How to Use Seller Central's Permissions Manager to Control SP-API and Third-Party App Access
Seller Central’s Permissions Manager (Settings ▶ User Permissions ▶ Permissions Manager) shows a unified list of every SP‑API app, developer name, and exact scopes like “Read Orders, Write Inventory”. Sellers can grant, modify, or instantly revoke access with one click, enabling quarterly audits to drop apps idle for 30 days.
Overview
Amazon’s Permissions Manager, located inside Seller Central, gives sellers a single view of every third‑party app that can reach their account through the Selling Partner API (SP‑API). The tool lets you see who is connected, what data they can touch, and lets you add or remove access at any moment. Managing these permissions is crucial because many sellers rely on external software for inventory, pricing, analytics, and advertising, and each connection represents a potential data‑security risk.
Key Points
- Unified dashboard — All SP‑API authorizations appear on one page, so you can instantly spot which apps have access, such as a pricing optimizer that shows up alongside a fulfillment‑reporting service.
- Explicit consent required — Before any app can read or write to your account, it must pass the SP‑API consent flow; you will see a permission screen that lists every data type the app wants.
- Fine‑grained scopes — Permissions are broken down by function (orders, inventory, financials, reports), allowing you to grant read‑only access for a sales‑analytics tool while denying write rights.
- Instant revocation — If a trial‑period tool expires or you no longer trust a developer, a single click removes its token and blocks future API calls.
- Developer details displayed — The manager shows the developer’s name, the application title, and the exact API scopes granted, helping you verify that “Acme Analytics” is not masquerading as a different service.
How the Permissions Manager Works
- Open the Permissions page — From Seller Central, select Settings ▶ User Permissions, then click the Permissions Manager tab; you’ll see a table listing every authorized third‑party app.
- Review each entry — Each row includes the developer’s name, the app’s label (e.g., “Smart Reprice”), and the scope list (e.g., “Read Orders, Write Inventory”). For example, a logistics integration might show only “Read Shipments” while a full‑service ERP shows both read and write scopes.
Analysis & Recommendations
Why This Matters
Having a single view of all SP‑API tokens lets sellers quickly spot stale or over‑privileged connections, reducing data‑breach risk. The instant revocation button removes a token immediately, and the quarterly audit recommendation helps maintain compliance with Amazon’s security expectations.
Key Takeaways
- Permissions Manager lists every authorized SP‑API app with developer name, app title, and scopes such as “Read Orders, Write Inventory”.
- A single‑click “Remove” button instantly invalidates an app’s token and logs the revocation date.
- Quarterly audits are advised: review apps not used in the past 30 days and revoke them.
- New app consent flow mirrors the Permissions Manager layout, requiring explicit approval of each requested scope.
Recommended Actions
- →In Seller Central go to Settings ▶ User Permissions ▶ Permissions Manager and review the app table.
- →Click the Remove button for any app idle for >30 days or with unnecessary write scopes.
- →Record each change (date, app name, scopes granted/revoked) in a spreadsheet for compliance.
Comments
Join the discussion
Log in or create an account to share your thoughts on this update.
No comments yet. Be the first to share your thoughts!