SP-API no longer requires AWS IAM or AWS Signature Version 4
On 2 October 2023 Amazon eliminated the need for AWS IAM users and Signature Version 4 signing in the Selling Partner API. Authentication now requires only a Login with Amazon OAuth 2.0 access token (Bearer) in the Authorization header.
Overview
On 2 October 2023 Amazon removed the requirement for AWS Identity and Access Management (IAM) credentials and the AWS Signature Version 4 signing process from the Selling Partner API (SP‑API). From that date forward, developers authenticate exclusively with Login with Amazon (LWA) OAuth 2.0 tokens, a change that cuts integration complexity and reduces ongoing maintenance for sellers and solution providers.
Key Points
- IAM resources eliminated — Sellers no longer need to create IAM users, attach the
AmazonSPAPIAccesspolicy, or rotate access keys for SP‑API calls. - SigV4 signing dropped — The intricate Signature Version 4 algorithm is no longer required; a simple Bearer token in the
Authorizationheader is sufficient. - LWA as sole auth method — All authentication continues to rely on OAuth 2.0 access tokens issued by Login with Amazon, preserving the existing OAuth flow.
- Endpoint behavior unchanged — Every SP‑API operation, data model, and rate‑limit rule remains identical; only the authentication layer has been altered.
- Security model retained — Amazon still validates token scopes, enforces TLS, and checks token expiration, so overall security posture is not weakened.
- Automatic migration — The switch occurred on 2 October; any integration that still attempts IAM‑based authentication now receives a 401 error, prompting an immediate update.
How the New Authentication Flow Works
- Obtain an LWA access token — Register an LWA security profile in the Amazon Developer Console, then use the profile’s client ID, client secret, and a stored refresh token to request a fresh OAuth 2.0 access token from
https://api.amazon.com/auth/o2/token. Example: an inventory‑management SaaS exchanges its long‑lived refresh token for a new access token every hour to keep its API calls authorized. - Attach the token to the request — Insert the received access token into the HTTP header using the format . No additional headers, canonical request strings, or signed timestamps are needed.
Analysis & Recommendations
Why This Matters
Integrations that still send IAM credentials will receive 401 errors, causing order, inventory, or report calls to fail. Switching to LWA tokens reduces code complexity, removes key rotation, and eliminates AWS charges for dedicated IAM users.
Key Takeaways
- Effective 2 Oct 2023 IAM users and the AmazonSPAPIAccess policy are no longer used for SP‑API.
- SigV4 signing is dropped; a simple 'Authorization: Bearer <token>' header is sufficient.
- LWA security profiles must request scopes such as sellingpartnerapi::orders, ::reports, ::notifications.
- Failed IAM‑based calls now return HTTP 401, prompting immediate migration.
Recommended Actions
- →In Seller Central > Developer Central, register or update an LWA security profile and note the client ID/secret.
- →Replace any AWS4Signer or boto3 signing code with a POST to https://api.amazon.com/auth/o2/token to obtain a bearer token and add it to the Authori...
- →Delete unused IAM users, access keys, and AmazonSPAPIAccess policies in the AWS console to reduce attack surface.
Comments
Join the discussion
Log in or create an account to share your thoughts on this update.
No comments yet. Be the first to share your thoughts!