Will Shopify's Login History Still Show a Login From Weeks Ago?
Login history retention on Shopify stops at the five most recent sessions per staff member, so BUILD the forensic trail outside the platform. Route staff sign-in through your own identity provider and keep its logs as long as policy requires. Shopify's store activity log adds context but caps at 250 displayed results with no export. Audit-log apps starting at $9.99/month (verified Sep 2026) extend change history, not login history.
Your profile — see how the verdict shifts
- Confidence
- High — The ceiling is documented and exact: Shopify's user-management activity log lets you review the five most recent login sessions and, for each, the date, IP address, ISP, the staff member's location at login, and the browser and operating system. No plan tier lifts that count, and Plus adds nothing here. The app search was deliberate rather than assumed. We browsed the App Store's Store Management security category and searched the sitemap for activity-log, audit-log, login-history and session-log listings. Logify, AuditRay and Otheriver Audit Logs were each fetched in full and searched for login: only page-chrome matches came back, with no login-session-history feature described on any of the three. Tickr Customer Login History does track logins, but its own description scopes it to customers rather than staff and admin users, so it does not answer this question. AuditRay's Pro tier genuinely holds 365 days of event history against Shopify's five-session view, which is why it earns a row. What no app on the Store demonstrates is a staff sign-in record with IP address and browser going back three weeks. Okta and OneLogin publish no Shopify App Store app at all: on Plus you wire a SAML or OIDC provider into admin, or bridge it with a third-party SSO app, and the provider's own sign-in log becomes the artifact your auditor reads. That routing is our recommendation, not a Shopify-stated remedy.
- Reference scenario
- $20M–$100M GMV · Shopify Plus · 25+ staff accounts across agency and in-house · an incident-response policy with a written log-retention clause
- As of
- September 2026
Decision at a Glance
| Your profile | Verdict | Why |
|---|---|---|
| Under 10 staff accounts · no audit obligation | WAIT | Five sessions per person covers a store where three people log in and everyone knows everyone. Turn on two-step verification and move on. |
| 10–50 staff · internal security policy only | BUY | An audit-log app at $9.99–$19/month (verified Sep 2026) buys back change history cheaply. It won't record sign-ins, so write that gap into the policy instead of pretending it's covered. |
| 50+ staff or agency access · SOC 2 evidence expected | BUILD | Auditors ask for sign-in records with dates and IP addresses across a review period. Five sessions per user cannot produce that, and an identity provider can. |
| Regulated or contractual retention clause (12 months+) | BUILD | A retention clause you signed is a hard requirement, and Shopify's native view fails it on day one. Route sign-in through the identity provider and ship its events to your SIEM. |
What Login History Retention Limits Actually Drives
| Outcome | Impact | How it works |
|---|---|---|
| Operational efficiency | High | An access review that queries a sign-in log takes an hour; one that reconstructs history from five sessions per user and screenshots takes a week and still has holes. |
| Data & insight | High | Sign-in telemetry with IP addresses and locations is what anomaly detection runs on, and Shopify's five-session window is too short a series to detect anything from. |
| Revenue — indirect | Medium | Enterprise and public-sector contracts increasingly ask for evidence of access controls before signing, and a missing login trail slows or blocks that paperwork. |
| Customer experience | Low | Shoppers never see staff login logs, and the only customer-visible effect arrives on the bad day when an incident takes longer to scope. |
Spend ceiling: Don't buy an audit-log app to solve login forensics — it solves a different problem. Size the spend to the retention clause you actually signed: no clause means no spend, and a 12-month clause means an identity provider.
What buying enables (top apps)
- + Admin change history running months or a year past what the native admin shows, live the same afternoon
- + Alerting on sensitive edits into Slack, Discord or a webhook, which Shopify's own logs never do
- + CSV export of event history from AuditRay's Basic tier upward, against a native store activity log that can't be exported at all
- + A cheap answer for the common question (who changed this price) without touching authentication
What building additionally unlocks
- + A staff sign-in record with date, IP address and device that outlives five sessions, which no listing we checked provides
- + Retention set by your policy rather than by a vendor's pricing tier
- + Instant revocation across every connected system when someone leaves, not just Shopify
- + One access-review artifact covering Shopify alongside the rest of your stack
Find Your Verdict in 3 Questions
Does any contract, certification or internal policy require staff sign-in records older than the last five sessions?
Yes: Go to question 2.
No: Your verdict: WAIT — the native five-session view plus two-step verification is proportionate; revisit when an auditor asks.
Do you already run an identity provider (Okta, OneLogin, Entra ID) for other systems?
Yes: Your verdict: BUILD — extend the existing provider to Shopify staff and the sign-in record comes with it.
No: Go to question 3.
Is the immediate need change history (who edited which field) rather than sign-in forensics?
Yes: Your verdict: BUY — an audit-log app from $9.99/month (verified Sep 2026) covers change history today; write the login gap into your policy.
No: Your verdict: BUILD — stand up the identity provider, because no App Store listing we checked records a staff sign-in with its IP address.
The TCC Scorecard — 12 Dimensions
TCC — Total Cost of Capability: what it actually costs to have this capability over three years, whichever way you get it. Each dimension is scored 0–5 for both paths. How we score →
| Dimension | Buy | Build | Why |
|---|---|---|---|
| Cost | |||
| Acquisition & implementation | An audit-log app installs the same afternoon; an SSO rollout across 25 staff plus a log pipeline runs 4–8 weeks (Deploi estimate, illustrative). | ||
| Recurring fees | App tiers run $9.99–$99/month (verified Sep 2026), while identity providers price per user per month and never stop. | ||
| Maintenance & upgrades | The app is the vendor's problem; SSO means owning provisioning, deprovisioning and a break-glass account you test twice a year. | ||
| Switching & exit | App event history lives in the vendor's database and leaves with the vendor; identity-provider logs are yours to export in any standard format. | ||
| Risk | |||
| Vendor risk | Logify carries 8 reviews and AuditRay none at all, so the category rests on very young listings; identity providers are enterprise infrastructure with their own audit history. | ||
| Security & compliance surface | An audit-log app adds a third party holding your admin event stream; SSO reduces credential sprawl and centralizes revocation. | ||
| Platform-deprecation exposure | Both paths ride Shopify's admin surface, but a SAML or OIDC connection is a standards-based integration rather than an app-specific one. | ||
| Value | |||
| Fit to requirement | No App Store listing we checked records a staff sign-in with its IP address; an identity provider records every one of them by default. | ||
| Time to market | An app is live today; SSO waits on provider procurement, staff migration and a tested break-glass path. | ||
| Performance & scale | Shopify shows 250 results maximum on the store activity log page, while a warehouse or SIEM holds years of sign-in events without a display cap. | ||
| Data ownership & AI-readiness | Sign-in telemetry in your own store feeds anomaly detection and access reviews; rented event history answers only the questions the app's UI asks. | ||
| Focus & opportunity cost | SSO is real security work that pays off beyond Shopify, but it is still a quarter of someone's attention you are spending. | ||
The App Landscape
| App | Status | Pricing | Best for |
|---|---|---|---|
| Logify: Activity & Staff Logs | Live — flagged — 4.8★, 8 reviews; young listing with a thin review base. Logs staff activity (who changed which field, and when) well past what the admin shows. The listing describes no login-session history: no sign-in timestamp, no IP address, no browser and operating system. | No free plan; Starter $19/month (100K logs/month, 170K staff-activity events, last 60 days retained); Business $39/month; Pro $59/month; Ultimate $99/month; 7-day free trial (verified Sep 2026) | Extending admin change history past the native window on a small budget |
| AuditRay | Live — flagged — No reviews yet; unreviewed listing, so treat the roadmap as unproven. Pro retains 365 days of event history against Shopify's five-session login view and adds Slack, Discord and webhook alerts. It records store and data changes, not staff sign-ins. | Free (7-day history, 10K events/month, 1 alert rule); Basic $9.99/month (30-day history, 50K events/month, CSV export); Pro $14.99/month (365-day history, unlimited events, Slack, Discord and webhook alerts); 14-day free trial (verified Sep 2026) | Long change-history retention with alerting at the lowest price in the category |
| Identity provider (Okta, OneLogin, Entra ID) | Live — Platform integration; no App Store listing. Okta and OneLogin publish no Shopify App Store app: on Plus you wire a SAML or OIDC provider into Shopify admin, or bridge it with a third-party SSO app. The provider keeps its own sign-in log, which is the retention this page is about. | Per-user subscription billed outside Shopify; budget $3–$8 per user per month (Deploi estimate, illustrative; confirm on the provider's current pricing page) | Staff login forensics that has to reach past five sessions |
| SSO plus log pipeline (custom) | Build lane — Route staff into Shopify through the identity provider, ship its sign-in events into your SIEM or warehouse, and add a scheduled capture of the store activity log. Shopify caps that page at 250 results, says it can't be exported or downloaded, and recommends screenshots or manual documentation for a compliance record. | $15,000–$35,000 one-time plus the identity-provider subscription (Deploi estimate, illustrative) | A retention clause you have to evidence in front of an auditor |
The Build Path
- SAML or OIDC single sign-on for staff: Staff authenticate at the identity provider, which records every sign-in with date, IP address, device and outcome, and keeps it for as long as your policy sets. Shopify's five-session view stops being the record.
- Event pipeline into a SIEM or warehouse: Stream provider sign-in events plus Shopify webhook traffic into one store, so an access review or an incident timeline is a query rather than a screenshot hunt.
- Scheduled capture of the store activity log: The store activity log shows 250 results maximum and can't be exported, so a weekly manual capture into your evidence folder is the only durable copy. Shopify recommends exactly that: screenshots or manual documentation.
- Effort band
- $15,000–$35,000 one-time (Deploi estimate, illustrative); lands in the $10–25K to $25–75K contact-form bands depending on how many systems join the SSO rollout
- Typical timeline
- 4–8 weeks (Deploi estimate, illustrative): provider setup, staff migration, break-glass testing, then the log pipeline
- Maintenance, honestly
- $4,000–$9,000/yr (Deploi estimate, illustrative) plus the per-user identity-provider subscription: joiner and leaver flows, a twice-yearly break-glass test, and retention-policy review.
- What you own — and what you take on
- You own: the sign-in record, its retention period, the export format, and the ability to answer an auditor without asking a vendor. You take on: provisioning and deprovisioning discipline, and a break-glass account that has to work the day the provider doesn't.
3-Year Total Cost of Capability
| Buy (app path) | Build (custom path) | |
|---|---|---|
| Year 0 (setup) | $0–$500 (illustrative) | $15,000–$35,000 (Deploi estimate, illustrative) |
| Years 1–3 (recurring) | $540–$2,200 (illustrative) | $14,700–$32,400 (Deploi estimate, illustrative) |
| 3-year total | ≈$540–$2,700 (illustrative) | ≈$30,000–$67,000 (Deploi estimate, illustrative) |
- † All figures illustrative samples for the reference scenario — not quotes, not verified pricing.
- † App path: one audit-log subscription in the $14.99–$59/month range held flat for three years, with no login-session coverage.
- † Build path: 25 staff on an identity provider, one SSO rollout, and a log pipeline into an existing warehouse; three-year horizon.
What the Sticker Price Hides
On the buy path
- — Audit-log apps record field changes, not sign-ins — the two get conflated at install and discovered during an incident
- — Retention is a pricing lever: 7 days free, 30 days on Basic, 365 days on Pro at $14.99/month (verified Sep 2026)
- — Event caps are per month, and a busy Plus store burns through a 10K-event tier fast
- — Logify has 8 reviews and AuditRay none, so category continuity is a live risk, and your history leaves with the vendor
On the build path
- — Per-user identity-provider licensing scales with headcount, and agency seats count too
- — Deprovisioning discipline is the whole point and the easiest thing to let slip
- — A break-glass account that nobody tests is a break-glass account that doesn't work
- — $4,000–$9,000/yr upkeep plus the provider subscription (Deploi estimate, illustrative)
What Merchants Say
The recurring shape of the complaint: a suspicious order gets noticed a fortnight later, and by then the admin's login list has already rolled past the session anyone wanted to look at.
Audit-log app buyers report the mismatch quickly: they installed it expecting sign-in forensics and got a field-change feed, which is useful for a different problem.
If You Change Your Mind Later
If you bought and outgrow it
Export what the plan allows before you cancel, because accumulated event history sits in the vendor's database and AuditRay's CSV export starts on the Basic tier. Retention resets to Shopify's five sessions the moment the app is uninstalled, so capture anything you might need first.
If you built and want out
Nothing is stranded: SAML and OIDC are standards, and sign-in logs export from any identity provider in formats your next tool reads. Swapping providers is a migration project rather than a data loss, and the Shopify side of the configuration is a settings change.
When This Answer Changes
We're watching for:
- ▸ Shopify extending the user-management activity log beyond five sessions, or adding an export to it
- ▸ An audit-log app shipping an explicit staff sign-in feed with IP address and browser — none of the listings we checked describes one
- ▸ A contract or certification landing on your desk with a log-retention clause longer than your current record
Verdict change log:
No changes since first publication (September 2026).
Common Questions
How far back does Shopify's login history go?
Shopify's user-management activity log shows the five most recent login sessions per staff member. Each entry carries the date, IP address, ISP, the staff member's location at login, and the browser and operating system. A sixth login pushes the oldest one out. A three-week-old sign-in survives only if that staff member has logged in fewer than five times since.
Can the store activity log fill the gap?
The store activity log covers admin changes, not login sessions, so it fills only part of the gap. Shopify caps the page at 250 displayed results, states the log can't be exported or downloaded, and recommends screenshots or manual documentation for a compliance record. Use it for context around an incident and keep the login trail in your identity provider.
Do audit-log apps record staff logins?
Audit-log apps record store and data changes, not staff login sessions. Logify (4.8★, 8 reviews) starts at $19/month with 60-day retention, and AuditRay's Pro tier holds 365 days for $14.99/month (verified Sep 2026). Neither listing claims to capture a sign-in event with its IP address and browser. For login forensics past five sessions, the identity provider is the system of record.
Your Next Steps
If you're going with BUILD(matches your selected profile)
- Write down the actual retention requirement in months, and who asks for it
- Inventory staff and agency accounts with admin access, including dormant ones
- Wire SAML or OIDC staff sign-in into Shopify admin and migrate users in waves
- Ship provider sign-in events into your SIEM or warehouse with a defined retention period
- Test the break-glass account, then diary a repeat test in six months
If you're going with BUY
- Confirm on the current listing whether the app records sign-in events or only field changes
- Match the plan's retention window to your policy: 30 days and 365 days are different products
- Check the monthly event cap against your real admin activity, not a guess
- Set alert rules for permission and payout changes on day one
- Record the login-history gap in your incident-response plan rather than assuming it's covered
Official Docs & Sources
- User management activity log — Shopify Help Center
- Store activity log — Shopify Help Center
- Organization-level permissions — Shopify Help Center
Official documentation linked for verification — our verdicts and estimates are our own.
Related Decisions
Can You See Every App's Access Scope in One Place?
Shopify discloses an app's data-access scopes at install and afterward one app at a time from its about page, with no consolidated view across the app fleet.
Can You Trust Every App Store App to Honor GDPR Deletion?
Shopify rejects any App Store app that fails to answer the mandatory compliance webhooks, with a 30-day action window. Custom apps sit outside that scope.
Does 'Built for Shopify' Mean an App Passed Security Review?
Built for Shopify certifies Core Web Vitals, admin latency and 50 net installs. No security or data-handling requirement appears anywhere in the criteria.
Do Custom Apps Inherit Any of Shopify's Compliance Vetting?
Shopify's app review covers both public app types, listed and unlisted. Custom apps are never described as reviewed, and compliance webhooks follow the App Store.
Shopify Theme Sections: Buy Premium or Build a Section Library?
A custom theme section library wins at mid-market campaign tempo; below the floor, a premium theme is the right call.
Need a login trail that survives an audit?
We wire Shopify Plus staff access into your identity provider and pipe the sign-in events somewhere you can actually query them. Five sessions stops being the answer you have to give.
Contact us todayVerdict scored for the reference scenario above. Estimates are not quotes; app pricing carries its verification date and gets re-verified quarterly. Full scoring anchors: see the TCC methodology.
Read how we score these decisions (the TCC Framework). No affiliate links, no paid placement — no app vendor pays to appear here.