Amazon Warns Sellers: Only Use Vetted Apps from the Official Appstore
In early February 2026 Amazon warned sellers that every third‑party app must appear in the Amazon Appstore. Sellers have a 30‑day window to audit their “Manage Your Apps” list, revoking any integration not listed or inactive for 90 days, or risk suspension.
Overview
Amazon has issued a warning that every third‑party application linked to a seller’s account must be listed in the official Amazon Appstore. The directive, released in early February 2026, aims to stop unvetted tools from accessing sensitive sales data or compromising account security. Sellers who ignore the notice risk data breaches, policy violations, and possible suspension of their Amazon storefronts.
Key Points
- Appstore‑Only Rule — Only applications that appear in the Amazon Appstore have passed Amazon’s security and compliance checks, meaning they are safe to connect to a seller account.
- Mandatory Audit — Sellers must open the “Manage Your Apps” page in Seller Central and verify that every listed integration matches an Appstore entry, removing any that do not.
- Permission Clean‑up — Any app that has not been used in the past 90 days or that the seller cannot identify should have its access token revoked immediately.
- Pre‑Connection Check — Before granting API credentials to a new service, sellers should search the Appstore catalog for the tool’s name and confirm the developer’s Amazon‑verified status.
- Enforcement Timeline – Amazon has given sellers a 30‑day window to complete the audit; after that, accounts with unapproved connections may be flagged for review or suspended.
How Amazon Vets Third‑Party Apps
Amazon’s vetting framework follows three sequential pillars, each designed to filter out risky software before it reaches the marketplace.
- Policy Alignment Review — Developers submit a compliance package that demonstrates adherence to the Amazon Services Business Solutions Agreement; for example, a pricing‑automation tool must disclose that it never manipulates Buy Box eligibility, and Amazon cross‑checks the claim against its policy database.
- Data‑Security Certification — The app’s architecture is examined for encryption at rest and in transit, secure token storage, and role‑based access controls; a inventory‑management solution that stores sales figures in an unencrypted S3 bucket would fail this stage and be rejected.
Analysis & Recommendations
Why This Matters
Non‑compliant apps can expose sales data and trigger Amazon enforcement, potentially suspending storefronts during peak periods like Prime Day. By meeting the 30‑day audit deadline and cleaning inactive permissions, sellers protect data and maintain uninterrupted sales.
Key Takeaways
- Only apps listed in the Amazon Appstore pass Amazon’s security and compliance checks.
- Sellers must complete the audit within 30 days from the early February 2026 notice.
- Any app unused for more than 90 days must have its access token revoked immediately.
- Amazon performs quarterly automated scans and can suspend apps that request new read‑write permissions.
Recommended Actions
- →Log into Seller Central > Settings > Manage Your Apps, export the integration list, cross‑reference each entry with the Amazon Appstore, and revoke...
- →For each retained app, edit its OAuth scope to the minimal required permission (e.g., read‑only pricing) via the app’s settings page.
- →Create a calendar reminder to repeat the audit every 90 days and document revocations, reasons, and screenshots in a spreadsheet for potential Amaz...
Comments
Join the discussion
Log in or create an account to share your thoughts on this update.
No comments yet. Be the first to share your thoughts!