UPDATE: Discontinued Support - LWA Tokens can no longer retrieve PII in Selling Partner API
Amazon has removed PII retrieval via LWA tokens in SP‑API, effective immediately. Developers must now use the OAuth flow with the read:buyer_info scope; otherwise endpoints will return 403 or omit buyer fields. This change requires updating integrations and monitoring for missing PII.
Overview
Amazon has removed the ability for developers to pull personally identifiable information (PII) from the Selling Partner API (SP‑API) using Login with Amazon (LWA) access tokens. The change, announced in an updated “Discontinued Support” notice, takes effect immediately. Sellers and developers who rely on SP‑API to retrieve buyer data must adjust their integrations to use the new authorization flow.
Key Points
- LWA tokens no longer return PII — Any SP‑API request authenticated with an LWA token will now omit buyer name, address, email, and phone fields from the response.
- All LWA‑authenticated calls are affected — Order, shipment, and buyer‑information endpoints that previously returned full details will now provide only non‑PII data.
- New “SP‑API Authorization” flow is required — Developers must switch to the OAuth flow that issues a separate access token with the “read:buyer_info” scope.
- Endpoints still exist but need new token —
GetBuyerInfoandGetOrderBuyerInforemain operational but will reject requests lacking the required scope. - Immediate enforcement — The policy is in effect from the moment of the announcement; no grace period is provided.
- Explicit buyer consent is mandatory — The new token can only be issued after the buyer approves the “read:buyer_info” permission during the authorization step.
- Scope validation happens at token issuance — Tokens issued without the required scope will trigger a 403 Forbidden status or silent removal of PII fields.
- Sandbox testing is now essential — Developers must verify the new flow in the SP‑API sandbox before deploying to production.
- Legacy integrations will fail silently — Calls that still use the old LWA token will return incomplete data, potentially breaking downstream processes.
- Compliance is tied to Amazon’s policy — Failure to update integrations can result in API access restrictions or account suspension.
Analysis & Recommendations
Why This Matters
Developers using LWA tokens will get incomplete data or 403 errors, breaking order processing, analytics, and compliance. Must switch to new token with read:buyer_info scope to retrieve buyer details and avoid service disruptions.
Key Takeaways
- LWA tokens no longer return buyer name, address, email, phone fields
- Endpoints like GetBuyerInfo will reject requests lacking read:buyer_info scope
- Missing scope triggers 403 Forbidden or silent PII removal
- No grace period; enforcement is immediate
Recommended Actions
- →Audit SP‑API calls in Seller Central > Developer Tools > API Credentials to identify LWA token usage
- →Update OAuth flow to request read:buyer_info scope and add consent screen for buyers
- →Test new token in SP‑API sandbox and verify GetBuyerInfo returns full data
Comments
Join the discussion
Log in or create an account to share your thoughts on this update.
No comments yet. Be the first to share your thoughts!