Application Management API v2023-11-30 is now in Production
Amazon has moved the Application Management API version 2023‑11‑30 to Production as of May 23 2024. The new REST endpoint /applications/{applicationId}/rotateClientSecret lets sellers programmatically replace LWA client secrets across all marketplaces.
Overview
Amazon has promoted the Application Management API version 2023‑11‑30 from its sandbox environment to the live Production platform. The new endpoint enables sellers and developers to rotate the client secret linked to their Login with Amazon (LWA) credentials automatically. Because the change spans every Amazon marketplace, any seller that relies on LWA for authentication must adjust their integration workflow.
Key Points
- Production availability — As of the announced rollout date, the 2023‑11‑30 API version is fully active on Amazon’s Production servers.
- Automated secret rotation — Sellers can now replace LWA client secrets through a REST call, removing the need to edit secrets manually in Seller Central.
- Global marketplace reach — The endpoint works across all Amazon marketplaces, from the United States and Canada to European and Asian sites, affecting every LWA‑enabled seller.
- Enhanced security posture — Regular, programmatic secret changes lower the chance of credential leakage and align with industry‑standard security practices.
- Developer‑friendly design — The API follows conventional REST patterns, accepts JSON payloads, and returns clear HTTP status codes, making it straightforward to embed in existing automation scripts.
How the Application Management API Works
- Create a rotation request — The seller issues a
POSTto/applications/{applicationId}/rotateClientSecret, supplying the currentclientIdand a newly generated secret in the request body.- Example payload:
{ "clientId": "amzn1.application-oa2-client.abcdef1234567890", "newClientSecret": "Z9y8X7w6V5u4T3s2R1q0pO" }
- Example payload:
- Amazon validates the call — Amazon confirms that the supplied
clientIdbelongs to the caller’s developer account, checks that the new secret satisfies complexity requirements, and verifies the LWA access token used for authentication.
Analysis & Recommendations
Why This Matters
Automated secret rotation eliminates manual updates in Seller Central, reducing outage risk and meeting security best‑practices. Sellers can now schedule nightly rotations, store the new secret in AWS Secrets Manager, and instantly propagate it to order‑processing bots and inventory sync services.
Key Takeaways
- Production rollout of API version 2023‑11‑30 occurred on 2024‑05‑23.
- Endpoint POST /applications/{applicationId}/rotateClientSecret accepts JSON with clientId and newClientSecret.
- Successful rotation returns a 200 OK with fields applicationId, clientSecretStatus="ROTATED", and effectiveDate timestamp.
Recommended Actions
- →Create a scheduled job (e.g., AWS Lambda) that calls POST /applications/{applicationId}/rotateClientSecret nightly and stores the new secret in AWS...
- →Refactor all code to read the LWA client secret from the secret store instead of hard‑coded values or Seller Central UI.
- →Set up a CloudWatch alarm that queries /applications/{applicationId}/rotationHistory for unexpected rotations and alerts the security team.
Comments
Join the discussion
Log in or create an account to share your thoughts on this update.
No comments yet. Be the first to share your thoughts!