Amazon Sign-in
- SellerOS FIDO2 Security Key is a service for Amazon passkey registration and sign-in, including Seller Central sign-in flows that offer a passkey option. SellerOS Remote Assistant provides a software security key in Windows, using the system PIN prompt and a confirmation step. No browser extension is required.
- It is intended for teams using system security key authentication in their Windows store environments. Administrators initialize devices, manage PINs and disable devices. Users initiate a request on Amazon, enter the security key PIN and confirm.
- Web Passkey and FIDO2 are separate services. Web Passkey uses a browser extension and SellerOS console approval; FIDO2 uses the remote assistant, a device driver and Windows security key verification. Use one method per authentication request and disable the Web Passkey extension during FIDO2 authentication to avoid intercepting the same request.
Setup & Initialization
- Install or update SellerOS Remote Assistant from the remote-control page for the device. The current setup workflow targets Windows 10 / 11 x64. Enable and open FIDO2 Security Key in the assistant.
- Open PIN Management from the assistant on that machine. A SellerOS system administrator verifies their own account password and sets the security key PIN, currently 4 to 32 digits. This is neither the Windows sign-in PIN nor the Amazon password.
- Install the device driver through the assistant and approve the required Windows administrator prompt. The assistant attempts to connect once the driver and device configuration are ready; connect the security key from its window if needed. Disabling the feature stops participation in new authentication requests.
- Use Verify PIN in the assistant to check the Windows security key workflow before registering with Amazon. RDP sessions can be affected by WebAuthn redirection and operating-system limitations; verify that the actual session can reach the intended device first.
Registration & Daily Sign-in
- Registration: add a passkey in Amazon account security settings, choose Security Key in the system prompt, enter the configured PIN and approve after checking the website in the assistant. The assistant cannot identify an account that the website has not supplied. Amazon determines whether registration succeeds.
- Sign-in: select the passkey option in a supported Amazon or Seller Central sign-in flow, then use the registered security key to complete PIN verification and confirmation. The same PIN on a new machine does not give it access to credentials on another machine.
PINs, Credentials & Records
- PINs are encrypted in the SellerOS backend. Viewing or changing a PIN requires verification of the current system administrator password and is recorded as an administrative action. PIN management does not mean that website passkey private keys are stored on the backend.
- Current FIDO2 credentials are encrypted under the local Windows user. Keep other Amazon sign-in and recovery methods before reinstalling the system or changing the Windows user. Reconfiguring a PIN on the backend cannot restore the original credentials.
- Device and authentication records follow the user's store access permissions and include the device, website RP ID, available account information, time and processing result. FIDO2 does not supply the full page URL, browser User-Agent or actual operator identity. Generating a credential or signature does not prove that Amazon completed registration or sign-in.
Availability & Limits
- Availability depends on Amazon account eligibility, the sign-in options offered by the site, browser, Windows version and remote session. It is not guaranteed for every Amazon account or marketplace and is not intended to bypass account permissions or platform security checks.
- This is a SellerOS software security key service, not an Amazon product or FIDO-certified hardware. Using the Windows security key prompt does not provide Windows Hello biometrics or Windows lock-screen sign-in. Contact SellerOS support for setup assistance.