Streamer dashboard

Security

The Security page answers three questions: who is signed in to my account right now, where did they sign in from, and can I get in quickly without going through a platform. The first two are look-and-kick; the third is passkeys.

What it solves

A compromised account rarely announces itself. Settings change, notifications get switched off, and you find out days later. This page lays out the active sessions and recent login activity so you can spot the entry that does not belong and cut it off yourself, without waiting on the platform to do something about it.

Passkeys

A passkey signs you in with your device's fingerprint, face or PIN. No password to type, and no one-time code that can be phished out of you. An account can hold several — one on the phone and one on the desktop is the usual setup. Name them after the device; you will want to know which is which when it is time to delete one.

The passkey itself lives on your device or in your password manager and only the public key is stored here, so deleting an entry gives nobody any new information — that key simply stops opening the door. Add the new device's passkey before you retire the old phone, otherwise platform sign-in is the only way back in.

Signed-in devices

This lists the sessions that are still valid, each with its operating system, browser and approximate location; the one you are reading this on is marked as the current device, and at most the 20 most recent are shown. Sign out anything you do not recognise, or use "sign out all other devices" to keep the current one and drop the rest — including any that did not fit on the list.

Once revoked, that device can no longer extend its session and is asked to sign in again within about fifteen minutes — it is not cut off the instant you click. So if you suspect the account is compromised, signing out other devices is only step one: also revoke the authorisation on the platform (Twitch / YouTube) and check that your platform identities have not been tampered with.

Login history

A record of recent successful sign-ins, with platform, device and approximate location, kept for 90 days. The difference from the list above: that one shows what is still live, this one shows what happened — a suspicious session that ended long ago only appears here.

Where the location comes from

Location is estimated from the network address and resolves to a city or region at best. Full IP addresses are never displayed. Inaccuracy is normal: mobile networks often land wherever the carrier's gateway sits, and a VPN simply shows its exit node. So when judging whether something is suspicious, the device and the timestamp are more reliable than the place — "a browser I have never used" says far more than "a city one over".

Common misconceptions

  • Signing out other devices changes no settings. It only invalidates those sessions; linked platforms, plan and channel roles are untouched.
  • There is no password to reset. Sign-in here is platform authorisation plus passkeys. If you suspect the account is at risk, the right moves are: sign out other devices, review your platform identities, and revoke the authorisation on the platform's own settings.
  • The login-alert switch is not on this page. It lives under notification preferences on the Account page, and can go to email or Discord DM.
  • A wrong-looking location is not proof of a breach. Check whether the device and time line up first, then decide whether to revoke.