Two panels: Logins and Banned sessions
Storeep gives you two separate panels under Settings. Logins lists every active login to your own merchant account so you can spot and end suspicious sessions. Banned sessions lists every IP address and device that has been blocked from your storefront. Both panels require the Settings permission, so staff without it cannot open them.
Logins (active account sessions)
Open Settings, then the Logins card (described as "Active sessions and login history"). The table lists all active logins for your account, newest first, 40 per page. Each row shows:
- Date: when the login was created, in your store timezone.
- IP: the IP address the login came from.
- Country: a flag derived from that IP.
- Browser, OS, Device: the detected browser, operating system, and device.
Your current login carries a This device badge. Its checkbox and logout button are disabled so you cannot accidentally sign yourself out. A note at the top warns: "Logging in from a location or IP address you don't know may indicate that the account has been hacked."
Logging out a session
- To end one login, click the power icon at the end of its row (tooltip: Logout the session).
- To end several at once, tick their checkboxes, then use the Logout sessions action in the table dropdown.
Logging out deletes that login token immediately. Whoever was using it is returned to the login screen on their next request. You cannot select your current login, so this never logs you out.
Banned sessions
Open Settings, then the Banned sessions card ("Blocked IPs and devices from your store"). This panel merges two ban sources into one list, newest first, 20 per page: banned IP addresses (from a session marked banned) and banned devices (from the Shield blocklist). A note explains: "IPs and devices banned from your store. Bans created from order details appear here even when the Spy Blocker or Shield app is not installed."
Reading the ban table
- IP / Device: the exact IP address for an IP ban, or the device fingerprint for a device ban. The ban date and time (store timezone) sits below it.
- Type: a tag reading IP (globe icon) or Device (shield icon).
- Country: a flag from the linked session, or a dash when no session data is attached.
- Browser, OS, Device: from the linked session, or a dash.
- VPN/Proxy: Detected or Undetected from the session, or a dash when unknown.
Device-ban rows borrow their country, browser, OS, device, and VPN columns from the most recent session that shared the same fingerprint, which is why those cells can show a dash if no matching session exists.
Releasing a ban
- To lift one ban, click the unlock icon at the end of its row (tooltip: Release this ban).
- To lift several, tick their checkboxes, then choose Release selected bans from the dropdown.
You can mix IP and device bans in a single release and they all lift together. Releasing an IP ban re-enables that session; releasing a device ban removes the fingerprint from the Shield blocklist and unblocks every session that shared it. The whole release runs in one transaction, so if anything fails, nothing changes and you can simply try again.
How bans get created
Bans never appear on their own. They come from these actions:
- Spy Blocker, automatically: when installed and active, it blocks copying text and downloading images, and escalates a developer-tools or inspection attempt into an IP ban for that visitor. The inspection ban only triggers on desktop, since real developer tools cannot be opened on a phone. In the Spy Blocker app these banned IPs appear under a list called Spies.
- Order details, manually (IP): from an order, you can ban the customer's IP. This works even without the Spy Blocker app. Clicking it again unbans the IP.
- Order details, manually (device): from an order, you can ban the customer's device. This action requires the Shield app to be installed. Clicking it again unbans the device.
Good to know
- Bans are store-wide. They apply across every market and page of your storefront, not per country.
- If Shield Decoy mode is on, banning a device keeps that visitor seeing a normal store with fake order confirmations instead of an immediate block, so they may not realize they are banned.
- A banned IP or device is refused at session creation, which stops new orders from that visitor.
- When you have no banned IPs or devices yet, the panel shows an empty state instead of a table.