ixBrowser Exclusively Launches Passkey Module Feature

Clark
Clark
IPWeb Technical Researcher

In 2026, Google Ads and Amazon are accelerating the mandatory rollout of Passkey. Starting July 15, Google Ads requires Passkey for sensitive operations (e.g., adding users, modifying billing); from August 5, API new refresh tokens must be authenticated with Passkey; and from August 19, Passkey will be mandatory for all Admin, Billing, and Standard users. Amazon, meanwhile, fully opened Passkey login for Seller Central to global sellers in July and plans to mandate it for some stores starting in the second half of this year. These timelines make it clear: Passkey has moved from optional to mandatory.

For multi-account operators, Passkey’s inherent binding to physical devices greatly increases the risk of device fingerprint correlation—how can you meet platform security requirements while preventing multiple accounts from being identified as originating from the same device or studio? ixBrowser’s newly launched Passkey feature offers four flexible AAGUID configuration modes (Follow System, Random, Zero AAGUID, and IX-Passkey), allowing you to precisely control how device fingerprints are presented across different scenarios, striking the optimal balance between compliance and anti-association.

What is Passkey?

Passkey is a next-generation passwordless authentication technology based on the FIDO Alliance standards. It uses built-in biometrics (fingerprint, facial recognition) or screen-lock PINs on your device to verify your identity, so you never need to remember any passwords.

In short, Passkey replaces “a password you remember” with “you yourself” to prove who you are.

Passkey passwordless authentication illustration
Illustration: Passkey uses device biometrics or a screen-lock PIN for authentication.

Core Advantages of Passkey

Compared with traditional passwords, Passkey delivers revolutionary improvements in security and user experience:

Phishing-resistant and leak-proof: Passkeys are bound to the device and cannot be shared, guessed, copied, or accidentally disclosed to others. They are never transmitted over the network, so even on phishing sites, they cannot be stolen.

Faster and more convenient: Logging in with a Passkey takes just a fingerprint scan or a face scan—up to 50% faster than traditional passwords. No need to remember passwords or wait for SMS verification codes.

Privacy protection: Your biometric data is stored only locally on your device; platforms do not collect or store any biometric information.

Cross-platform compatibility: Major platforms including Apple, Google, and Microsoft fully support Passkey, and over 15 billion accounts worldwide can already use Passkeys.

Passkey biometric and device authentication ecosystem
Illustration: Passkey connects devices, biometrics, and passwordless login.

Why Must You Pay Attention to Passkey Now?

In the past, Passkey was just a “nice-to-have” option. But starting in the second half of 2026, it is becoming a “must-have” requirement.

If you manage multiple Google Ads accounts or Amazon stores simultaneously, the traditional “one device, one identity” model will no longer work—because each Passkey is tied to a specific physical device. How can you enable multiple accounts to use Passkey independently within their own “environments” without interfering with or linking to each other?

This is exactly the core problem that ixBrowser’s Passkey feature solves.

Four Configuration Modes of ixBrowser Passkey

ixBrowser offers four flexible Passkey AAGUID configuration modes for different scenarios. Before diving in, let’s briefly explain what AAGUID is.

AAGUID (Authenticator Attestation Global Unique Identifier) is a 16-byte identifier defined in the WebAuthn specification that identifies the model of the authenticator (i.e., the password manager or device) that created the Passkey. In simple terms, AAGUID is the “device ID card” of a Passkey—it tells the website: “this Passkey was created by iCloud Keychain” or “this Passkey was created by Windows Hello.”

Website servers can use the AAGUID to determine the type of device the user is using, enabling device fingerprinting and risk control decisions.

ixBrowser’s four Passkey configuration modes essentially allow you to flexibly control how this “device ID card” is presented, adapting to different operational scenarios.

Follow System

Operation mechanism: Automatically reads the User-Agent (UA) and operating system information of the current browser environment and mimics the most reasonable native authenticator for that environment. For example, under Mac/Safari it mimics Apple’s iCloud Keychain; under Windows/Edge it mimics Windows Hello.

Core distinction: Highly consistent with the environment—device fingerprints perfectly match the browser environment.

Use cases:

Registration/login on high-risk websites: Some strict sites (e.g., financial platforms, large internet platforms) verify device fingerprints. If the UA shows an iPhone but the AAGUID is a Windows-specific device identifier, it will likely be flagged as risky. “Follow System” perfectly solves this environmental mismatch.

Everyday incognito use: The preferred option for mimicking an ordinary real user.

Random

Operation mechanism: Each time the Passkey interface is called, a brand-new, completely random AAGUID is dynamically generated.

Core distinction: Each interaction appears as a new “unknown device,” with no correlation between devices.

Use cases:

Batch account registration/disposal: Prevents multiple accounts from being linked by the website server to the same device or studio due to sharing the same AAGUID.

Stress testing or black-box testing: Developers use this to test the server’s handling and compatibility with unknown or massive numbers of AAGUIDs.

Note: On a very small number of extremely strict websites that only accept AAGUIDs from “known vendors,” this mode may cause registration failures.

Zero AAGUID

Operation mechanism: Forces output of an all-zero AAGUID (00000000-0000-0000-0000-000000000000).

Core distinction: An absolute privacy mode that complies with the WebAuthn official standard. The WebAuthn specification clearly states that if you do not wish to expose the device model to protect user privacy, you should use an all-zero AAGUID. An all-zero AAGUID is a privacy signal indicating that the authenticator actively hides the device model—it is not an error or a null value.

Use cases:

General website access: The vast majority of standard-compliant websites support the all-zero AAGUID—this is the most universally safe option.

Anti-tracking: You do not want the website to collect any information about your hardware/software type; not even “pretending” is desired—you simply tell the website “no comment.”

ixB-Passkey

Operation mechanism: Uses a fixed, dedicated AAGUID pre-set by ixBrowser.

Core distinction: Has a highly stable fixed signature, clearly declaring itself as ixBrowser Passkey.

Use cases:

Internal systems / corporate intranets: Some internal or specific systems may have whitelisted ixBrowser’s AAGUID, allowing only this identifier to be trusted and granted access.

How to Use ixBrowser’s Passkey Feature and Important Notes

Using ixBrowser’s Passkey feature is very simple and requires only a few steps:

Open ixBrowser and enter the browser environment you wish to configure.

Opening a browser profile in ixBrowser
Step 1: Open the browser profile you want to configure in ixBrowser.

In the Preferences, locate the Passkey Manager item and click to enable it.

Enabling Passkey Manager in ixBrowser preferences
Step 2: Find and enable Passkey Manager in Preferences.

After enabling, the Passkey simulation identity configuration option appears below. Choose one of the four modes according to your usage.

Selecting a Passkey AAGUID configuration mode in ixBrowser
Step 3: Select the appropriate Passkey AAGUID configuration mode.

Save the settings. Then, when you call the WebAuthn interface to create or use a Passkey within that browser environment, the AAGUID strategy you selected will be applied automatically.

Note: The Passkey feature supports kernel version 148 and above only.

2026 is the critical turning point when Passkey moves from “optional” to “standardised.” The simultaneous push by Google Ads and Amazon means that passwordless authentication has become an irreversible trend.

For multi-account operators, this is both a challenge and an opportunity—those who can adapt to the new rules of the Passkey era first will gain the upper hand in account security and operational efficiency.

Experience ixBrowser’s Passkey feature now, plan ahead, and confidently embrace the passwordless future!

About the author
View all articles
Clark
Clark
IPWeb Technical Researcher

A technical writer specializing in IP proxy services and network architecture. All content is derived from over six years of hands-on experience at a leading IP proxy provider, covering areas such as large-scale proxy network orchestration, optimization of SOCKS5/HTTP protocol stacks, and the dynamics of anti-scraping strategies and countermeasures. The goal is to dissect the engineering logic underpinning network security, stability, and efficiency.

Service areas
Proxy IP network architecture anti-scraping countermeasures protocol optimization for web scraping large-scale data collection engineering

You may be interested in

What Is WebDriver Selenium browser automation basics

What Is WebDriver? Selenium Browser Basics

Web pages that depend on JavaScript, clicks, form input, or browser state often need more than a plain HTTP request. WebDriver gives test and automation code a standardized way to open a browser, interact with page elements, and inspect the result. Quick Answer WebDriver is a standardized way for software to control a web browser through commands such as opening a page, finding an element, clicking, typing, reading text, and closing the session. Selenium WebDriver is the best-known implementation used for browser testing and automation. WebDriver is useful when a workflow depends on real browser behavior, including JavaScript rendering and...

Ryan

Ryan

IP Proxy Research Team

Rotating vs Sticky Proxies in Hidemium: Which IPWeb Proxy Setup Is Right for You?

Rotating vs Sticky Proxies in Hidemium: Which IPWeb Proxy Setup Is Right for You?

If you're using IPWeb proxies with Hidemium Antidetect Browser, one of the first decisions is whether your browser profile should use a sticky proxy or a rotating proxy. The difference is simple: Sticky proxy: keeps the same IP address for a defined session. Rotating proxy: automatically changes the exit IP over time or between connections. For Hidemium users, sticky proxies are generally better when a browser profile needs a consistent network identity, while rotating proxies are more suitable for research, data collection and workflows that benefit from IP diversity. This guide explains when to use each IPWeb proxy type with...

Clark

Clark

IPWeb Technical Researcher

MostLogin Honest Review 2026

MostLogin Honest Review 2026

MostLogin is one of the more ambitious newcomers in the antidetect-browser market. Instead of offering only isolated browser profiles, it combines desktop fingerprints, team collaboration, automation APIs, Android cloud phones, and AI-agent integration in one platform. That breadth is its biggest advantage - and also the reason to approach it carefully. MostLogin looks remarkably capable for its price, but it is still a young product without the long operating history or extensive independent testing of established competitors. Review basis: MostLogin's desktop client experience, published pricing, and available third-party reports reviewed. Quick verdict Overall rating: 8.6/10 MostLogin is an attractive choice...

Clark

Clark

IPWeb Technical Researcher

Ready to scale your data operations?
Join 10,000+ teams using IPWeb to power their web data collection. Start free today.

Strictly anti-abuse

Fraud, automated operation, and unauthorized use are prohibited.

Enterprise-level services

For legitimate commercial and technical use cases only

Risk control and restrictions

Abnormal behavior may trigger service restrictions or termination.

Compliance data use

Data acquisition and use must comply with relevant regulations.

Privacy protection first

The collection or misuse of sensitive personal information is strictly prohibited.

All services are subject to《the Usage Policy》