Security logOOC
Failed sign-ins, rate limits and bursts of denied pages across the site, for site staff.
The security log shows site staff what looks like someone trying their luck: sign-ins that failed or were tampered with, people hitting a rate limit (too many card look-ups, letters, uploads, imports or invite codes in a short time), and accounts that open many pages they can’t see.
Each line names the account when someone was signed in. The source is a keyed hash of the IP address, so lines from the same place match, but the address itself is never stored. Lines are kept for 90 days. It is out of character, and only the site owner and site staff can open it, from the Site page. It covers the whole site, every server on it.
Rate limits
When someone goes over a limit they see “Too many attempts. Wait a minute and try again.” The limits are generous for real use. One line is written per limit and window, not one per attempt.