Important Notice: Discontinued Support - LWA Tokens can no longer retrieve PII in Selling Partner API
Amazon will strip buyer PII from legacy LWA tokens on July 31 2023 and require a new access token scoped with sellingpartnerapi::notifications by August 31 2023. Calls without the new scope will return HTTP 403 errors, breaking order‑processing flows that rely on email, phone or address data.
Overview
Amazon is retiring the legacy Login with Amazon (LWA) token method that previously allowed the Selling Partner API (SP‑API) to return buyer personally identifiable information (PII) such as email addresses and shipping details. The phase‑out begins on July 31 2023, when LWA tokens stop delivering any PII, and concludes on August 31 2023, when all SP‑API calls that need PII must be made with a newly scoped access token. Sellers and solution providers must adjust their integrations now to keep order‑processing flows running and stay compliant with Amazon’s data‑privacy rules.
Key Points
- PII stripped from LWA tokens — Starting July 31 2023, any SP‑API request that presents an LWA token will receive responses that exclude buyer email, phone, and address fields.
- New token scope required — From August 31 2023 onward, only access tokens generated with the
sellingpartnerapi::notificationsscope (or an equivalent scope) are authorized to retrieve PII. - Migration deadline — All production applications must adopt the new token flow by the end of August 2023; otherwise, requests for PII will be rejected with HTTP 403 errors.
- Code changes needed — Integrations that embed the LWA token directly or rely on automatic token refresh without specifying the new scope will fail until they are updated.
- Privacy compliance — The change aligns the SP‑API with Amazon’s broader privacy standards, reducing the chance of accidental PII exposure.
How the Token Transition Works
-
Capture a refresh token — Continue using the standard LWA authorization‑code flow to obtain a refresh token. For example, a seller‑central application redirects the user to
login.amazon.comwithclient_idandscope=profile; after the user consents, the app receives a refresh token that can be stored for later use. -
Request a refreshed access token with the new scope — Instead of calling the legacy token endpoint, the app now posts to and includes three key parameters: , the stored refresh token, and . A concrete Python snippet might look like:
Analysis & Recommendations
Why This Matters
Seller applications that pull buyer email, phone or shipping address from the Orders API will lose that data after July 31 2023, causing fulfillment delays and potential compliance breaches. The new token scope must be used to restore PII access, and missing it triggers 403 rejections, impacting order‑label generation and buyer communications.
Key Takeaways
- LWA tokens stop delivering buyer email, phone, and address fields on July 31 2023.
- A new access token with the scope sellingpartnerapi::notifications is required to retrieve PII.
- All production apps must migrate by August 31 2023 or receive HTTP 403 errors on PII requests.
- Token requests must be posted to https://api.amazon.com/auth/o2/token with grant_type=refresh_token and the new scope.
Recommended Actions
- →Update your token refresh code to POST to https://api.amazon.com/auth/o2/token with scope=sellingpartnerapi::notifications (see Seller Central > Ap...
- →Run end‑to‑end tests on the Orders API (GET /orders/v0/orders) to confirm buyerInfo.email is returned with the new token.
- →Add log monitoring for HTTP 403/401 responses in your integration and alert if they appear after July 31 2023.
Comments
Join the discussion
Log in or create an account to share your thoughts on this update.
No comments yet. Be the first to share your thoughts!