Login history and two-step verification
Protect sign-ins with a code from your phone, require it from your team, and check who signed in to your store.
The Security page shows every sign-in to your dashboard from the last 12 months. Use it to spot a login you don't recognise, check when a teammate last worked in the store, or confirm when our support team looked at your store.
Turn on two-step verification
Two-step verification asks for a code from your phone every time you sign in, after your password or your Google sign-in. Even if someone learns your password, they can't get in without your phone.
- Open Settings → Profile and find Two-step verification.
- Click Set up. If you sign in with a password, enter it.
- Scan the QR code with an authenticator app, such as Google Authenticator, 1Password or Authy.
- Enter the 6-digit code the app shows, then click Turn on.
- Save your backup codes somewhere safe. Each one works once if you lose your phone.
Two-step verification belongs to your account, so it protects every store you work in.
Signing in with two-step verification on
After your password or Google sign-in, enter the code from your app. Don't have your phone? Choose Email me a code instead, or Use a backup code.
Tick Trust this browser for 30 days on your own computer to skip the code there for a month.
Tip: Lost your phone and your backup codes? Ask the store owner or an admin to reset your two-step verification from Settings → Team. If you're the owner, contact YNS support.
Require it from your whole team
The owner and admins can make two-step verification compulsory for everyone working in the store.
- Turn it on for your own account first.
- Open Settings → Security and click Require next to Require two-step verification.
- Check the list of teammates who don't have it yet, then confirm.
From then on, anyone without two-step verification is asked to set it up the next time they open the store, and can't do anything there until they have. Settings → Team shows who has it on.
Open your login history
Go to Settings → Security. Each entry shows:
- What happened – a sign-in, a failed sign-in, a sign-out, or YNS support opening the store
- Who – the team member it belongs to
- How – password, Google or GitHub, plus the second step if there was one
- Where from – the browser and device, the IP address, and the city and country we could tell from it
- When – the date and time, in your own time zone
Use the tabs to show only one kind of event, the date filter to narrow it to a period, and Older to page back.
Who sees what
| Person | What they see |
|---|---|
| Owner and admins | Everyone on the team, plus YNS support visits. A Team member filter shows one person at a time |
| Everyone else | Only their own sign-ins |
A sign-in belongs to a person, not a store. If someone works in several stores, their history shows every time they signed in to the dashboard, but never which store they opened.
Only the dashboard is covered. Your customers signing in to your storefront or at checkout don't appear here.
Failed sign-ins
A failed sign-in means someone typed the right email with the wrong password, or the wrong two-step code. One or two usually mean a typo. Many in a row, especially from a place your team doesn't work from, can mean someone is guessing.
Caution: If you see failed sign-ins you don't recognise on your own account, change your password straight away. If they're on a teammate's account, ask them to do the same.
YNS support visits
When our support team opens your store to help you, the history shows YNS support opened the store. You'll see one entry per support person per day, however many pages they looked at. We keep a record of who it was on our side.
How long we keep it
Entries are deleted automatically after 12 months.