Amazon Pushing Passkey Verification for Seller Central Sign-In
Amazon is rolling out password‑less passkey login for Seller Central, starting optional in April 2024 and becoming mandatory by January 2025. Sellers can use fingerprint, Face ID or Windows Hello via the FIDO2 standard, with each device requiring its own passkey.
Overview
Amazon is urging every Seller Central user to enable passkey verification, a password‑free login method that relies on device biometrics. The rollout begins now as an optional feature, but Amazon’s history suggests it will soon become mandatory. Sellers who act early will avoid future access disruptions and strengthen protection against account takeovers.
Key Points
- Passwordless login introduced — Sellers can sign in using fingerprint, facial recognition, or a device PIN instead of a traditional password and SMS code.
- Credentials stay on the device — Authentication data is encrypted and stored locally, meaning Amazon’s servers never hold the secret keys.
- Phishing resistance built in — Because passkeys are generated per site and never travel over the network, they cannot be captured by phishing sites or SIM‑swap attacks.
- Broad platform support — The feature works on Chrome, Edge, Safari, Android, iOS, and Windows devices that implement the FIDO2 standard.
- Multi‑device registration required — Each device a seller uses to access Seller Central must have its own passkey, so a laptop and a smartphone need separate setups.
- Industry trend aligns — Google, Apple and Microsoft have already made passkeys the default for their services, and the FIDO Alliance reports a 40 % year‑over‑year increase in passkey deployments across enterprises.
How Passkey Verification Works
- Device enrollment — In Seller Central’s security settings, the seller selects “Add Passkey,” then the browser prompts the device to create a new cryptographic key pair. For example, an iPhone user taps “Create Passkey,” and the device generates a private key stored in the Secure Enclave while the public key is sent to Amazon.
- Biometric binding — The private key is linked to a biometric factor such as Touch ID or Face ID. When the seller later attempts to log in, the device asks for the fingerprint; only a successful biometric match releases the private key to sign the authentication request.
Analysis & Recommendations
Why This Matters
Passkeys eliminate password leaks and SMS‑based SIM‑swap attacks, protecting high‑volume sellers from account takeover. Mandatory enforcement in Jan 2025 means any seller without a registered device will be blocked, risking revenue loss.
Key Takeaways
- Optional rollout begins April 2024; mandatory enforcement starts Jan 2025.
- Passkeys use device‑stored private keys bound to biometrics (Touch ID, Face ID, Windows Hello).
- Each device (desktop, smartphone) must register its own passkey; no shared credentials.
- FIDO2‑compatible browsers (Chrome, Edge, Safari) and OSes (iOS, Android, Windows) are supported.
Recommended Actions
- →Log into Seller Central > Settings > Login Security and click ‘Add Passkey’ on each primary device.
- →Add a recovery passkey on a backup laptop to avoid lockout if a device is lost.
- →Update team access list in Seller Central > User Permissions to confirm each user has registered a passkey.
Comments
Join the discussion
Log in or create an account to share your thoughts on this update.
No comments yet. Be the first to share your thoughts!