Announcing Vendor Central Self-Authorization
On 18 October 2022 Amazon Vendor Central retired its legacy developer‑console token screen and launched a self‑service authorization portal that lets a single client ID issue refresh tokens for multiple vendor groups. Legacy tokens remain usable for 90 days, after which they must be regenerated via the new portal.
Overview
On 18 October 2022 Amazon Vendor Central retired its old developer‑console token screen and introduced a self‑service authorization portal. The new interface lets vendors request refresh tokens for multiple vendor groups from a single application, cutting onboarding time and simplifying credential management. Sellers using inventory, pricing, or order APIs must adopt the updated flow to avoid service interruptions.
Key Points
- Single‑application token issuance — One client ID can now generate refresh tokens for any number of vendor groups, removing the need to maintain separate credentials per group.
- Self‑service grant creation — Vendors initiate and manage authorization grants directly in the portal, eliminating reliance on Amazon support tickets for token provisioning.
- Onboarding time reduced to minutes — The instant‑grant model shrinks the typical multi‑day setup to a few minutes once the consent screen is approved.
- Granular token revocation — Each refresh token is scoped to a specific vendor group, allowing sellers to revoke a single group’s access without affecting others.
- Legacy token sunset — Tokens issued through the retired console stay active for 90 days; after that window they must be regenerated via the new portal.
- Improved security posture — Scoped tokens limit exposure, and the portal logs all grant activity for easier audit and compliance.
How Vendor Central Self‑Authorization Works
- Application registration — The developer registers the third‑party tool in Vendor Central and receives a client ID and client secret. Example: An inventory‑sync service registers and is assigned the client ID “VC‑APP‑5678” together with a secret key.
- Vendor‑group selection — Inside the self‑authorization portal the user checks every vendor group the application should access. Example: A seller with “Books US” and “Toys EU” groups selects both checkboxes before proceeding.
- Grant request submission — The portal presents an Amazon‑hosted consent screen that lists the requested scopes such as orders, listings, or pricing.
Analysis & Recommendations
Why This Matters
The new instant‑grant model cuts onboarding from days to minutes and consolidates credentials, but any token issued through the retired console will stop working after the 90‑day grace period. Sellers who do not migrate will see API authentication failures, while the scoped tokens give the ability to revoke access for a single vendor group without disrupting others.
Key Takeaways
- Retired console token screen was removed on 18 Oct 2022; the self‑authorization portal now handles grant creation.
- One client ID can generate refresh tokens for any number of vendor groups, eliminating separate credentials per group.
- Legacy tokens stay active for a 90‑day grace period before they must be regenerated via the new portal.
- Refresh tokens are scoped per vendor group, enabling granular revocation without affecting other groups.
Recommended Actions
- →Log into Vendor Central > Developer Settings, register or locate your application to obtain a client ID and client secret if not already done.
- →Go to Vendor Central > Self‑Authorization portal, select all required vendor groups, approve the consent screen, and capture the new refresh token.
- →Within 90 days, replace any old refresh_token values in your integration configuration files with the newly issued token and test API calls.
Comments
Join the discussion
Log in or create an account to share your thoughts on this update.
No comments yet. Be the first to share your thoughts!