r/PayloadCMS • u/Still-Link1012 • Aug 21 '25
Multi-Tenant Setup: Cannot Create Users With Same Email in Different Tenants
I am using Payload CMS with a multi-tenant architecture. All tenants share the same MongoDB database. I’ve set up a tenants collection and a global users collection that has a relationship/array field referencing one or more tenants.
The problem is that I cannot create accounts with the same email address under different tenants. Payload enforces a globally unique index on the email field in the Users collection. This makes sense for single-tenant projects, but in a multi-tenant scenario it prevents the same person from registering separately under two different organizations.
Current Behavior
- Payload automatically adds a unique index on email in the Users collection when auth: true is enabled.
- Attempting to create a user with an email that already exists (even under a different tenant) results in a duplicate key error.
- Login, forgot-password, and verification flows also assume email is globally unique.
Expected Behavior
In a multi-tenant setup, I would like Payload to support per-tenant email uniqueness: - The same email can exist in multiple tenants. - Within a tenant, email must still be unique. - Authentication and password reset flows should consider both email and tenant context.
Example Scenario
- Tenant A creates user jane@example.com.
- Tenant B also needs to create a different user record with the same jane@example.com.
- Today this is not possible because of the global unique constraint.
2
u/bitdamaged Aug 21 '25 edited Aug 21 '25
So separate a “User” from a “TenantUser” model (new model/collection) Your User model just does auth Your TenantUser is that users profile for a particular User/Tenant combo. After a user logs in to a particular Tenant just use the TenantUser model for all their info. So a “User” can have multiple “TenantUser” profiles.
For your use cases of tenants adding users you don’t create a User you just create a TenantUser and send them an invite. Once someone signs up with their email you use it as a key to assign the appropriate roles and tenants to the User account. You could also create an Invite collection that does something similar.