// answer

Did Apple Change App Store Review Rules for Logins?

Short answer

Yes. Apple now states more clearly that apps with account-based features must give App Review full access, using a valid demo account or a fully featured demo mode, plus any needed credentials or notes.

If you want to ask a follow-up rather than read one: Join a community

Did Apple change App Store review rules around account access and demo logins

Yes. Apple’s current review guidance says App Review must be able to reach the full app experience, and if features require sign-in you should provide a valid demo account, or a fully featured demo mode with the needed notes and resources. The rule is about reviewer access, not about letting them guess their way through your product.

Apple now says this in several places. The App Review guidance tells you to provide full access, and if some features require signing in, to give a valid demo account username and password. The App Store Review Guidelines also say that if your app includes account-based features, you should provide either an active demo account or a fully featured demo mode, plus anything else the reviewer needs.

What people get wrong is thinking Apple wants a throwaway login and nothing else. Apple’s current guidance also asks for review notes, backend access during review, and explanations for special setup, extra hardware, or auth codes when those are part of the flow. If the reviewer cannot see the core experience, the submission is incomplete from Apple’s point of view.

The inconvenient part is that “login required” is not a complete answer. If your app needs a login, Apple still expects a working path through the product, meaning the account has to be live, the backend has to be reachable, and the reviewer has to be able to get past anything non-obvious. If the app has multiple account types, Apple’s review tips say to include credentials for each type in the notes.

Apple also distinguishes between access for review and access for the public. Its guidelines on account sign-in say apps with significant account-based features should not force a login when the core app functionality is not tied to a specific social network, and they should provide access without login or through another mechanism when that fits the app. That is the part many teams miss: review access rules and product access rules overlap, but they are not identical.

A practical example helps. If your app is a workout tracker and the dashboard, history, and export tools all live behind sign-in, then App Review needs credentials that reach those screens, plus any setup steps, sample data, or permissions needed to test them. If your app has a demo mode instead, that mode has to show the real behavior, not a blank shell or a marketing tour.

If your team uses a one-time code, a device binding, a QR scan, or a second factor, put that in App Review Information before submission. Apple’s review materials specifically warn that if extra authentication is required, you should supply the code in advance or be prepared for the review to stall until someone can resolve it. That is not a policy loophole, it is the standard path for getting a review finished.

The best way to read the current rules is simple: Apple did not move toward hidden-product reviews, it moved toward clearer access requirements. The company now states the reviewer must be able to exercise the app, and it spells out the acceptable ways to do that: demo account, demo mode, notes, credentials, working backend, and any special materials the app needs.

For teams building with a test exchange like DevConnect, the useful takeaway is to prepare a reviewer-ready account before you ship. The same principle applies on every submission: if a feature only works after login, the login path has to be part of the review package, not an obstacle the reviewer has to solve. You can keep the product private and still make review smooth by documenting the exact path. https://devconnectplatform.com

A good submission note usually answers four questions: which account to use, what to click first, what data or permissions are already in place, and what special step the reviewer should expect. Apple’s own guidance points reviewers toward the App Review Information section for these details, so that is where the answer should live. If the app has separate admin and user flows, include both.

So, yes, the rules changed in the sense that Apple’s current guidance is more explicit and more operational. The standard is now easier to read and harder to ignore: give App Review real access, give it the login details it needs, and give it enough context to verify the app without guessing.

FAQ

Do I always need a demo account No. If the app does not require sign-in for the part being reviewed, you may not need one. If any important feature is behind authentication, Apple expects a valid demo account or an approved demo mode that exposes that feature set.

Can I use a demo mode instead of real credentials Yes, if Apple can still review the full experience. Apple’s guidelines say a fully featured demo mode can replace a demo account when legal or security obligations prevent you from sharing real login access, but the mode still has to show the app’s actual functionality.

Where do I put extra login steps like OTP or auth codes Put them in App Review Information and in the notes field for the version you submit. Apple’s review guidance says to include special configurations, credentials, and any code needed to complete sign-in so the reviewer does not get stuck halfway through.

What happens if the reviewer cannot get into the account The review can stall or fail because Apple cannot verify the app’s behavior. Apple’s own materials say incomplete information, unreachable backend services, or missing login details slow review and can lead to rejection.

Does this affect unlisted apps or beta review too Yes. Apple says unlisted apps still follow App Review guidelines, and its review detail APIs include demo-account fields for review use. Distribution type does not remove the need to provide working access when the app uses authentication.

Frequently asked questions

Do I always need a demo account

No. If the app does not require sign-in for the part being reviewed, you may not need one. If any important feature is behind authentication, Apple expects a valid demo account or an approved demo mode that exposes that feature set.

Can I use a demo mode instead of real credentials

Yes, if Apple can still review the full experience. Apple’s guidelines say a fully featured demo mode can replace a demo account when legal or security obligations prevent you from sharing real login access, but the mode still has to show the app’s actual functionality.

Where do I put extra login steps like OTP or auth codes

Put them in App Review Information and in the notes field for the version you submit. Apple’s review guidance says to include special configurations, credentials, and any code needed to complete sign-in so the reviewer does not get stuck halfway through.

What happens if the reviewer cannot get into the account

The review can stall or fail because Apple cannot verify the app’s behavior. Apple’s own materials say incomplete information, unreachable backend services, or missing login details slow review and can lead to rejection.

Does this affect unlisted apps or beta review too

Yes. Apple says unlisted apps still follow App Review guidelines, and its review detail APIs include demo-account fields for review use. Distribution type does not remove the need to provide working access when the app uses authentication.

Know someone stuck on this? Send them the answer.

Sources

Every link here was fetched and confirmed to resolve before this page went live.

More on this topic: App testing

Related questions

Not the question you had?

Ask it. Every source gets fetched and checked before anything goes up, so it takes a day or two, and questions that cannot be answered honestly do not get a page at all.

No account, no email address needed.

Where developers talk about this

DevConnect has communities for the things this page covers. Smaller than the big forums, and nobody is farming engagement.