Amazon says it began expanding passkey support for Seller Central in July 2026, and its announcement says some accounts may be required to use passkeys later. Amazon’s Seller Central announcement does not say every account is already required to use one.

Decision: Keep each passkey with the person who signs in, on a device or password manager that person controls. Don’t save a shared team credential on a shared remote Mac.

Fastest safe path: Set up and test the passkey from the user’s own controlled device first. Use the remote Mac for Seller Central work, and complete cross-device verification only if the live sign-in page offers it.

For cross-border sellers: you need Seller Central on a remote Mac and want to know where the passkey belongs. For account holders: you need separate access for team members and a usable recovery route. For team administrators: you need to check remote access, permissions, and credential handoff when roles change.

Last updated September 24, 2026. Checked against Amazon’s passkey and sub-user announcements, current Seller Central account instructions, and Apple’s passkey documentation.

Amazon Seller Central passkeys 2026: establish credential ownership

Treat a passkey, an Amazon user, a macOS user, and a remote connection as separate things. A person may use a remote Mac without owning the Amazon account credential stored on a different device. Keeping those boundaries clear makes it easier to tell whether a problem is a sign-in issue, a team-permission issue, or a remote-access issue.

Before changing settings, write down who will sign in and what access they need. The account holder should use their own sign-in. A team member should use an individual Amazon user identity where Seller Central supports it, rather than borrowing the account holder’s credentials. Amazon’s sub-user announcement and user-permission guidance are the right references for checking how access is assigned.

The practical boundary is simple:

  • Amazon user: the identity and platform permissions used to sign in.
  • Passkey: a sign-in credential registered for a user and held by that user’s chosen device or credential service.
  • macOS user: the local account used to access the remote Mac. It does not establish Amazon permissions.
  • Remote connection: the way you reach the Mac. It does not replace Amazon verification or account recovery.
A shared host creates hidden costs if you treat it as the credential owner. Staff turnover can leave credentials behind; a remote session may be available to more than one operator; and a Mac administrator’s control of the host does not make that administrator the right holder of each Amazon credential. Keep the account relationship and the workstation relationship documented separately.

**Keep the boundary:** A remote Mac is a work environment, not a shared vault for Amazon sign-in credentials. Store the passkey with its actual user.

Step 1: Check the account and recovery route

Start in the Amazon account that will be used for day-to-day work. Open the sign-in settings available to that account, and follow the instructions shown on the current Seller Central page. The account may show a passkey option, another verification method, or a notice about a future requirement. Don’t infer that a feature is enabled for all accounts from Amazon’s announcement alone.

Use this sequence before registering anything:

  1. Confirm the account holder or individual user who will perform the work. Don’t begin from a team member’s browser session if you cannot verify whose Amazon identity is active.
  2. Open the current Login & Settings area if it appears in that account’s Seller Central instructions. Follow the wording and route shown there; don’t rely on a saved screenshot from another account.
  3. Note the passkey option and any other verification or recovery methods the page offers. Keep the current recovery route available while you test the new sign-in.
  4. Confirm who controls the device or password manager where the passkey will be saved. If it is a managed device, check who can administer or recover that credential.
  5. Capture the setup screen only if you need an operations record. Hide the account name, email address, store identifiers, profile details, and any recovery information before sharing the image.
The setup page is the source of truth for your account’s available options. A help post or another seller’s account view can help you understand the feature, but it cannot establish what your own account currently supports.

Step 2: Register and test the passkey on its owner’s device

Register the credential from a device or password manager the actual user controls. Apple describes passkeys as credentials that can be available across a user’s devices through supported services; its iCloud Keychain security overview explains the protections for that Apple service. That is not a reason to put every team member’s passkey on a shared Mac.

Follow the current account page rather than assuming that every Seller Central account has identical screens:

  1. Sign in as the intended user and open the passkey setup option shown in the account’s Login & Settings instructions.
  2. Read the page’s description of where the credential will be saved. Select only a device or credential service the user can access and manage.
  3. Complete the registration prompt. If the page presents alternative verification steps, follow those steps as directed.
  4. Record the credential’s custodian and its storage location in your private operations record. Do not record the passkey itself, its recovery secret, or a screenshot that exposes sensitive information.
  5. Sign out, start a fresh sign-in, and test the passkey from the user’s controlled device.
  6. Check that the other verification or recovery methods you intend to retain are still available. Do not assume the passkey replaces every code, challenge, or account-recovery step.
A successful setup prompt is not enough to prove that you can sign in later. The fresh sign-in checks whether the user can actually invoke the credential after leaving the setup session.

Step 3: Sign in from the remote Mac without moving the credential

Open Seller Central on the remote Mac and enter the intended Amazon user’s sign-in details. Read the page before choosing a verification path. If it offers a cross-device passkey option, follow the prompt and complete the approval on the credential owner’s device.

Apple documents using a passkey stored on one device with another device in supported situations. Its cross-device passkey instructions and nearby-device sign-in guide describe Apple’s general flow. They do not confirm that Amazon offers the same choice for every account, browser, or sign-in attempt. The FIDO Alliance’s passkey overview explains the broader passkey model, but the Amazon page still determines the available path.

Use this remote sign-in sequence:

  1. Confirm that the Amazon user shown in the sign-in flow is the person whose passkey you tested.
  2. Look for a cross-device or nearby-device option only if the page offers one. If a QR code or another handoff prompt appears, follow the instructions shown on both devices.
  3. Approve the request on the credential owner’s device. Don’t send a one-time prompt or account challenge to another team member for convenience.
  4. Return to the remote Mac and verify that Seller Central shows the intended account and store context.
  5. Record whether the route worked and which alternatives the page offered. Don’t write down secret values or sensitive recovery details.
  6. If the cross-device choice is missing, stop and use the verification route shown by Amazon. Don’t assume that changing the Mac, browser, or network will add an option that the page does not provide.

**Don’t force a match:** A passkey that works on the owner’s device may still not be offered as a cross-device route on a particular Seller Central page. Follow the visible options and preserve the account’s recovery path.

FAQ: setup, device choice, and fallback

Where should I begin when setting up a Seller Central passkey?

Sign in as the account holder or the individual who will use the account, then check the current Login & Settings page for its passkey instructions. Register the credential on a device or password manager that person controls. Test a fresh sign-in before relying on it, and keep any recovery methods still offered by Amazon.

Should I save the passkey on the remote Mac?

Usually not if the Mac is shared or administered as a team host. Keep the credential on the user’s own controlled device or password manager, and use the remote Mac as the work session. A cross-device prompt may be available, but you should act only on the live sign-in page’s options.

Can an Amazon sub-user register an individual passkey?

Set up each team member with an individual Amazon user identity, then have that person register credentials for their own sign-in according to the current Seller Central instructions. Don’t share the account holder’s passkey. Review the platform’s current sub-user guidance before changing access, because the account page determines the options available to your team.

Can a phone passkey be used for sign-in on a remote Mac?

It may be possible if the Seller Central page offers a cross-device option and the phone or credential service supports the prompted flow. Apple’s cross-device documentation explains a general mechanism, not Amazon’s support for every account or browser. If no such option appears, use another verification or recovery choice shown by Amazon.

What should I check first after a failed passkey sign-in?

Capture the exact page message, confirm which Amazon user is active, and check whether that user can access the credential on their own device or password manager. Then review the other sign-in and recovery options on the page. Avoid repeatedly deleting credentials or switching remote hosts before you know what the error indicates.

Step 4: Give each Amazon sub-user a separate identity

A team needs individual platform identities so permissions and credential ownership can be reviewed when work changes hands. Amazon’s sub-user instructions should guide how you invite and configure each person; don’t assume that the account holder’s passkey can be delegated or that every user has identical settings.

For each person who needs access:

  1. Have the account holder add or review that person through the current Seller Central user-management flow.
  2. Assign only the access needed for that person’s responsibilities, following Amazon’s current permission options.
  3. Ask the individual to sign in under their own identity and check the passkey options shown in their account.
  4. Have that person register and test their own credential. Keep credentials separate even if several people use the same remote Mac for work.
  5. Record the user’s role, access owner, and credential custodian without storing the credential itself.
  6. When a person changes role or leaves, remove or adjust their Seller Central access through the platform’s supported process. Review who controls their credential and preserve a dated handoff record.
If a team member cannot see a passkey setting, don’t resolve that by sharing the account holder’s sign-in. Check the current sub-user instructions and the permissions assigned to that user, then follow the support path Amazon provides.

Step 5: Record acceptance and recover cleanly

A useful handoff record proves that the correct person can perform the work without exposing secrets. Keep the record in an approved internal location with limited access. It should identify the Amazon user, the person responsible for the credential, whether the remote sign-in was tested, and which recovery route the account page still offers.

Use a compact record such as this:

  • Amazon user or team role, without exposing unnecessary account details.
  • Credential custodian and the type of device or password manager used.
  • Remote Mac sign-in result: successful, unavailable option, or blocked.
  • The verification choices actually shown by Seller Central.
  • The person who confirmed the access and the date of that check.
  • Open issue and next action, such as following Amazon’s account recovery process.
When sign-in fails, work from the exact prompt instead of repeating setup blindly:
  1. Save a sanitized screenshot or transcribe the error text. Remove account identifiers and personal data.
  2. Confirm the correct Seller Central user is active. A credential registered for one person should not be treated as the other person’s.
  3. Check whether the credential is accessible to its owner on the device or service where it was registered.
  4. Return to the sign-in page and inspect the other verification or recovery choices Amazon provides.
  5. If the account reports a security hold, unusual activity, or an account-specific problem, follow Amazon’s official instructions and escalate through its supported account process.
  6. Don’t delete and recreate credentials, repeatedly retry a failing flow, or assume a different remote Mac will fix an account-side issue.
The first troubleshooting split is between **credential unavailable** and **Amazon account or verification issue**. The first calls for checking the owner’s device or credential service; the second calls for the platform’s displayed recovery and support process. Treat community reports as individual experiences, not proof that a symptom has one universal cause.

Compare credential storage choices before handoff

Use this table to choose where the passkey belongs. The fit ratings are operational guidance, not a claim that Amazon supports a particular credential provider in every account.

<
OptionCredential ownerTeam handoff riskFit for a shared remote Mac
User-controlled phone or personal deviceIndividual userLower if the device stays with its owner and recovery is maintained**Preferred** when Seller Central offers a compatible cross-device prompt
User-controlled password managerIndividual user or approved custodianDepends on the service’s access and recovery controls**Conditional**; confirm the user can invoke it from the sign-in flow
Shared remote Mac loginUnclear if multiple people can access the hostHigher; host access and credential ownership can become mixed**Avoid** for team-shared credentials
Account holder’s credential used by multiple staffAccount holder, but used by othersHigh; access changes are hard to track cleanly**Avoid**; use individual platform identities where supported
**Decision rule:** If one person owns the Amazon identity, that person should control its credential. If the team needs separate access, configure separate users first. If the page does not offer cross-device authentication, use the page’s supported alternative instead of relocating a shared passkey to the remote host.

Compare the remote Mac workflow with local sign-in

A remote Mac can provide a macOS work environment for Seller Central tasks, but it does not remove account checks or make passkey approval automatic. Compare the workflows before changing your team’s setup.

<
WorkflowWhat it solvesMain limitationOperational fit
Sign in from a user’s local deviceDirect access to the user’s own credential and sign-in pageDoes not provide a separate remote macOS work session**Good** when the task does not need remote Mac access
Use a remote Mac and approve on the user’s deviceSeparates the work session from credential custodyCross-device choice depends on what the live page offers**Good conditionally** for remote operations
Store a team credential on the remote MacAvoids switching devices during sign-inBlurs credential ownership and increases handoff exposure**Poor** for shared team work
If your task requires macOS, first decide whether the remote host is a dedicated user environment or a shared team resource. Check the [available MACGPU remote Mac options](https://macgpu.com/en/index.html) for the delivery and connection details relevant to your workflow. If you need to compare a US-based location, review the information on the [Silicon Valley Mac option](https://macgpu.com/en/m4-order-silicon-valley.html); do not treat the host location as a substitute for Amazon’s verification or recovery process.

The alternative to a remote Mac is to use a local Mac or another environment you already control. That can avoid remote-session handoff, but it may leave you without a separate always-available work host; a shared office device can also create user-separation and credential-custody problems. A remote Mac introduces its own dependencies, including a working remote connection and a clear rule about who can access the host. Choose based on the task and the people who need access, not on an assumption that any environment guarantees sign-in.

If you need macOS for recurring Seller Central operations, MACGPU may be worth considering as a separate work environment, provided you first confirm the account permissions, credential owner, and recovery options. Keep the passkey with its user, and review the service’s delivery and connection details before deciding whether a remote Mac fits your handoff model.