# Rejecting Authentication in AfterHook

**URL:** <https://forum.heroiclabs.com/t/rejecting-authentication-in-afterhook/5307>\
**Category:** Runtime Framework\
**Tags:** server-framework, authentication\
**Created:** [June 4, 2024, 4:06pm UTC](https://forum.heroiclabs.com/t/rejecting-authentication-in-afterhook/5307 "2024-06-04T16:06:36Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![Wobling](https://avatars.discourse-cdn.com/v4/letter/w/a698b9/32.png) [@Wobling](https://forum.heroiclabs.com/u/Wobling)\
**Post date:** [June 4, 2024, 4:06pm UTC](https://forum.heroiclabs.com/t/rejecting-authentication-in-afterhook/5307/1 "2024-06-04T16:06:36Z")

</div>

Hi,

I am using the CustomAuthentication to authenticate with another service.  
I want to store some information on Nakama about a custom account ID and then each login query that to make sure the AccountID from the client matches their original when they first logged in and an account was created.

If the AccountID they sent from the client doesn’t match that which we have on the backend I want to reject the auth, however, by the time the UserID is available to check the storage we’re in the afterHook and Auth has been granted.

I thought I could force a logout but then the client just re-auths next time it needs to make a request.

From my understanding there is no way to get the UserID during the beforeHook as it’s before the auth has occured.

Any help is greatly appreciated,  
Thanks,

Rob.

---

<div class="post-metadata">

**Author:** ![sesposito](https://sea2.discourse-cdn.com/flex020/user_avatar/forum.heroiclabs.com/sesposito/32/2594_2.png) [@sesposito](https://forum.heroiclabs.com/u/sesposito)\
**Post date:** [June 4, 2024, 4:22pm UTC](https://forum.heroiclabs.com/t/rejecting-authentication-in-afterhook/5307/2 "2024-06-04T16:22:02Z")

</div>

@Wobling the after hook is executed after the authentication happened at which point it cannot be stopped.

You could contact the authentication provider in the beforeHook and guard the Nakama authentication from continuing if the values don’t match. However this means that each successful auth will go to the provider twice.

> I want to store some information on Nakama about a custom account ID and then each login query that to make sure the AccountID from the client matches their original when they first logged in and an account was created.
> 
> If the AccountID they sent from the client doesn’t match that which we have on the backend I want to reject the auth

May I ask what’s the use-case for this?
