Overview
With the "Enable cookie binding for employees in the POS" setting, employee login can be bound to specific devices.
After activation, when an employee logs in at the POS for the first time, an authentication cookie is set on the device being used, registering that device as an authorized device. All subsequent login attempts from other devices are then blocked.
For example, this setting can be used to ensure that employees work only at the designated POS terminal or designated driver terminal.
Requirements
The user must not be an administrator, as cookie binding does not apply to administrators.
Setup
The function is a store setting and must be enabled separately for each store.
Procedure for enabling:
- Go to Admin: Store management > Stores > Edit > Settings.
- Navigate to the "Other settings" section.
- Enable the option "Enable cookie binding for employees in the POS".
- Click "Save".

After activation, the process works as follows:
- Cookie binding is enabled for the respective store.
- An employee then logs in at the POS.
- After a successful login, an authentication cookie is set on the device being used.
- This cookie binds the login to the respective device.
- The same employee can then no longer log in from another device. The following message appears: "No stores for this user to select".

Example
- An employee logs in at "POS 1" (POS terminal 1).
- During login, the authentication cookie is stored on "POS 1".
- This links the employee's login to this device.
- The employee cannot use the same login at "POS 2" (another POS terminal).
- If
the browser cookies are deleted on "POS 1", the device binding is
removed. The next login then sets a new cookie again.
Behavior with multiple locations (franchise)
Because this is a store setting, the function can be enabled individually for each location.
A separate cookie is set for each store POS terminal.
Example:
- Store A: Cookie binding enabled = Employees can log in only on the authorized device for this store.
- Store B: Cookie binding not enabled = Employees can continue to log in on different devices as usual.
Important note:
The device binding is based on the stored cookie.
If the browser cache or cookies are cleared, the binding is removed. The next login then sets a new cookie again.
Deleting cookies can be prevented on the POS devices (e.g. via device management or kiosk mode).
Please note
- The setting must be enabled separately for each store.
- The binding is established via a cookie in the browser of the respective device, not permanently via the user account.
- Deleting the browser cookies removes the existing device binding.
- After the cookies are deleted, the device binding can be restored by logging in again.
- The user must not have administrator rights, as cookie binding does not apply to administrators.