About this tool
Weighted 15-step checklist for Amazon two-step verification, backup methods, device deregistration, saved cards and voice-purchase locks.
This guide is a weighted, 15-control checklist for an Amazon account: two-step verification with an authenticator app, the backup method Amazon requires, passkeys, device deregistration, saved cards, gift-card balance and Alexa voice purchasing. Amazon accounts are attacked for what they can spend rather than what they contain, so payment and ordering controls are scored alongside the sign-in ones. Four controls are marked critical and the score is held at 69% until all four are complete.
Open Amazon Account 2FA Guide on AltFTool — it loads instantly in your browser.
Add your input to the workspace.
Adjust the options until the result looks right.
Copy or download the output and put it to work.
Stored cards, gift-card balance and one-click ordering are scored, not just the login, because that is what a takeover spends.
Amazon requires a backup verification method, and the checklist insists it lives on different hardware from your authenticator app.
The page runs locally, never asks for your Amazon sign-in, and stores no order or payment information.
Go to Your Account > Login & Security > Two-Step Verification (2SV) Settings and choose Get Started. Pick Authenticator App and scan the QR code with any TOTP app rather than choosing Phone Number, then add the backup method Amazon asks for before finishing.
Yes. Amazon will not complete two-step verification setup without a backup method, normally a phone number that can receive a code by SMS or voice call. Use a number on a different handset from your authenticator app so a single lost phone does not remove both routes in.
Change the password, then use the Secure Your Account option under Login & Security to sign out existing sessions, and check Your Addresses and Your Payments for entries you did not add. Report the order through Amazon's own help pages, and never call a phone number given in the suspicious email.
It is safe on a device only you use and unsafe anywhere else, because it stops that browser asking for the second factor at all. Leave it unticked on work, hotel, library and shared family computers, and clear trusted browsers if one of those machines changes hands.