# Magento admin login notifications on your phone

> Get a push notification when someone signs in to your Magento admin, and a High-priority one when admin logins fail, so you notice a login that wasn't you.

- Company: Magento (https://www.justpush.io/recipes/magento)
- Event: `admin.login` (Admin login)
- Tags: E-commerce, Security
- Install: https://studio.justpush.io/recipes/magento/admin-login
- Web page: https://www.justpush.io/recipes/magento/admin-login

## Setup

1. Click Install in Studio and sign in. The recipe is added to your account and you get a personal webhook URL.
2. Install the JustPush module in your shop: composer require justpush/magento-module-notify, then bin/magento setup:upgrade.
3. In the Magento admin, open Stores > Configuration > Services > JustPush and set Enabled to Yes.
4. Paste your webhook URL (shown in Studio after install) into the Admin login field, click Save Config, then click Send test.
5. Magento has no outgoing webhooks, so this recipe needs the free **JustPush module** in your shop ([source](https://github.com/JustPush-io/justpush-magento)). Install it once; it serves every Magento recipe:
6. ```bash
7. composer require justpush/magento-module-notify
8. bin/magento setup:upgrade
9. bin/magento cache:flush
10. ```
11. Then open **Stores → Configuration → Services → JustPush** in the Magento admin, set **Enabled** to **Yes**, paste the URL above into the **Admin login** field and click **Save Config**. Click **Send test**: this recipe answers with a quiet "🔔 Magento connected".
12. The **Admin login** field only exists at **Default Config** scope, because admin logins don't belong to a website. Failed logins are throttled by the module: at most one message per 15 minutes per username, and the push says how many attempts there were. Add `?success=0` to the end of the URL to only get pushes for failed logins.
13. The module sends from Magento's message queue, so Magento cron has to run (it usually does). Without cron, set **Send immediately (no cron)** to **Yes**.
14. The **Locked users** button opens the Magento admin. With Magento's default **Add Secret Key to URLs** setting, it lands on the dashboard rather than the page itself.
15. Requests aren't signed, so keep the URL private.

## Code

Studio calls `handleRequest(request)` with the incoming webhook (`{ method, headers, body, query, raw }`) and sends the message object it returns. Returning `null` sends nothing.

```js
// Magento → admin login
// Fires when the JustPush module (justpush/magento-module-notify) reports an "admin.login" or
// "admin.login_failed" event. The module sends at most one failed-login message per
// 15 minutes per username, with the number of attempts since the last one.
// Docs: https://github.com/JustPush-io/justpush-magento

// The module sends plain strings; treat blanks and nulls as missing.
function text(value) {
    return typeof value === "string" && value.trim() ? value.trim() : null
}

// Only link to real http(s) URLs.
function link(url, cta) {
    return typeof url === "string" && /^https?:\/\//.test(url) ? [{ cta, url }] : []
}

// Which shop sent it, so owners of several websites can tell them apart.
function shop(store) {
    if (!store || typeof store !== "object") return null
    const url = text(store.url)
    const host = url && /^https?:\/\//.test(url) ? url.replace(/^https?:\/\//, "").replace(/\/.*$/, "") : null
    return text(store.website) ?? text(store.store_view) ?? host
}

// The module's "Send test" button; every Magento recipe answers it.
function testPing(body) {
    const from = shop(body.store)
    return {
        title: "🔔 Magento connected",
        message: from ? `${from} is sending to this recipe` : "Your shop is sending to this recipe",
        topic: "Magento",
        priority: -1, // Low — you just clicked the button
    }
}

// Admin logins aren't tied to a website, so name the shop by its address.
function host(store) {
    const url = text(store?.url)
    return url && /^https?:\/\//.test(url) ? url.replace(/^https?:\/\//, "").replace(/\/.*$/, "") : shop(store)
}

function handleRequest(request) {
    const body = request.body && typeof request.body === "object" ? request.body : {}

    if (body.event === "test.ping") return testPing(body)

    // Guard: only handle this recipe's events, so other Magento events on this integration stay quiet.
    const admin = body.admin
    if (!["admin.login", "admin.login_failed"].includes(body.event) || !admin || typeof admin !== "object") {
        console.log(`Ignoring Magento event "${body.event ?? "unknown"}"`)
        return null
    }

    const username = text(admin.username)
    const ip = text(admin.ip)
    const site = host(body.store)

    if (body.event === "admin.login_failed") {
        const count = Number(admin.attempts)
        const attempts = Number.isFinite(count) && count > 1 ? `${Math.round(count)} failed attempts` : "Failed attempt"
        return {
            title: "⚠️ Failed admin login",
            message: [
                `${attempts}${username ? ` for ${username}` : ""}${ip ? ` from ${ip}` : ""}`,
                site,
            ]
                .filter(Boolean)
                .join(" · "),
            topic: "Magento",
            priority: 1, // High — could be someone guessing passwords
            buttons: link(admin.admin_url, "Locked users"),
        }
    }

    // ?success=0 keeps only failed logins.
    if (request.query?.success === "0") {
        console.log("Successful login and ?success=0 is set — skipping")
        return null
    }

    const name = text(admin.name)
    const who = name && username ? `${name} (${username})` : name ?? username ?? "An admin user"

    return {
        title: "🔐 Admin signed in",
        message: [`${who} signed in${ip ? ` from ${ip}` : ""}`, site].filter(Boolean).join(" · "),
        topic: "Magento",
        priority: 0, // Normal — you'll recognise your own logins; a stranger's is worth the ping
        buttons: link(admin.admin_url, "Open user"),
    }
}
```

## Magento admin.login webhook payload (sample)

```json
{
  "admin": {
    "ip": "203.0.113.7",
    "attempts": 1,
    "username": "john.smith",
    "admin_url": "https://shop.example.com/admin/admin/locks/index/"
  },
  "event": "admin.login_failed",
  "store": {
    "url": "https://shop.example.com/",
    "website": "Main Website",
    "store_view": "Default Store View"
  },
  "sent_at": "2026-09-30T14:29:28Z",
  "version": 1
}
```

## FAQ

### Does this work on iPhone and Android?

Yes. Install the JustPush app from the App Store or Google Play and sign in. Every phone signed in to your account gets the notification.

### Do I need to write code?

No. Install the recipe in Studio, paste your webhook URL into Magento and you are done. The code is there if you want to change the text, the sound or the buttons.

### Can I change what the notification says?

Yes. After install the recipe's code is yours. Edit it in Studio and test it against the sample payload before you save.

### What does it cost?

JustPush is free for 30 days. After that it's $19.99 a year, or $39.99 once. There is no extra charge for recipes.
