Amazon is forcing a shift to passkeys and it changes everything
This isn't just another minor security update; it is a fundamental change in how we handle authentication. Passkeys use your device's local hardware—think FaceID, fingerprint scanners, or even just your system PIN—to verify your identity. Because the "secret" stays on your device and isn't sent over the internet like a password, it makes phishing almost impossible. You can't accidentally type a passkey into a fake website.
The deployment process for individual users
If you are managing a personal or standard business account, the setup is actually quite fast. It’s a quick deployment that takes about two minutes. Here is the workflow:
1. Log into your Amazon Business or personal account.
2. Navigate to the Login & Security section.
3. Find the Passkeys option and click Set up.
4. Follow the system prompts on your phone or computer to register your biometric or PIN.
A major tip here: Amazon specifically recommends setting this up on at least two different devices. Since passkeys sync through Apple ID, Google accounts, or Microsoft accounts, you aren't stuck if you lose your phone, but having a secondary registered device (like a tablet or laptop) is a much safer failsafe.
Managing shared accounts and secondary users
This is where it gets a bit more complex, especially for those running Amazon Business accounts with multiple team members. You can no longer just "share" a single set of login credentials. If multiple people need access, you have to move to a structured user permission model.
If you try to share one login, you'll run into a wall because each person needs their own unique passkey tied to their own device. To do this correctly, you need to follow this specific configuration for adding secondary users:
1. Go to Settings and select User Permissions.
2. Select the specific account for the new user.
3. Enter the user’s contact information and select Send invitation.
(Note: The secondary user MUST use a brand-new email address that has
never been associated with any Amazon account before).
4. Repeat for all necessary team members.
5. Instruct the new users to follow their unique email invitation.Only once these users are officially registered as secondary users can they create their own passkey to log in independently. This is a much more robust AI-era security workflow, as it provides a clear audit trail and eliminates the massive vulnerability of shared passwords.
If you run into technical friction during this transition, Amazon's support claims a response time of under 24 hours. If your hardware simply doesn't support passkeys, you'll need to reach out to Customer Service immediately to prevent being locked out once the mandatory phase hits your account.