Setup
- SellerOS Passkey is an administrator preview for approving remote-browser authentication. It requires Windows 10/11, .NET Framework 4.8, Chrome 115+ or a compatible Edge release, a Windows companion and an authorized SellerOS administrator account. Installing the extension does not grant an account or administrative access.
- The developer preview is available to authorized administrators from the console. Store distribution is not yet available. The store companion must be built for the extension ID assigned by that store. Do not install untrusted executables or extensions.
- Read the disclosure and explicitly enable the extension. An administrator completes a one-time connection check to associate, but not approve, the device. Then register or sign in directly on the foreground Amazon page without arming a request or keeping setup open. The web controller prompts for the administrator password; the first confirmation also approves the device. Each request waits up to 60 seconds.
- Keep the requesting website in the foreground and approve from the operator computer. Each Amazon request requires fresh verification of the SellerOS administrator password on the portal, not the Amazon password or Windows PIN.
Privacy Policy
- This policy covers the SellerOS Passkey extension, Windows companion and authentication backend. Updated: 2026-09-30. Service operator: CWind Network Technology Co., Ltd.. Contact: support@c2345.com.
- When enabled, the extension reads the active tab URL on allowed Amazon domains to decide locally whether to receive registration and sign-in requests; it does not retain that URL as browsing history. WebAuthn data includes origins/RPs, challenges, website account identifiers, credential IDs, public keys and signed responses. The companion supplies a machine label, public device identity and device-proof signatures, sends signed automatic requests over HTTPS to us.c2345.com, and relays approval notifications through the clipboard gateway to the web console.
- Website passkey private keys are generated and encrypted on the backend and are not sent to the remote browser or companion. The companion stores a separate device identity key protected by Windows DPAPI for the current user.
- Approval logs include SellerOS users, devices, website account identifiers, credential IDs, request and decision times, outcomes, and both parties’ IP/User-Agent as observed by SellerOS. These are not necessarily the IP addresses seen by the target website. User-Agent is client-supplied; account identifiers are not automatically seller/store IDs.
- Extension storage contains only enablement, disclosure revision and consent time. The extension does not read passwords, cookies, general page content or browser history and contains no ad trackers or third-party analytics SDKs. SellerOS passwords are verified separately by the portal. Normal same-origin session cookies accompany HTTPS requests; the extension does not enumerate or export them.
- Compatibility diagnostics retain only redacted requirements, not account names, challenges or credential IDs. The browser-wide proxy may receive unrelated authentication requests; out-of-scope requests are rejected locally without forwarding their raw contents to the backend.
Use, Sharing & Retention
- Data is used only for requested authentication, device authorization, security auditing, recovery and necessary troubleshooting. It is not sold or used for advertising, credit/lending decisions, unrelated profiling or collection of merchant operating data.
- Necessary public keys, credential IDs and signed responses are returned to the requesting website, never SellerOS passwords or private keys. Authorized account administrators and service operators access necessary data for authorization, support or legal obligations; data is not disclosed to data brokers.
- Full requests are short-lived records: subsequent requests clean entries expired for over one hour; immediate idle-time deletion is not promised. Credentials are retained for recovery and approval logs are stored separately. This administrator preview does not yet apply a universal automatic deletion schedule; deletion requests require verified manual handling.
- SellerOS Passkey’s use and transfer of information received from Chrome or Edge APIs adheres to the applicable store User Data Policies, including Limited Use requirements. Executable scripts are packaged with the extension; backend responses are authentication data, not remotely hosted code.
Disable & Delete
- Stop cancels the current request; Disable keeps automatic reception off. Leaving an allowed Amazon page releases automatic interception. Removing the extension does not delete device identities, backend credentials or website sessions. The console can revoke devices or disable individual credentials. Amazon does not notify this system when a binding is deleted. Retained records do not prove website acceptance, and unassigned credentials or credentials assigned to another machine are excluded from automatic sign-in.
- For deletion, email support@c2345.com with “SellerOS Passkey data deletion”, your SellerOS username and requested scope. Do not send passwords, private keys or credential files. We verify identity and organizational authority before processing and explain any legally/security-required minimum audit retention and backup handling.
- Deleting credentials can prevent account access. Keep independent recovery methods and remove the corresponding passkey on the target website. Reinstalled systems create a new device identity and require new administrator approval.
Limits
- This is a software authenticator, not an Amazon product or FIDO-certified hardware. It does not impersonate Windows Hello or biometrics and does not provide Windows sign-in or native CTAP2 access for arbitrary applications.
- Supported sites, algorithms and authentication options are limited to those in the console. Unrelated sign-ins can be cancelled while the proxy is active. A signed response does not prove website acceptance or guarantee future compatibility.