---
url: 'https://www.corbado.com/blog/amazon-passkeys-launch'
title: 'Amazon Passkeys: Response to Consumer Demand with Poor Implementation'
description: 'Amazon introduces passkeys, signaling a shift in e-commerce authentication. While the move is great in general, its implementation can be improved.'
lang: 'en'
author: 'Vincent Delitz'
date: '2023-10-16T00:00:00.000Z'
lastModified: '2026-04-17T06:00:10.093Z'
keywords: 'amazon passkeys'
category: 'Passkeys Reviews'
---

# Amazon Passkeys: Response to Consumer Demand with Poor Implementation

Amazon, the [e-commerce](https://www.corbado.com/passkeys-for-e-commerce) behemoth, has recently and silently
joined the passkey bandwagon. Recognizing the increasing demand by consumers to enhance
security and in particular user convenience, Amazon rolls out passkeys widely across most
devices and browsers. This underlines Amazons commitment to bend to consumer demand. This
move follows the trend among tech giants, with Apple, Google, and others like
[TikTok](https://www.corbado.com/blog/tiktok-passkeys), [OnlyFans](https://www.corbado.com/blog/onlyfans-passkeys) and
[Uber](https://www.corbado.com/blog/uber-passkeys) leading the passkeys wave, while Amazon rather late joins the
party.

![Amazon Passkey Sign in](https://www.corbado.com/website-assets/652dad80bdd8b74dadbd9074_amazon_passkeys_sign_in_8a63e626c8.png)

Read also our in-depth analysis on [e-commerce](https://www.corbado.com/passkeys-for-e-commerce) funnels at
Amazon.

## Key Facts

- **Relying Party ID fragmentation** forces Amazon users to register separate passkeys per
  regional domain (e.g., amazon.com vs. amazon.de), creating a disjointed experience for
  international shoppers on the same device.
- **Conditional UI (Passkey Autofill)** is absent from Amazon's implementation, a feature
  competitors have already adopted, reducing sign-in seamlessness for returning users.
- **Native app support is missing**: Amazon's shopping app and Prime Video both lack
  passkey functionality, causing confusion when a passkey created via the web cannot be
  used in mobile apps.
- **Redundant OTP prompts** remain for users with 2-step verification enabled, despite
  passkeys being two-factor authentication by default, adding an unnecessary friction
  step.
- Amazon's passkey rollout across most devices and browsers mirrors moves by Apple,
  Google, TikTok and Uber, signaling broader **e-commerce industry adoption momentum**.

## The Upside of Amazons Passkey Integration

- **Enhanced Security:** Passkeys make users lives safer, mitigating
  [phishing](https://www.corbado.com/glossary/phishing) threats and eliminating the hassle of coming up and
  remembering passwords.
- **Consumer Education:** Given Amazon's vast user base, this rollout is set to
  familiarize a large segment of non-tech-savvy users with the benefits of passkeys. The
  ease of use might convince these users to demand passkeys from other online platforms as
  well.
- **Industry Implications:** The ripple effect of Amazon's move can potentially catalyze a
  widespread shift in the [e-commerce](https://www.corbado.com/passkeys-for-e-commerce) and SaaS industry towards
  quick [passkey adoption](https://www.corbado.com/blog/passkey-adoption-business-case).

![Amazon Passkey Overview FAQ](https://www.corbado.com/website-assets/652dad9b0259a4fa49f69822_amazon_passkeys_overview_faq_47602be74e.png)

## Why Amazon messed up its Passkey Implementation

- **Relying Party ID Issues:** Depending on a user's country that he has set, he may be
  redirected to different Amazon domains, requiring separate passkeys for each country /
  top-level domain. This is due to the security structure of passkeys, as each passkey
  needs to be registered for one [Relying Party](https://www.corbado.com/glossary/relying-party) ID (e.g.
  amazon.com and amazon.de). In screenshot 3, you see that for one device
  ([Windows 11](https://www.corbado.com/blog/passkeys-windows-11) with Chrome) two passkeys were set up.
- **Conditional UI Is Missing:** By not implementing
  [Conditional UI](https://www.corbado.com/glossary/conditional-ui) (Passkey Autofill), Amazon missed out on a
  critical feature that could have made passkey use even more seamless for users. The
  reasons behind are still unclear as other companies have implement
  [Conditional UI](https://www.corbado.com/glossary/conditional-ui) already.
- **Inferior Device Management:** Current device detection and management for passkeys is
  clunky, possibly leading to user confusion, especially for those using browsers like
  [Chrome on Mac](https://www.corbado.com/glossary/chrome-on-mac), where a
  [QR code](https://www.corbado.com/blog/qr-code-login-authentication) was shown instead of explaining that a
  passkey is not available or just skipping passkeys (QR codes still being a major
  struggle for most consumers).
- **No Native App Support:** Surprisingly, native apps either for Amazon's shopping app or
  for Prime Video lack passkey support (see screenshot 4 and 5 below with the message that
  no passkey could be created) which could lead to user confusion if a passkey was created
  on this device via the web application.
- **Redundant Verification Steps:** If a user has set up 2-step verification, they still
  need to go through an additional one-time code verification, which is kind of an
  unnecessary steps as
  [passkeys are 2FA by default](https://www.corbado.com/blog/psd2-passkeys/are-passkeys-two-factor-authentication).

![Two Passkeys for Two Relying Party IDs on the Same Device (Windows 11 + Chrome 118)](https://www.corbado.com/website-assets/652dadb8a443aeb4f944b9e4_amazon_passkeys_management_windows_chrome_40c1304bda.png)

![Amazon Passkeys on Native Android App](https://www.corbado.com/website-assets/652daec5592a530009f5cc46_amazon_passkeys_android_native_5a259abe25.png)

![Amazon Passkeys on Native iOS App](https://www.corbado.com/website-assets/652daedd0259a4fa49f7f749_amazon_passkeys_ios_native_0c4ee5b228.png)

## Looking Forward

Amazon has room for improvement. Prioritizing updates like making native apps
passkey-ready, introducing [Conditional UI](https://www.corbado.com/glossary/conditional-ui), and refining device
management can considerably enhance user experience. Addressing the
[Relying Party](https://www.corbado.com/glossary/relying-party) ID issue would also be a step in the right
direction but here best practices in the industry for multi-national services still need
to be defined.

In conclusion, while Amazon's venture into passkey authentication is a significant
milestone, it's evident that the journey to perfecting this feature is just beginning.
Lets hope that Amazon takes the feedback on board and iterate a better passkey
implementation soon.

## Frequently Asked Questions

### Why does Amazon make me use a different passkey for each country's website?

Amazon redirects users to regional domains (such as amazon.com or amazon.de) based on
their country setting, and each passkey is cryptographically bound to a specific Relying
Party ID. Because amazon.com and amazon.de are distinct Relying Party IDs, a separate
passkey must be registered for each, meaning a single device can end up storing multiple
Amazon passkeys.

### What is Conditional UI and why should Amazon add it to its passkey flow?

Conditional UI, also called Passkey Autofill, surfaces available passkeys directly in the
username field so users can authenticate without navigating extra menus. Amazon has not
implemented this feature despite other companies already doing so, making its passkey
experience less intuitive than the current industry standard.

### Can I sign into the Amazon shopping app or Prime Video with a passkey?

No. As of this analysis, neither Amazon's native shopping app nor Prime Video supports
passkey authentication. Users who create a passkey through Amazon's web application may
encounter an error or unexpected behaviour when trying to sign in through the mobile apps.

### Why am I still asked for a one-time code after signing into Amazon with a passkey?

Amazon still triggers an OTP prompt for accounts that have 2-step verification enabled,
even after a successful passkey authentication. This step is redundant because passkeys
inherently satisfy two-factor authentication requirements by combining device possession
with biometric or PIN verification.
