New: Introducing SP-API support for third-party providers
In June 2024 Amazon added a Transfers API (v2024‑06‑01) and new “TPP Operator”/“TPP Viewer” roles to the SP‑API, plus the `sellingpartnerapi::payments` OAuth scope and mandatory MFA for TPP credentials. These let approved third‑party providers programmatically trigger payouts and retrieve payment data.
Overview
In June 2024 Amazon expanded the Selling Partner API (SP‑API) to include open‑banking‑style connections for third‑party providers (TPPs). The upgrade adds a dedicated Transfers API, broadens the Sellers API, and introduces role‑based permissions that let external fintech services move and reconcile funds on a seller’s behalf. Sellers and their technology partners need to understand these changes because they create a secure, programmatic route for payments that previously required manual steps inside Seller Central.
Key Points
- Transfers API v2024‑06‑01 — Allows approved TPPs to trigger payouts from an Amazon seller balance to an external bank account, such as a payment processor sending a seller’s earnings to a newly opened business checking account.
- Sellers API extension — Provides new endpoints for authorized TPPs to pull account‑holder information and payment‑service metadata; a bookkeeping SaaS can now fetch a seller’s settlement records and automatically generate journal entries.
- New role definitions — Adds “TPP Operator” and “TPP Viewer” roles, enabling a fintech partner to execute transfers while restricting its view to only the data required for compliance.
- OAuth 2.0 scope expansion — Requires TPPs to request the
sellingpartnerapi::paymentsscope; a budgeting application must ask the seller to approve this scope before it can read payout details. - Enhanced security checks — Mandates multi‑factor authentication (MFA) for the issuance of TPP credentials; a banking API, for example, will send a one‑time passcode to the seller’s registered phone before granting access.
How SP‑API Support for Third‑Party Providers Works
- TPP registration — A fintech firm creates an account in Amazon’s Developer Console, selects the “Third‑Party Provider” program, and uploads compliance documents such as an ISO 27001 certificate; only after verification does Amazon issue API credentials.
- Role assignment — The seller logs into Seller Central, opens the “User Permissions” page, and assigns the TPP either the “Operator” role (to initiate transfers) or the “Viewer” role (to read data). For instance, a cash‑flow management tool may receive the Operator role, while an analytics dashboard is given Viewer access.
Analysis & Recommendations
Why This Matters
Fintech partners can now initiate ACH transfers directly from a seller’s Amazon balance, e.g., moving $5,200 to a Stripe‑connected account, eliminating manual payout steps. Sellers gain granular control with Operator and Viewer roles and must enable MFA, reducing fraud risk. Integration code must be updated to request the new payments scope and call the v2024‑06‑01 endpoint.
Key Takeaways
- Transfers API v2024‑06‑01 enables TPPs to trigger payouts from Amazon balances to external bank accounts.
- New role definitions “TPP Operator” and “TPP Viewer” separate transfer execution from read‑only access.
- OAuth scope `sellingpartnerapi::payments` is required for any TPP to read or initiate payment‑related actions.
- MFA is now mandatory for issuing TPP credentials and for approving transfer requests.
Recommended Actions
- →In Seller Central go to User Permissions and assign the appropriate “TPP Operator” or “TPP Viewer” role to each fintech partner.
- →Confirm that all third‑party apps you use have been updated to request the `sellingpartnerapi::payments` scope and to call the v2024‑06‑01 Transfer...
- →Enable multi‑factor authentication for TPP API credentials via the Developer Console > Security Settings.
Comments
Join the discussion
Log in or create an account to share your thoughts on this update.
No comments yet. Be the first to share your thoughts!