EARLY ACCESS Create your account and prepare your listings. Purchases are not open yet.
← All policies

Account verification and security

Email checks, optional authenticator 2FA, and recovery.

DRAFT · September 10, 2026 · Requires operator details and legal review before public launch.

Sign-in and email checks

Public accounts use a one-time email code to register and sign in. Login codes expire after 10 minutes, work only in the requesting browser, can be used once, and have attempt limits. Sign-in sessions last up to 12 hours. When an authenticator is enabled, an authenticator or unused recovery code is also required to sign in and perform sensitive actions. Staff tools always require authenticator protection. Keep access to your mailbox and recovery codes secure; no password is stored by the marketplace. The private staging site can continue to use ChatGPT sign-in.

Authenticator protection

You can add a time-based authenticator after email verification when the secure server configuration is connected. Once enabled, email verification alone cannot authorize sensitive actions. Time-based codes cannot be reused; save the one-time recovery codes shown at activation. Do not share the setup key or recovery codes.

Session controls

The additional verification uses a server-recorded, expiring browser cookie with HttpOnly and SameSite controls and Secure on HTTPS. Clear verification on all browsers from Security if needed, and also sign out of the primary account. Losing all recovery methods requires the final account-provider recovery process; support must not bypass identity verification.

Preview availability

Real email codes require a connected email provider and verified sender. Authenticator secrets require an encrypted server configuration. The interface reports unavailable configuration and does not claim a code was sent when delivery was not accepted by the provider. These services and production security review are launch prerequisites.

Contact marketplace support →