Added to Amalert: Jan 30, 2026
Amazon Tightens SP-API Security Rules: What Sellers and Developers Must Do Before June 25
Amazon will enforce new SP‑API security rules on June 25 2025. All traffic must use TLS 1.2 or higher, API keys must be rotated at least every 90 days, and non‑PII data can be retained for a maximum of 18 months. A formal Key Management System is also required.
Overview
Amazon will enforce a revamped set of security and data‑protection rules for the Selling Partner API (SP‑API) on June 25 2025. The updates raise the bar on encryption, credential handling, supply‑chain oversight, and incident response. Sellers and developers who keep their integrations active after the deadline automatically accept the new terms, making early preparation essential.
Key Points
- Encryption baseline — All API traffic must use TLS 1.2 or higher; any integration still on TLS 1.0/1.1 will be blocked after the deadline.
- Credential rotation — API keys must be regenerated on a regular schedule, and password policies must remember the last ten passwords to prevent reuse.
- Supply‑chain scope — Third‑party vendors, contractors, and subcontractors are now subject to the same data‑protection standards as the primary API user.
- Vulnerability remediation — Critical flaws must be patched within seven days, while high‑risk issues have a 30‑day deadline.
- Data‑retention limits — Non‑PII records may be kept for a maximum of 18 months; security logs require at least 12 months of storage.
- Key Management System (KMS) — Organizations handling encrypted data must adopt a formal KMS for key generation, storage, rotation, and retirement.
What's Changing
-
Standardized terminology — Amazon now uses a unified “Selling Partner” lexicon and defines roles such as “Primary API User” and “Authorized Representative.”
Example: A developer who previously referenced “seller account” must update documentation to the new “Selling Partner” term to avoid compliance warnings. -
Network‑level hardening — Anti‑virus and malware solutions must incorporate tamper‑prevention controls, and accounts lock after ten consecutive failed logins.
Example: A third‑party integration that only logs failed attempts will need to add an automatic lockout feature after the tenth failure.
Analysis & Recommendations
Why This Matters
If sellers or developers do not upgrade to TLS 1.2, implement automated key rotation, or enforce the 18‑month data‑retention limit, their SP‑API integration will be blocked after June 25 2025, leading to service disruption and possible compliance penalties.
Key Takeaways
- TLS 1.0/1.1 will be blocked after June 25 2025; only TLS 1.2+ is accepted.
- API keys must be regenerated on a schedule (e.g., every 90 days) and password policies must retain the last ten passwords.
- Non‑PII records may be stored for no more than 18 months; security logs require at least 12 months of retention.
Recommended Actions
- →Run a TLS scan on every SP‑API endpoint in Seller Central > Settings > API Integration and upgrade any client or server that negotiates TLS 1.0/1.1...
- →Create an automated rotation job in your CI/CD pipeline to regenerate API keys every 90 days and update all scripts; document the process in your d...
- →Implement a KMS (e.g., AWS KMS) and schedule a nightly job to purge non‑PII data older than 18 months while archiving security logs for at least 12...
Comments
Join the discussion
Log in or create an account to share your thoughts on this update.
No comments yet. Be the first to share your thoughts!