The login page, and the one rule about it

After the access queue finishes, the market shows its login. There are two ways in, and there is one rule that catches almost every fake. Both below.

Password login

Username and password, plus a captcha on most logins. This is the path for everyone. If you are not registered yet, the same page has a link to create an account, which is free. After a successful login you choose how long to stay signed in, anywhere from 15 minutes up to 6 hours. Shorter is safer on a machine you share; longer is just more convenient on your own.

PGP login

Instead of typing a password, the market hands you a short text challenge and you sign it with your private PGP key. The signature is your password. This path is for people who keep a key on a hardware token or a USB stick and do not want the same secret in two places. Same rules apply below, word for word.

The one rule.

Your password is only ever typed on a page whose address ends in .onion. A page ending in .com, .org, .net, .xyz, or a bare domain that asks for your Awazon password is not the market, whatever its logo looks like. That single check filters out almost every credential grabber, because almost all of them need a normal browser to exist at all.

What a real login actually looks like

You land on it from the queue, without leaving the .onion. It asks for a username and a password, shows a captcha, and offers the session length choices. Nothing else is required: no phone number, no email verification mid-login, no “confirm your identity” step that redirects you somewhere else. If a login flow starts asking for things the market does not need, stop and look at the address bar.

If you have lost your password

Recovery is handled on the market’s own login page, on the .onion. You do it there, you do it once, and you never do it on a page that reached you through a “password reset notice” email or a message. When in doubt about any reset page, the test is the same: does the address end in .onion?