Use a public destination, not account access
A seller can use a public handle, page, or post URL to identify where a package should go. That is different from asking for credentials to sign in as you.
Keep control of your password, recovery email, and two-factor authentication.
Treat login requests as a stop sign
Do not share passwords, one-time verification codes, backup codes, browser sessions, or administrator permissions to receive a package.
If a request changes after you pay, pause the process and use documented support or refund policies rather than weakening account security.
Double-check the destination
Make sure the handle, page, or post is public, live, and spelled exactly as intended. A typo can send activity to the wrong account.
Save your order reference and review connected apps and administrator roles routinely.