EspressoSecurity

Shop WiFi only

Staff clock in on the shop's own WiFi, or they don't clock in at all. It's an IP restriction: DailyBrew looks at the network a check-in came from, so nobody punches in from the bus.

Why this exists

Without an IP restriction, anyone holding your check-in code can clock in from anywhere.

At home, on the bus, at their other job. Pass the code to a colleague and that colleague can clock in without ever coming through the door — and you'd only find out by standing at the door yourself.

How it works

Your shop's network has one address

Every internet connection has a public address handed out by your provider. When staff are on the shop WiFi, their check-in arrives from that address. DailyBrew sees it every single time.

You say which networks count

In your shop settings you list the addresses you trust — the field is called "Your shop's networks". A check-in from anywhere else is turned away with a plain message.

Staff notice nothing

They scan the same QR code they always scan. On the right network it just works. On the wrong one, they're told check-in only works on the shop's WiFi.

What you get

No clocking in from the sofa

Home, the car park, the café down the road — none of them work. They have to be on a network you approved.

As many networks as you need

Main WiFi and a backup line? Add both. WiFi, ethernet, a phone hotspot — list as many as you like, one per line.

It won't lock you out

Turn it on, forget to add an address, and DailyBrew lets everyone in as normal. Nobody gets stranded at the door by a half-finished setting.

Works with whatever you have

Fixed address, changing address, VPN — if the check-in arrives from an address on your list, it counts. Any provider, any setup.

Setting it up

Under a minute. Do it at the shop, on the WiFi you want to tie check-ins to.

1

Open Shop settings

From Today, click "Shop settings" in the menu and scroll to "Shop WiFi only".

2

Turn on Shop WiFi only

Flip "Only from the shop WiFi". On the free plan you'll be asked to move to Espresso first.

3

Add the shop's network

Click "+ Use the network I'm on" and DailyBrew fills in the address it sees. You can also type addresses yourself, one per line, if you have more than one.

4

Save

That's it. From now on every check-in is matched against your list, and anyone on another network gets a message telling them why.

Common questions

What if the shop's address changes?

Some providers hand out an address that moves now and then. When it does, your staff are turned away until you update it — go to shop settings, click "+ Use the network I'm on" again, and save. If it moves often, ask your provider for a fixed address, or use Near the shop only instead.

Can I allow more than one network?

Yes, as many as you like — one per line. Handy if you have a main WiFi, a backup line, a manager's hotspot, or more than one place under the same shop.

What does someone see when they're turned away?

A warm amber note saying check-in only works on the shop's network. No codes, nothing cryptic — just what to do about it.

Can I use this with Near the shop only and One phone per person?

Absolutely. IP restriction, geofencing and device verification each work on their own, so switch on as many as you want. A check-in has to pass every one you've turned on.

What if I turn it on and add nothing?

DailyBrew reads an empty list as a setting you haven't finished, and lets everyone check in. It's a safety net — you can't lock out the whole team by accident.

Comes with Espresso

Shop WiFi only comes with Espresso ($19.99/month or $199/year) — an IP restriction, plus device verification, geofencing, leave management, manager roles, and more.

Ready to tie check-ins to your WiFi?

Start free. Move up to Espresso when you're ready.