To prevent anybody to open identity onto Sphinx, please can you consider to integrate invitation support ?
sending email + invitation code > email invitation with preregistration inside sphinx
Exposed by an Endpoint in Sphinx API to fire such invitation from linked applications backoffice.
authorization to register using email + invitation code to continue
That's an interesting suggestion, but something that can be implemented outside Sphinx. I would ask and suggest you create a feature request that can be voted by others.
For now you can simply disable user registration and simply register users yourself from code, based on any criteria you want.