.

Signing in. A pending or rejected customer who tries to sign in sees the message for their status and stays signed out. The same customer is also refused on:

  • the checkout sign-in popup;
  • REST (POST /V1/integration/customer/token) and GraphQL (generateCustomerToken) customer tokens;
  • the RSS feed login;
  • password-less sign-ins: social login, the email confirmation link, the automatic sign-in after registration, Login as Customer on the storefront and through GraphQL (generateCustomerTokenAsAdmin), and store switching.

Through the REST and GraphQL token endpoints Magento replaces every sign-in error with its generic message.

Sign-in message on a phone (Hyvä)
Sign-in message on a phone (Hyvä)

After approval. The customer gets the "Account Approved" email and can sign in as usual. If you reject the account, the customer gets the "Account Not Approved" email, with the reason if you enabled that.

6. Approving and rejecting

Approval Queue

Softaware > Customer Approval > Approval Queue lists the pending and rejected accounts with ID, name, email, approval status (Pending, Rejected), rejection reason, group, company, country, website (under Columns) and registration date. Search by keyword (name, email address and the other indexed customer fields) or filter the columns. Rejected accounts stay listed, so you can still approve them later.

Approval Queue
Approval Queue
  • Mass actions: Approve and Reject.
  • Row actions: View Customer, Approve and Reject. To add a rejection reason, use the Reject button on the customer page.

The menu item shows the number of waiting accounts, for example "Approval Queue (2)", and a message in the admin notice bar says how many accounts are waiting.

Customer page

On Customers > All Customers > edit customer a notice shows the approval status, and the toolbar has Approve and Reject buttons. Reject asks for an optional reason, which is stored with the account and shown in the queue.

Customer page with Approve and Reject
Customer page with Approve and Reject

Customer grid

Customers > All Customers has an "Approval Status" column with a filter, and the mass actions Approve Account and Reject Account under Actions.

Rejecting or resetting a customer

Rejecting a customer, or setting them back to pending, signs them out of the storefront, ends "Remember Me" sessions and revokes their API tokens. Customers cannot change their own status: the approval attributes are not in any form, and a status sent with a customer save is ignored.

Permissions (ACL)

Under System > Permissions > User Roles > Role Resources > Softaware > Customer Approval:

ResourceAllows
Approve and Reject CustomersThe Approval Queue, the customer page buttons, the mass actions and the REST API
SettingsStores > Configuration > Softaware > Customer Approval

The customer grid mass actions are visible to every admin who can see the customer grid, but they only work with the "Approve and Reject Customers" permission.

7. Command line

bin/magento softaware:customer-approval:status                          # list pending accounts
bin/magento softaware:customer-approval:status --status=rejected        # list rejected (or approved) accounts
bin/magento softaware:customer-approval:status jane@example.com --set=approved [--no-email]
bin/magento softaware:customer-approval:status 42 --set=rejected --reason="Trade customers only"
bin/magento softaware:customer-approval:status 42 --set=pending

A customer is given by ID or email address; use --website=<id> when the same email exists on several websites. --no-email changes the status without emailing the customer.

8. REST API and events

With an admin token and the "Approve and Reject Customers" permission:

GET  /V1/softaware/customer-approval/:customerId            -> "pending" | "approved" | "rejected"
POST /V1/softaware/customer-approval/:customerId/approve     {"notify": true}
POST /V1/softaware/customer-approval/:customerId/reject      {"reason": "...", "notify": true}
POST /V1/softaware/customer-approval/:customerId/pending

The event softaware_customer_approval_status_changed (with customer, previous_status, status and reason) is dispatched on every change, for example to send the status to a CRM.

9. Troubleshooting

ProblemSolution
New accounts are not held for approvalCheck Enabled for the website (not only the default scope), the Require Approval For setting, the selected groups and the auto-approve groups and domains. Accounts created in the admin are always approved.
The customer grid has no "Approval Status" columnRun bin/magento indexer:reindex customer_grid.
The team gets no emailFill in Recipients; no email is sent while it is empty. Check that Magento can send email.
A customer cannot sign in after approvalCheck the status on the customer page. Through REST or GraphQL, refused attempts count towards Magento's account lockout; unlock the account under Account Lock if needed.
The link in the team email opens the dashboardThe link has no admin secret key. With "Add Secret Key to URLs" on, the admin opens the dashboard first.
The registration notice looks unstyled on HyväRebuild the Hyvä theme CSS after installing or updating.

10. Uninstall

bin/magento module:disable Softaware_CustomerApproval
composer remove softaware/module-customer-approval
bin/magento setup:upgrade

Once the module is removed, nobody is held for approval: pending and rejected customers can sign in again. The customer attributes softaware_approval_status and softaware_approval_reason stay in the database until you remove them.

Changelog

Release notes

1.2.2

Latest
  • Product listing, FAQ and user guide (docs/)

1.2.1

Fixed

  • README: the module requires softaware/module-core ^1.0 (the README said ^1.2; composer.json was right).

1.2.0

  • Approval queue: keyword search (name, email address and the other indexed customer fields).
  • Approval queue: approval status shown as Magento status badges (Pending, Approved, Rejected), a one-line introduction, and, when no account is waiting, a short explanation with an "Open Settings" button instead of an empty table. Long email addresses wrap instead of widening the grid; the Website column is hidden by default (available under Columns) so the grid fits at 1024 px.
  • Customer grid: the "Approval Status" column shows the same status badges; mass actions renamed to "Approve Account" / "Reject Account".
  • Confirmation dialogs titled "Approve Account" / "Reject Account"; the queue's row "Reject" confirmation explains how to add a reason. Row action "View Customer".
  • Notice bar and mass-action messages use proper singular/plural wording ("1 customer account is waiting for approval", "3 customer accounts approved") instead of "account(s)".
  • Settings: Approval Rules opens first, every field explains what it does and its default, "Recipients" is validated as a comma-separated list of email addresses, and every field can be reset to its default ("Use system value").
  • Approval queue: the status badges were not shown (raw status codes such as "pending" were displayed).

1.1.0

  • Requires softaware/module-core instead of softaware/module-base. The admin menu and ACL now sit under Softaware_Core::core ("Softaware"); roles that had access keep it (migrated by module-core). After updating all SoftAware modules, softaware/module-base can be removed.

1.0.1

  • Accounts created directly through the customer repository on the storefront (Softaware Social Login sign-ups, other modules) got no approval status, which counts as approved, so they skipped approval entirely. New customers saved through the repository now get their status from the approval rules too (a status sent with the customer is ignored), and the shop team is notified.
  • GraphQL generateCustomerTokenAsAdmin (Login as Customer for headless storefronts) issued tokens for pending and rejected customers. It is refused now, like the storefront "Login as Customer".
  • "Login as Customer" and other sign-ins by customer id ignored the approval switch when it was enabled on a website only (the default scope was read). The customer's own website is used now.
  • Rejecting or setting a customer back to pending now also ends their "Remember Me" (persistent cart) session.
  • Email confirmation link of an account that still needs approval: the customer saw "Thank you for registering" next to the approval message and was sent to an empty account page; now only the approval message is shown on the sign-in page.
  • Registrations outside the registration form (e.g. social sign-up) show the "needs approval" registration message instead of the "waiting for approval" error.
  • Approved email: no longer tells customers to use "the password you chose", which customers who signed up through a social login do not have.

1.0.0

  • Approval of new customer accounts per website: all accounts or selected customer groups, auto-approve groups and email domains; existing customers approved on install.
  • Sign-in blocked for pending/rejected customers on Luma and Hyvä forms, checkout login, REST and GraphQL tokens, and password-less sign-ins.
  • Registration flow message/redirect, registration form notice (Luma and Hyvä).
  • Admin: customer grid column, filter and mass actions; approve/reject buttons with reason; approval queue; pending count in menu and notice bar.
  • Emails to the shop team and to customers (approved/rejected); REST API; CLI.

FAQ

Questions, answered

Something else on your mind? The developers who wrote the module answer before and after you buy.

Ask a question →

Already installed it? Open a support ticket

Is approval switched on straight after installing?

No. The module is installed switched off, so it does not suddenly block registrations. Turn it on per website under Stores > Configuration > Softaware > Customer Approval > Approval Rules > Enabled. Customers that exist when the module is installed are approved.

Can only some customer groups need approval?

Yes. Set "Require Approval For" to selected customer groups and choose the groups. The group is the one the new account is assigned to, by default the "Default Group" under Customers > Customer Configuration > Create New Account Options. With "All new accounts" you can instead pick groups that are approved straight away.

Can I approve my own staff or known companies automatically?

Yes, with "Auto-approve Email Domains": enter domains such as yourcompany.co.uk, one per line or comma-separated. *.example.com includes sub-domains.

What does a pending customer see?

After registering, the customer is not signed in. The usual "Thank you for registering" message is replaced by your approval message, and the customer is sent to the login page or a CMS page of your choice. When they try to sign in, they see the message for their status (pending or rejected). All texts can be changed per store view.

Can a pending customer get in another way?

No. Besides the sign-in form, the module refuses the checkout sign-in popup, REST and GraphQL customer tokens, the RSS feed login and password-less sign-ins such as social login, email confirmation links, the automatic sign-in after registration, Login as Customer and store switching. New accounts get their status from the rules however they are created, including checkout, REST, GraphQL and social login.

Does it work with Hyvä?

Yes. The registration notice has a Hyvä template, and sign-in and registration use Magento's own controllers in both themes, so the messages appear as usual. Checkout on Hyvä uses the Luma checkout fallback.

Are accounts I create in the admin held for approval?

No. Accounts created by an admin, through the admin or integration API, or from the command line are approved straight away.

How do I approve or reject accounts?

In the Approval Queue (Softaware > Customer Approval > Approval Queue), with the Approve and Reject buttons on the customer page, with the "Approve Account" and "Reject Account" mass actions in Customers > All Customers, with the admin REST API or with the softaware:customer-approval:status command.

Can I tell the customer why the account was rejected?

Yes. The Reject button on the customer page asks for an optional reason. With "Include Rejection Reason in Email" on, the reason is included in the "Account Not Approved" email.

What happens when I reject an approved customer?

The customer is signed out of the storefront, "Remember Me" sessions are ended and their API tokens are revoked. The same happens when you set a customer back to pending.

Who gets told about new accounts?

The addresses under "Email to Shop Team > Recipients" get an email for each new account waiting for approval. No email is sent while the field is empty. Customers get an email when their account is approved or not approved; both can be switched off.

Can customers change their own status?

No. The approval attributes are not in any customer form, and a status sent with a customer save (for example through the REST API) is ignored.

Does it hide prices from visitors who are not signed in?

No, that is not part of this module.

Support

Help from the developers who wrote it

From the blog

Guides and articles

  • Approving new customer accounts on a trade-only Magento shop

    Magento Open Source lets anyone register and sign in straight away. Here is how to hold new accounts for review on a trade-only shop, and which core settings you still need to change.