The account and the login screen
created on the market ยท nothing else knows your passwordAWazon Market entry addresses
awazonip66usn4oq6vn5b3fqjyjjvavzu3ototnjbmi2wg6bocfc7aqdawazonwilo4vky6obkwrkv62vx24tnf5323pts6d7gohdoj4pjt646qdawazonvewzuve3emyxtz2z7ko6bjv6m6qieioi2tuvbgwiomn6vyryydThree entry points to one market, all equivalent. If one does not load, open the next one.
An AWazon Market account exists in exactly one place: on the market, at one of the .onion addresses. The register link sits in the storefront header, next to the login link, and the account is created there, in that session, on that circuit. There is no app store version of the sign-up, no partner portal, no "create your account here" page on any ordinary domain. If a page outside the .onion offers to create the account for you, it is creating it for itself.
What the login screen contains
Three fields, in this order: username, password, and a 2FA code, which appears only if two factor authentication is turned on for the account. Nothing else. No captcha on the login itself, no "remember my device" checkbox with a fine-print surprise, no upsell. The queue and the robot check come before the storefront, not around the login, so by the time the login form is on screen you have already proven to be a person to the market.
Nothing on this page will ever ask you for your password. The only place a password on this market is entered is the login screen of the market itself, inside Tor Browser, on a .onion address.
The password the market cannot send back
The market does not keep a reset channel, and that is deliberate: a password reset email is an email, and an email is a route a copy can follow. The practical consequence is one habit. Write the password down, offline, on paper, at the moment of registration, while it is still fresh. A browser password manager is fine on a personal machine and is a liability on a shared one, because the whole point of the offline note is that it travels nowhere.
Two factor authentication
2FA on the market uses a standard TOTP code from an authenticator app on your phone. At setup the market shows a backup code once. Once, meaning the screen shows it, you write it down, and it is never displayed again. That backup code is what makes a lost phone survivable: without it, a lost phone and a forgotten password are the same event.
Turn 2FA on before the first order, not after. The order is when the account stops being a curiosity and becomes a balance, and the window between "worth stealing" and "protected" is exactly the size of one checkout.
Messages that are not the market
The market talks to you inside the market: order updates, seller messages, ticket replies, all in the account. An email with a link that asks for a password is not one of those. Neither is a message "from support" that arrives in the chat with a fee attached before the fee is explained. The test is always the same: would the real market, the one that just made you wait in a queue, ask for that? If the answer is no, close the tab.
Logging in from a new place
A login from a new device or a new location behaves like any careful account: it works, it may be slower behind the queue, and the 2FA code is required exactly as before. Nothing on the market side "detects a new device" with an alarm and a fee; that is a copy's idea of security. If the login works without drama, it worked.