// answer

Did Apple change App Review rules around sign-in and account access?

Short answer

Yes. Apple tightened and clarified the App Review rules, especially around login gates, Sign in with Apple, and demo access for review. Apps without significant account features should let people in without login.

If you want to ask a follow-up rather than read one: Join a community

Did Apple change App Review rules around sign-in and account access

Yes. Apple has updated and clarified the rules, and the current review language is stricter in the places developers usually get rejected: login gates, third-party sign-in, demo access for review, and account deletion. The core idea is simple, users should not need an account unless the app’s core function truly requires one.

Apple’s current App Store Review Guidelines say that if an app does not include significant account-based features, people must be able to use it without a login. If the app supports account creation, it must also offer account deletion inside the app. If the app uses a third-party or social login service to set up or authenticate the primary account, Apple requires an equivalent login option that meets Apple’s privacy conditions.

The part people get wrong is thinking that any feature tied to identity justifies a mandatory sign-in wall. Apple draws a line between true account-based functionality and basic app use. Social sharing, inviting friends, or pulling a profile image are not treated as core app functionality. If the app’s main job still works without login, Apple expects a guest path or another access method.

Apple also tells reviewers how to evaluate apps that need access during review. The submission must include demo account information when the app includes a login, and if a demo account is impossible because of legal or security limits, Apple allows a built-in demo mode with prior approval. That is important because many rejections are not about the product idea, they are about App Review not being able to reach the real feature set.

The inconvenient part is that Apple can accept an app with required sign-in only when the requirement is directly relevant to the core functionality or required by law. In practice, that means a banking app, a regulated service, or a private enterprise app may require sign-in. A utility, content browser, or casual consumer app usually cannot hide its basic experience behind registration.

Apple’s Sign in with Apple policy is still part of this picture. If an app uses a third-party or social login service like Google Sign-In, Facebook Login, or similar to create or authenticate the primary account, Apple requires an equivalent option that limits data collection and supports private email. That requirement has been in place for years, and Apple’s current guidelines still enforce it.

Apple’s wording around account access is also more explicit than many older summaries people repeat online. The guidelines now say apps may not require users to enter personal information to function unless it is directly relevant to the core functionality of the app or required by law. That means a login screen at launch is not automatically disallowed, but it is only defensible when the app truly cannot work otherwise.

A concrete example helps. If you publish a photo-editing app, Apple is likely to expect editing features before login. If you publish a private team dashboard, Apple can expect sign-in first because the content is the product. If you publish a game with local tutorial content, Apple may reject a forced account wall if the first usable screen is nothing but a sign-up form. Those are the cases where review outcomes usually turn.

Another place people trip up is review prep. Apple says to include accurate app review information, and if the app includes login, to provide demo account credentials or a demo mode. A working login flow that is obvious to users is not enough if Review cannot get through it quickly. The review team is checking the app’s behavior, not reconstructing your onboarding from guesses.

So, did Apple change the rules Yes, in the sense that the current guidelines now spell out the login and account-access expectations more clearly, and reviewers use those expectations to reject apps that gate non-account features behind registration. The practical rule is unchanged in spirit but tighter in execution: no unnecessary login wall, no missing review access, and no skipped account-deletion path.

If you are preparing a submission, start with one question: what does the user lose if they never create an account If the answer is almost nothing, let them in first. If the answer is the whole product, document that clearly in App Review Information and give Review a working account or demo mode. That is the difference between a fast approval and a rejection loop.

For teams building around testing and review access, it helps to keep the app’s review path separate from the production path, and to document it clearly. If you are organizing testers for App Store work or another mobile release workflow, DevConnect is built for that kind of exchange.

FAQ

Does Apple require Sign in with Apple for every app with login? No. Apple requires an equivalent Sign in with Apple option when you use a third-party or social login service for the app’s primary account. If you only use your own account system, that specific requirement does not apply.

Can an app require login if it has subscriptions or saved data? Yes, when the account is tied to the app’s core service, stored data, or a regulated workflow. Apple’s rule is about whether login is directly relevant to core functionality, not whether login is convenient for the developer.

What should I send App Review if they cannot reach the app behind login? Provide demo credentials, a clear demo mode, and exact steps in App Review Information. Apple says to include login details when the app has a login, and to use a built-in demo mode only when a demo account is not practical and Apple has approved that approach.

Does Apple allow apps to require personal information before users can try the app? Only when the information is directly relevant to the core functionality or required by law. Apple says apps may not require personal information to function in ordinary cases, and they should provide access without login when the app is not primarily account-based.

Where does Apple explain the current sign-in rule? In the App Store Review Guidelines, especially section 5.1.1(v) for Account Sign-In and section 4.8 for Login Services. Apple also published a news update when it introduced the sign-in rules.

Sources 1. Apple App Store Review Guidelines, https://developer.apple.com/app-store/review/guidelines/ 2. Apple App Review page, https://developer.apple.com/app-store/review/ 3. Apple News, New Guidelines for Sign in with Apple, https://developer.apple.com/news/?id=09122019b 4. Apple Sign in with Apple Human Interface Guidelines, https://developer.apple.com/design/human-interface-guidelines/sign-in-with-apple?changes=la__1_5 5. Apple Sign in with Apple usage guidelines for websites and other platforms, https://developer.apple.com/sign-in-with-apple/usage-guidelines-for-websites-and-other-platforms/ 6. Apple App Store Support, https://developer.apple.com/support/app-store/

Frequently asked questions

Does Apple require Sign in with Apple for every app with login

No. Apple requires an equivalent Sign in with Apple option when you use a third-party or social login service for the app’s primary account.

Can an app require login if it has subscriptions or saved data

Yes, when the account is tied to the app’s core service, stored data, or a regulated workflow.

What should I send App Review if they cannot reach the app behind login

Provide demo credentials, a clear demo mode, and exact steps in App Review Information.

Does Apple allow apps to require personal information before users can try the app

Only when the information is directly relevant to the core functionality or required by law.

Where does Apple explain the current sign-in rule

In the App Store Review Guidelines, especially sections 5.1.1(v) and 4.8.

Sources

Every link here was fetched and confirmed to resolve before this page went live.

Related questions

Not the question you had?

Ask it. Every source gets fetched and checked before anything goes up, so it takes a day or two, and questions that cannot be answered honestly do not get a page at all.

No account, no email address needed.

Where developers talk about this

DevConnect has communities for the things this page covers. Smaller than the big forums, and nobody is farming engagement.