October 2023 SP-API Release Announcement
On October 2, 2023 Amazon released SP‑API SDK 2.0 for Java and C# that removes IAM and SigV4, enabling single OAuth 2.0 bearer token authentication. This change cuts onboarding time by eliminating IAM role creation and SigV4 signing, allowing developers to use getAccessToken() to fetch short‑lived tokens.
Overview
On October 2, 2023 Amazon rolled out a significant update to the Selling Partner API (SP‑API). Version 2.0 of the Java and C# SDKs eliminates the need for AWS Identity and Access Management (IAM) roles and AWS Signature Version 4 (SigV4) signing. Sellers and developers can now connect to SP‑API with a single OAuth 2.0 bearer token, cutting onboarding time and reducing maintenance.
Key Points
- No IAM Required — The new SDKs drop the IAM role creation step, allowing developers to skip the AWS console and policy setup.
- SigV4 Removed — Requests are no longer signed with SigV4; the SDK handles authentication automatically.
- SDK 2.0 Released — Updated Java and C# libraries now manage token acquisition, request headers, and error handling out of the box.
- Simplified Onboarding — Sellers can start using SP‑API endpoints with fewer prerequisites, speeding time to market.
- Backward Compatibility — Existing integrations built on older SDKs continue to function while migrating to the new version.
How the Feature Works
- OAuth 2.0 Token Retrieval — The SDK calls
getAccessToken(), exchanging a stored refresh token for a short‑lived bearer token that authenticates every request. - Automatic Header Injection — Once the token is obtained, the SDK attaches it to the HTTP
Authorizationheader for all API calls, eliminating manual SigV4 signing. - Endpoint Calls — Developers invoke high‑level SDK methods (e.g.,
GetOrders,ListInventory,SubmitFeed) without constructing raw HTTP requests. - Built‑in Retries & Error Parsing — The SDK retries transient errors automatically and converts SP‑API error responses into structured exceptions for easier debugging.
Context Section
- Before: A fulfillment system had to create an IAM user, attach a policy granting SP‑API permissions, and sign every HTTP request with SigV4. Custom signing helpers and secure storage of IAM credentials were required in the deployment pipeline.
Analysis & Recommendations
Why This Matters
Sellers can now use a single OAuth 2.0 bearer token, reducing setup steps and attack surface. The SDK automatically handles token refresh and retries, speeding time to market and lowering maintenance.
Key Takeaways
- October 2, 2023: SP‑API SDK 2.0 released for Java and C#.
- IAM roles and SigV4 signing are removed; authentication uses OAuth 2.0 bearer tokens.
- SDK automatically injects Authorization header via getAccessToken() and retries transient errors.
- Backward compatibility ensures older SDKs still function during migration.
Recommended Actions
- →Upgrade to SP‑API SDK 2.0 for Java or C# in your project dependencies.
- →Delete any IAM users or roles used for SP‑API and store the refresh token securely.
- →Run integration tests against orders, listings, and reports endpoints to confirm token-based authentication and error handling.
Comments
Join the discussion
Log in or create an account to share your thoughts on this update.
No comments yet. Be the first to share your thoughts!