Amazon says it began expanding passkey support for Seller Central in July 2026, and its announcement says some accounts may be required to use passkeys later. Amazon’s Seller Central announcement does not say every account is already required to use one.
Decision: Keep each passkey with the person who signs in, on a device or password manager that person controls. Don’t save a shared team credential on a shared remote Mac.
Fastest safe path: Set up and test the passkey from the user’s own controlled device first. Use the remote Mac for Seller Central work, and complete cross-device verification only if the live sign-in page offers it.
For cross-border sellers: you need Seller Central on a remote Mac and want to know where the passkey belongs. For account holders: you need separate access for team members and a usable recovery route. For team administrators: you need to check remote access, permissions, and credential handoff when roles change.
Last updated September 24, 2026. Checked against Amazon’s passkey and sub-user announcements, current Seller Central account instructions, and Apple’s passkey documentation.
Amazon Seller Central passkeys 2026: establish credential ownership
Treat a passkey, an Amazon user, a macOS user, and a remote connection as separate things. A person may use a remote Mac without owning the Amazon account credential stored on a different device. Keeping those boundaries clear makes it easier to tell whether a problem is a sign-in issue, a team-permission issue, or a remote-access issue.
Before changing settings, write down who will sign in and what access they need. The account holder should use their own sign-in. A team member should use an individual Amazon user identity where Seller Central supports it, rather than borrowing the account holder’s credentials. Amazon’s sub-user announcement and user-permission guidance are the right references for checking how access is assigned.
The practical boundary is simple:
- Amazon user: the identity and platform permissions used to sign in.
- Passkey: a sign-in credential registered for a user and held by that user’s chosen device or credential service.
- macOS user: the local account used to access the remote Mac. It does not establish Amazon permissions.
- Remote connection: the way you reach the Mac. It does not replace Amazon verification or account recovery.
**Keep the boundary:** A remote Mac is a work environment, not a shared vault for Amazon sign-in credentials. Store the passkey with its actual user.
Step 1: Check the account and recovery route
Start in the Amazon account that will be used for day-to-day work. Open the sign-in settings available to that account, and follow the instructions shown on the current Seller Central page. The account may show a passkey option, another verification method, or a notice about a future requirement. Don’t infer that a feature is enabled for all accounts from Amazon’s announcement alone.
Use this sequence before registering anything:
- Confirm the account holder or individual user who will perform the work. Don’t begin from a team member’s browser session if you cannot verify whose Amazon identity is active.
- Open the current Login & Settings area if it appears in that account’s Seller Central instructions. Follow the wording and route shown there; don’t rely on a saved screenshot from another account.
- Note the passkey option and any other verification or recovery methods the page offers. Keep the current recovery route available while you test the new sign-in.
- Confirm who controls the device or password manager where the passkey will be saved. If it is a managed device, check who can administer or recover that credential.
- Capture the setup screen only if you need an operations record. Hide the account name, email address, store identifiers, profile details, and any recovery information before sharing the image.
Step 2: Register and test the passkey on its owner’s device
Register the credential from a device or password manager the actual user controls. Apple describes passkeys as credentials that can be available across a user’s devices through supported services; its iCloud Keychain security overview explains the protections for that Apple service. That is not a reason to put every team member’s passkey on a shared Mac.
Follow the current account page rather than assuming that every Seller Central account has identical screens:
- Sign in as the intended user and open the passkey setup option shown in the account’s Login & Settings instructions.
- Read the page’s description of where the credential will be saved. Select only a device or credential service the user can access and manage.
- Complete the registration prompt. If the page presents alternative verification steps, follow those steps as directed.
- Record the credential’s custodian and its storage location in your private operations record. Do not record the passkey itself, its recovery secret, or a screenshot that exposes sensitive information.
- Sign out, start a fresh sign-in, and test the passkey from the user’s controlled device.
- Check that the other verification or recovery methods you intend to retain are still available. Do not assume the passkey replaces every code, challenge, or account-recovery step.
Step 3: Sign in from the remote Mac without moving the credential
Open Seller Central on the remote Mac and enter the intended Amazon user’s sign-in details. Read the page before choosing a verification path. If it offers a cross-device passkey option, follow the prompt and complete the approval on the credential owner’s device.
Apple documents using a passkey stored on one device with another device in supported situations. Its cross-device passkey instructions and nearby-device sign-in guide describe Apple’s general flow. They do not confirm that Amazon offers the same choice for every account, browser, or sign-in attempt. The FIDO Alliance’s passkey overview explains the broader passkey model, but the Amazon page still determines the available path.
Use this remote sign-in sequence:
- Confirm that the Amazon user shown in the sign-in flow is the person whose passkey you tested.
- Look for a cross-device or nearby-device option only if the page offers one. If a QR code or another handoff prompt appears, follow the instructions shown on both devices.
- Approve the request on the credential owner’s device. Don’t send a one-time prompt or account challenge to another team member for convenience.
- Return to the remote Mac and verify that Seller Central shows the intended account and store context.
- Record whether the route worked and which alternatives the page offered. Don’t write down secret values or sensitive recovery details.
- If the cross-device choice is missing, stop and use the verification route shown by Amazon. Don’t assume that changing the Mac, browser, or network will add an option that the page does not provide.
**Don’t force a match:** A passkey that works on the owner’s device may still not be offered as a cross-device route on a particular Seller Central page. Follow the visible options and preserve the account’s recovery path.
FAQ: setup, device choice, and fallback
Where should I begin when setting up a Seller Central passkey?
Sign in as the account holder or the individual who will use the account, then check the current Login & Settings page for its passkey instructions. Register the credential on a device or password manager that person controls. Test a fresh sign-in before relying on it, and keep any recovery methods still offered by Amazon.
Should I save the passkey on the remote Mac?
Usually not if the Mac is shared or administered as a team host. Keep the credential on the user’s own controlled device or password manager, and use the remote Mac as the work session. A cross-device prompt may be available, but you should act only on the live sign-in page’s options.
Can an Amazon sub-user register an individual passkey?
Set up each team member with an individual Amazon user identity, then have that person register credentials for their own sign-in according to the current Seller Central instructions. Don’t share the account holder’s passkey. Review the platform’s current sub-user guidance before changing access, because the account page determines the options available to your team.
Can a phone passkey be used for sign-in on a remote Mac?
It may be possible if the Seller Central page offers a cross-device option and the phone or credential service supports the prompted flow. Apple’s cross-device documentation explains a general mechanism, not Amazon’s support for every account or browser. If no such option appears, use another verification or recovery choice shown by Amazon.
What should I check first after a failed passkey sign-in?
Capture the exact page message, confirm which Amazon user is active, and check whether that user can access the credential on their own device or password manager. Then review the other sign-in and recovery options on the page. Avoid repeatedly deleting credentials or switching remote hosts before you know what the error indicates.
Step 4: Give each Amazon sub-user a separate identity
A team needs individual platform identities so permissions and credential ownership can be reviewed when work changes hands. Amazon’s sub-user instructions should guide how you invite and configure each person; don’t assume that the account holder’s passkey can be delegated or that every user has identical settings.
For each person who needs access:
- Have the account holder add or review that person through the current Seller Central user-management flow.
- Assign only the access needed for that person’s responsibilities, following Amazon’s current permission options.
- Ask the individual to sign in under their own identity and check the passkey options shown in their account.
- Have that person register and test their own credential. Keep credentials separate even if several people use the same remote Mac for work.
- Record the user’s role, access owner, and credential custodian without storing the credential itself.
- When a person changes role or leaves, remove or adjust their Seller Central access through the platform’s supported process. Review who controls their credential and preserve a dated handoff record.
Step 5: Record acceptance and recover cleanly
A useful handoff record proves that the correct person can perform the work without exposing secrets. Keep the record in an approved internal location with limited access. It should identify the Amazon user, the person responsible for the credential, whether the remote sign-in was tested, and which recovery route the account page still offers.
Use a compact record such as this:
- Amazon user or team role, without exposing unnecessary account details.
- Credential custodian and the type of device or password manager used.
- Remote Mac sign-in result: successful, unavailable option, or blocked.
- The verification choices actually shown by Seller Central.
- The person who confirmed the access and the date of that check.
- Open issue and next action, such as following Amazon’s account recovery process.
- Save a sanitized screenshot or transcribe the error text. Remove account identifiers and personal data.
- Confirm the correct Seller Central user is active. A credential registered for one person should not be treated as the other person’s.
- Check whether the credential is accessible to its owner on the device or service where it was registered.
- Return to the sign-in page and inspect the other verification or recovery choices Amazon provides.
- If the account reports a security hold, unusual activity, or an account-specific problem, follow Amazon’s official instructions and escalate through its supported account process.
- Don’t delete and recreate credentials, repeatedly retry a failing flow, or assume a different remote Mac will fix an account-side issue.
Compare credential storage choices before handoff
Use this table to choose where the passkey belongs. The fit ratings are operational guidance, not a claim that Amazon supports a particular credential provider in every account.
| Option | Credential owner | Team handoff risk | Fit for a shared remote Mac |
|---|---|---|---|
| User-controlled phone or personal device | Individual user | Lower if the device stays with its owner and recovery is maintained | **Preferred** when Seller Central offers a compatible cross-device prompt |
| User-controlled password manager | Individual user or approved custodian | Depends on the service’s access and recovery controls | **Conditional**; confirm the user can invoke it from the sign-in flow |
| Shared remote Mac login | Unclear if multiple people can access the host | Higher; host access and credential ownership can become mixed | **Avoid** for team-shared credentials |
| Account holder’s credential used by multiple staff | Account holder, but used by others | High; access changes are hard to track cleanly | **Avoid**; use individual platform identities where supported |
Compare the remote Mac workflow with local sign-in
A remote Mac can provide a macOS work environment for Seller Central tasks, but it does not remove account checks or make passkey approval automatic. Compare the workflows before changing your team’s setup.
| Workflow | What it solves | Main limitation | Operational fit |
|---|---|---|---|
| Sign in from a user’s local device | Direct access to the user’s own credential and sign-in page | Does not provide a separate remote macOS work session | **Good** when the task does not need remote Mac access |
| Use a remote Mac and approve on the user’s device | Separates the work session from credential custody | Cross-device choice depends on what the live page offers | **Good conditionally** for remote operations |
| Store a team credential on the remote Mac | Avoids switching devices during sign-in | Blurs credential ownership and increases handoff exposure | **Poor** for shared team work |
The alternative to a remote Mac is to use a local Mac or another environment you already control. That can avoid remote-session handoff, but it may leave you without a separate always-available work host; a shared office device can also create user-separation and credential-custody problems. A remote Mac introduces its own dependencies, including a working remote connection and a clear rule about who can access the host. Choose based on the task and the people who need access, not on an assumption that any environment guarantees sign-in.
If you need macOS for recurring Seller Central operations, MACGPU may be worth considering as a separate work environment, provided you first confirm the account permissions, credential owner, and recovery options. Keep the passkey with its user, and review the service’s delivery and connection details before deciding whether a remote Mac fits your handoff model.