Merchant Notifications and Activity Log: Watch Your Account
MercanPay in-panel notifications, email alert settings, the activity log and open sessions. Keep an eye on payments, payouts and security events in one place.

Merchant notifications and the activity log are the two main ways to follow what happens in your MercanPay account. Notifications tell you what happened: a payment arrived, a payout completed, support replied. The activity log tells you who did what, when and from where. This post covers both, plus email settings and session management.
The Notifications page
The Notifications page lists important account events in time order, and the panel shows an unread count so new items stand out. Events fall into four categories:
| Category | What it includes |
|---|---|
| Payments | Paid, underpaid, overpaid and cancelled invoices |
| Withdrawals | Completed, failed or rejected payouts, and results of trusted-address requests |
| Account | Account approval and status changes |
| Security | Password changes and resets, Authenticator turned on or off, withdrawal locks |
Replies to your support tickets and closed tickets show up here too. See Merchant support tickets.
You can filter by category, show unread items only, and mark everything as read in one click.
Email alerts: what do you want in your inbox?
In-panel notifications are always listed. Email is controlled by two switches:
- Payment emails: when a payment arrives, or an invoice is underpaid or overpaid.
- Withdrawal emails: when a payout completes, fails or is rejected.
These switches only affect email. Turn them off and the events still appear on the Notifications page.
A rough guide:
- A few payments a day? Keep payment emails on.
- High volume? Payment emails can flood your inbox. If your orders are processed automatically by webhooks, turning them off and watching the panel may be tidier.
- Withdrawal emails: we recommend keeping them on. Knowing about every outflow from your balance is a good security habit.
Security emails, such as a changed password or a disabled Authenticator, don't depend on these switches and are always sent.
Notifications are not a trigger for business logic. Fulfil orders from signed webhooks; the event list is in Crypto payment webhook events.
The activity log: who did what?
The activity log records actions taken on your account, including:
- sign-ins and sign-outs,
- security changes (password, Authenticator, sign-in method),
- invoice creation and cancellation,
- withdrawal requests and saved-address changes,
- API key creation and revocation,
- report downloads,
- optionally, individual API requests.
Each entry shows the time, outcome and IP address. You can search the log and filter by action type. API requests are hidden by default because they add up quickly on an integrated account, but you can show them while debugging an integration.
When to check it
- Regularly: a quick weekly look helps you spot a sign-in you don't recognise.
- After a security email: the log shows the details and the IP.
- When a change is questioned: "who changed the webhook URL?" is answered here.
- Before opening a support ticket: noting the time and outcome of the action speeds things up.
To keep a copy, export the Activity dataset from the panel as CSV, Excel or PDF; see Export crypto payment reports.
Open sessions
The security section lists the sessions where your account is signed in, with each one's last activity and your current session marked. You can:
- Sign out a session: for example, one left open on a shared computer.
- Sign out all other sessions: everything except the one you're using. Do this first if you lose your phone or see a suspicious sign-in.
Sign-in verification method
Signing in to MercanPay always takes two steps. You choose what the second step asks for:
| Method | Asked at sign-in |
|---|---|
| A code sent to your email | |
| Authenticator | A code from an app such as Google Authenticator |
| Both | An email code and an Authenticator code |
Once the Authenticator is set up you can move to a stronger method. One important detail: weakening sign-in, say from "both" back to "email only", requires an Authenticator code on top of your password. Someone who has your password and an open session still can't strip the second factor.
The wider logic of 2FA and withdrawal security is in Crypto merchant account security.
Spotted something suspicious? Five steps
- Sign out all other sessions.
- Change your password. Withdrawals may then be locked for a while as a safety measure.
- Review your API keys and revoke any you don't trust.
- Check your saved withdrawal addresses.
- Open a support ticket and include the times of the relevant log entries.
FAQ
If I turn off payment emails, will I miss payments?
No. Payments still show on the Notifications page and in the invoice list, and your webhooks are sent as usual. Only the emails stop.
Why don't I see my API requests in the activity log?
They're hidden by default. Turn on the option to show them.
I see a session I don't recognise. What now?
Use "Sign out all other sessions" right away, then change your password and review your API keys.
Why can't I change my sign-in method without an Authenticator code?
Downgrading to a weaker method is exactly what an attacker would try first, so it requires the Authenticator code.
Get started with MercanPay
Watch payments, payouts and account security from one panel: apply as a merchant and explore the documentation.


