Amazon has simplified how you grant an agency, tool or freelancer access to your Seller Central account. Amazon announced the change in its public SP-API changelog on 19 August 2026: sellers now grant permissions in three steps, and the roles on offer are scoped automatically to the service categories that provider is qualified for. The part most sellers have never registered: every authorization expires after 365 days, and it has to be granted again.
What changed
All of the below is confirmed on Amazon’s own publicly-accessible developer documentation and changelog.
- Three ways in, all initiated by the provider or by you. A provider shares an authorization link generated from the Solution Provider Portal, you hit Authorize Now on their Service Provider Network listing, or the request arrives in the manage-service-requests dashboard. The old multi-step invite is not the route any more.
- Roles are scoped to what the provider is qualified for. Amazon’s wording is that roles “are automatically scoped to your qualified service categories” — and that if a provider needs access beyond those, “you must complete qualification for them first.” The provider cannot ask you for a role it has not been approved to hold.
- You can cut it down before you confirm. The authorization screen shows the roles that provider was approved for, and Amazon’s documentation says you can adjust individual roles or restrict access before confirming. There is also a country/region filter, so access can be scoped geographically.
- It expires. Amazon’s documentation is explicit: “the selling partner must reauthorize your public application every 365 days, or anytime you add a role to your application.” The authorization is good for 365 days and then it is not.
- Adding a role restarts consent. If a provider adds a role to its application, you reauthorize — regardless of where you are in the 365 days.
- For SPN-originated grants, the provider has to close the loop. If you authorize from a Service Provider Network listing, the provider must confirm the service request before the authorization goes active. Your click is not the last step.
What we are not printing
Trade write-ups are circulating specific dates for a broader re-consent wave this autumn, including a hard deadline for providers to sort their role coverage. We could not confirm a single one of those dates on a publicly accessible Amazon page, and we could not find a second outlet that reported them independently rather than restating the first. So we are not printing them. Treat any date you see attached to this story as unverified until it shows up in your own Seller Central notifications.
Separately: search this topic and you will mostly surface articles citing April 2025 and August 2025. That is the original Solution Provider Portal migration, when providers had to register at all. Different event, a year earlier. Do not plan against those dates either.
What it means for a private-label seller
The security model is genuinely better than what it replaced, and that is worth saying plainly. Scoped roles, a visible list of who holds what, an expiry date, and one place to revoke. Handing a contractor a secondary user login with more access than the job needed was the old normal, and it was bad.
The cost is that the expiry is silent and the failure is silent. Nothing about a lapsed authorization looks like an outage. Your repricer stops repricing. Your PPC tool stops pulling search-term data and the last report it built just sits there looking current. Your bulk listing tool stops uploading. You find out because a number stopped moving, not because anything alerted you — and if that lands in the weeks you are pushing Q4 inventory and finalising listings, you will be reading a stale dashboard while you make your most expensive decisions of the year.
There is a second-order effect worth watching, and it comes straight from the scoping rule. If the new authorization only offers the roles a provider is currently qualified for, a provider that has been using a role informally — never approved for it on the portal — comes back with less access than it had. The tool will still look connected. It will quietly fail at one job. That is a worse failure than a clean disconnection, because nothing on your side reads as broken.
What this doesn’t tell you: when your specific authorizations expire, or whether Amazon is staging the transition by account. We cannot see inside your Seller Central, and the 365-day clock started whenever each grant was made — which means yours are not all going to expire together.
What to do about it
- Inventory your access this week. Seller Central → Settings → User Permissions, plus the Manage Your Apps page. Write down every provider, every app, and what each is actually for. Most accounts have at least one entry nobody left in the business can identify.
- Revoke what you no longer use. The agency you left in March does not need a live connection to your account. A re-consent moment is the cheapest opportunity you will get to clean this up, and revoking costs you nothing if you are wrong.
- Ask each provider you keep whether they are qualified on the Solution Provider Portal for the roles they actually use. That is the specific question. A provider who cannot answer it is the one that comes back with a hole in its access.
- Read the roles screen when the prompt comes. Do not click through it. The screen lets you restrict roles and scope by region before you confirm, and that is the one moment you get to. Grant what the tool needs to do its job and nothing more.
- Treat every “re-authorize your access” email as phishing until you have proven otherwise. A predictable wave of re-consent messages is exactly the cover credential thieves wait for. Start from inside Seller Central, or from the provider’s Service Provider Network listing. Never from a link in an email — including one that looks like it came from Amazon.
If nothing in your account is connected to an outside tool or agency, there is nothing here for you to do.
Sources
- Amazon SP-API changelog, “SP-API Updates: Simplified Authorization for Service Providers”, 19 August 2026 — primary, publicly accessible. The three-step flow, the three entry points, and role scoping to qualified service categories.
- Amazon SP-API documentation, “Learn How Sellers Authorize Service Providers” — primary, publicly accessible. Entry points, the role review and restrict step, the country/region filter, the 365-day validity, and the provider’s confirmation step for SPN grants.
- Amazon SP-API documentation, “Renew Authorizations” — primary, publicly accessible. The 365-day reauthorization requirement and the added-role trigger.