Sign-in session
The isp_pay_session cookie holds an opaque session token for portal authentication. The server stores its hash with an eight-hour expiry. The cookie is HttpOnly and SameSite=Lax; production HTTPS enables its Secure flag. Signing out removes the session from the server and expires the browser cookie.
Country examples
The homepage may contact GeoJS to estimate your country from your IP. It caches the detected country for one hour in session storage. A manually selected example country is kept in local storage. Returning to automatic detection clears the manual preference. This affects sample figures, not actual merchant configuration.
What is not stored
The sandbox and credential reveal screens do not intentionally persist raw API keys or passwords in browser storage. A copied key goes to your clipboard; a downloaded credential file is stored by your browser and must be protected by you. Browser extensions and shared devices can still create exposure.
Your choices
Sign out on shared devices and clear site storage if you want to remove local example preferences. Blocking the authentication cookie prevents portal sign-in. No advertising trackers or analytics cookies are intentionally included by this website release.
KEEP EXPLORING