Update to LWA credentials rotation deadline
Amazon has extended the cut‑off for rotating Login With Amazon (LWA) client secrets older than 180 days to May 31 2023, moving the original March 27 2023 deadline back by two months. Sellers must generate a new secret in the Developer Console, replace the LWA_CLIENT_SECRET in their code or AWS Secrets Manager, test token retrieval via https://api.amazon.com/auth/o2/token, and deactivate the old secret before the new date to avoid API suspension.
Overview
Amazon has extended the cut‑off for rotating Login With Amazon (LWA) client secrets that are older than 180 days. The new deadline is May 31 2023, pushing the original March 27 2023 target back by two months. Sellers must still replace outdated secrets or risk authentication failures that can halt order processing, advertising, and fulfillment API calls.
Key Points
- Extended deadline — All LWA applications with secrets older than 180 days must be updated by May 31 2023 instead of the previously announced March 27 2023 date.
- Uniform grace period — The revised timeline applies to sellers in North America, Europe, and Asia‑Pacific, removing any regional timing gaps.
- Process unchanged — The steps for creating a new secret, updating code, and testing remain exactly the same; only the calendar date has moved.
- Ongoing compliance checks — Amazon will continue to scan for overdue credentials after the new deadline and may suspend API access for non‑compliant apps.
- Expanded support — New documentation, step‑by‑step videos, and a dedicated help‑desk channel are now available to guide sellers through the extended window.
How LWA Credential Rotation Works
- Generate a new client secret — Sign in to the Amazon Developer Console, open the affected LWA application, and click “Create new secret.” For example, a seller who runs a custom order‑tracking dashboard receives a 32‑character string that will replace the old secret.
- Replace the secret in your integration — Update the configuration file, environment variable, or secret‑management store that your code references. A typical Node.js service might keep the secret in an AWS Secrets Manager entry called
LWA_CLIENT_SECRET; the seller would edit that entry with the newly generated value. - Test the authentication flow — Send a sandbox request to Amazon’s token endpoint (
https://api.amazon.com/auth/o2/token) using the new secret and confirm that a valid access token is returned. For instance, an inventory‑sync script should successfully obtain a token before calling the Listings API.
Analysis & Recommendations
Why This Matters
If a seller’s LWA secret is older than 180 days after May 31 2023, Amazon will block API access, stopping order processing, advertising and fulfillment operations. The extra eight‑week window eases scheduling but does not remove the compliance requirement, making timely rotation essential.
Key Takeaways
- Deadline for rotating LWA secrets older than 180 days is now May 31 2023 (previously March 27 2023).
- The new timeline applies uniformly to sellers in North America, Europe, and APAC.
- Rotation steps remain unchanged: create a new secret in the Developer Console, update LWA_CLIENT_SECRET (e.g., in AWS Secrets Manager), test the to...
- Amazon will scan for overdue credentials after the deadline and may suspend API access for non‑compliant apps.
Recommended Actions
- →Log into Amazon Developer Console > LWA application > Create new secret; copy the 32‑character value.
- →Update the secret in your integration (e.g., edit the AWS Secrets Manager entry named LWA_CLIENT_SECRET) and redeploy the service.
- →Send a sandbox request to https://api.amazon.com/auth/o2/token using the new secret to verify token issuance, then delete or disable the old secret...
Comments
Join the discussion
Log in or create an account to share your thoughts on this update.
No comments yet. Be the first to share your thoughts!