Selling From the Beach
Deep Dive · July 2026
The safe way to share your Amazon account

Give your team the API. Keep your keys.

Your employee wants to make changes with software instead of clicking around Seller Central. This is the 10-minute setup that gives them real access: their own keys, only the permissions you tick, revocable with one delete. Written for sellers whose "developer" is an AI assistant, not a programmer.

Inside
  • The three ways sellers usually share access, and what each one costs
  • The app trick: one keycard per person, minted in your own console
  • Every click in the developer console, in order
  • The full permission checklist in plain English
  • The credential-safe AI setup, with the exact prompt your employee pastes
  • House rules you can send them word for word
10 min
one-time setup, inside Seller Central
3
strings of text you hand over
$0
per API call. Amazon never bills for it
1 delete
revokes everything when they leave
Selling From the Beach
Give your team the API · 02
Part one

The ask that started this: "Can I get API access?"

One of my employees asked me for API access this week. He updates listings: titles, images, prices, inventory. Clicking through Seller Central for every change is slow.

My first instinct was to stall. I trust the guy, obviously. But "hand an employee the keys to the Amazon account" feels like handing over the business. So before I answered, I looked at how sellers usually do this. There are two common answers, and both are bad.

Bad answer #1: share your Seller Central login

One password opens everything: listings, but also deposit settings, tax information, and user permissions. There is no audit trail; everything they do looks like you did it. And when they leave, you change the password and then re-enter it on every device and tool it ever lived in.

Bad answer #2: share the API keys your own tools run on

If you already use software on your account, you have a set of API credentials somewhere. Handing those over is worse than the password. That one token is the whole account: every marketplace, every permission your setup ever needed, and no way to tell their calls from yours. Revoking it means rotating credentials that every tool you run depends on. The day they leave becomes the day your automations break.

The fallback: just say no

Also a real cost. Your employee keeps clicking through pages that software should be handling, and you keep paying for those hours.

The third option

Amazon will mint a separate set of API credentials for each person, limited to permission boxes you tick, revocable without touching anything else you run. It sits one page deep in Seller Central, it costs nothing, and it takes about ten minutes. That is this guide.

Selling From the Beach
Give your team the API · 03
Part two

One app per person. That's the whole pattern.

The word "app" throws people off, so let's kill it early: nothing gets built, coded, or hosted. An "app" in Amazon's developer console is one registration entry whose only job is to mint credentials.

You create one app per person, named after them. Each app produces three strings of text. Those three strings are a keycard: software holding them can act on your account, within the permission boxes you ticked when you made the app.

What one keycard looks like
LWA_CLIENT_ID=amzn1.application-oa2-client.xxxxxxxx
LWA_CLIENT_SECRET=amzn1.oa2-cs.v1.xxxxxxxx
REFRESH_TOKEN=Atzr|IwEBxxxxxxxxxxxxxxxx
Three strings. No AWS keys, no server, nothing installed on your side. It works every day until the day you delete the app.

Why this shape wins

The honest caveat

Within the boxes you tick, their keycard still acts as the whole account. There is no per-product guardrail: a careless bulk listing update from them can damage listings account-wide. That risk is covered by trust, by ticking narrow boxes, and by the show-me-first rule on page 7. It is the same trade every company that gives staff real access makes.

Selling From the Beach
Give your team the API · 04
Part three · your side of the setup

Open the console, make the app.

1

Open the Developer Console

It lives at sellercentral.amazon.com/sellingpartner/developerconsole, logged into your seller account.

First visit ever? Amazon asks you to fill in a short developer profile before the console unlocks: who you are, what you'll use the API for. For a seller getting access to their own account, answer plainly. Approval can take a few days, which is the only slow part of this whole guide, so file it before you need it.

2

Create a new app client

On the console dashboard, create a new app client and fill in three things:

  • App name: the person's name, not the job. "Sam" beats "Listings Tool." Six months from now you want one glance at the list to tell you exactly whose access each app is.
  • API type: SP-API. That is the Selling Partner API, the one that covers listings, inventory, orders, and reports.
  • Business entity: Sellers. The form also offers Vendors, Shipping, and others; you are a seller, so tick Sellers.

After you save, the new app may show a "Draft" status. Ignore it. Draft apps mint working credentials; nothing more needs to be submitted or published.

Doing this for a second person later?

Same steps, another app. One app per person is the entire system: separate keycards, separate rate limits, separate off-switches. When I set this up I made one app per employee in the same sitting.

Selling From the Beach
Give your team the API · 05
Part three, continued

Tick only the boxes their job needs.

The app form shows a checklist of roles. Each box you tick is a set of doors the keycard can open. Fewer boxes, smaller blast radius. You can add a box later in Edit App if their job grows.

Here is the Sellers checklist in plain English. For a listings-and-operations person, the four marked ones are the set I'd start with.

Product Listing

Create and manage listings, including A+ content

Inventory and Order Tracking

Analyze and manage inventory and order status

Amazon Fulfillment

Ship to Amazon; FBA shipments

Selling Partner Insights

Account info and performance reports

Pricing

Set list prices, automate product pricing

Amazon Warehousing and Distribution

AWD shipments and inventory

Brand Analytics

Sales and inventory data

Finance and Accounting

Account and financial statements

Buyer Communication

Messaging to and from buyers

Buyer Solicitation

Ask buyers for feedback

Selling From the Beach
Give your team the API · 06
Part three, continued

Copy the three strings, hand them over.

3

Copy the client ID and secret

On the new app's row, click "View" under "LWA credentials." A popup shows the client ID (starts with amzn1.application-oa2-client.) and the client secret (starts with amzn1.oa2-cs.). Copy both.

4

Generate the refresh token

The third string hides one level deeper: click the dropdown arrow beside "Edit App" on the same row and pick "Authorize." On the page that opens, authorize the app against your own seller account. It displays a long string starting with Atzr|. That is the refresh token.

It shows once. If you navigate away without copying it, nothing is broken: run Authorize again and use the new one.

5

Hand them over, secret separately

Never send all three strings in one message. Email the client ID and refresh token, then text the client secret. If one channel leaks, the keycard is still incomplete.

Tell them the strings go straight into a password manager, and then into the connector's config file (next page). Never into a chat window, a shared doc, code they commit, or a screenshot.

One recurring chore, and it's yours

Every 180 days Amazon forces the client secret to be replaced. It emails you reminders, the rotation happens in your console, and it takes about two minutes. Send the new secret the same way (text), your employee swaps one line in their config, done. The other two strings never change.

Selling From the Beach
Give your team the API · 07
Part four · their side of the setup

No programmer needed. An AI assistant is the developer.

This is the part that changed recently. Amazon publishes an official connector that plugs its API into an AI assistant. The Claude desktop app runs it out of the box; your employee needs their own Claude account (a paid plan, Pro is enough). Once it's connected, they work in plain English: "change the second bullet on this listing," "what's in stock?", "prep the FBA shipment." The assistant makes the API calls.

The one rule that makes it safe

The three strings go into the connector's config file on their computer, never typed into the chat. Chat history is stored on the AI company's servers; the config file stays on their machine. The setup prompt below enforces this for them.

Day one, they paste this into their assistant and follow along:

The setup prompt they paste

"Set up Amazon's official SP-API connector (the @amazon-sp-api-release/sp-api-dev-mcp package) on this computer, step by step. I have a client ID, a client secret, and a refresh token. Never ask me to paste them into this chat: show me where they go in the connector's config file and I will type them in myself. Then call getMarketplaceParticipations to prove it works. Before anything that changes the account, show me what you are about to send and wait for my OK."

In the Claude desktop app, the config file the assistant will point them to lives under Settings, then Developer, then Edit Config, and the block they type the strings into looks like this:

The config block (Claude desktop app)
"amazon": {
  "command": "npx",
  "args": ["-y", "-p", "@amazon-sp-api-release/sp-api-dev-mcp",
           "sp-api-dev-assistant-mcp-server"],
  "env": {
    "SP_API_CLIENT_ID":     "their client ID",
    "SP_API_CLIENT_SECRET": "their secret",
    "SP_API_REFRESH_TOKEN": "their refresh token",
    "SP_API_REGION":        "na"
  }
}

If your employee lives in ChatGPT or Gemini instead, the connector needs a developer-grade setup there; the Claude desktop app is the plug-and-play path. First launch downloads the connector, so give it a few minutes. When "call getMarketplaceParticipations" comes back listing your marketplaces, they are in.

Selling From the Beach
Give your team the API · 08
Part five

The part I checked before I handed anything over.

My real worry was money. So before my employees got their strings, I pulled the full API catalog on my own account: 54 categories of endpoints. Not one of them can add or change bank accounts, deposit methods, tax settings, account settings, or user permissions.

"They can change listings but can't touch the money" is not a rule you configure and hope holds. The doors are not there. No permission box you tick creates them.

Inside the keycard's reach

Whatever boxes you ticked: listings, prices, images, inventory, orders, FBA shipments, reports. Enforced by Amazon per call.

Outside it, always

Bank accounts, payouts, deposit and tax settings, user permissions, account settings. Also ads and PPC: that is a separate system with its own separate access.

The rest of the safety model

Selling From the Beach
Give your team the API · 09
Part six

The handoff, ready to paste.

When you send the strings, send the rules with them. Here is the note for your team; take it word for word.

Paste this to your employee

"You're getting API access to the Amazon account: three strings of text, in two separate messages (the secret comes by text). Four rules. 1) They live in your password manager and the connector's config file, never in a chat window, a shared doc, code you commit, or a screenshot. 2) If you ever think they leaked, tell me the same day. Nobody will be mad; replacing them takes minutes. 3) Everything you do with them happens on the live account, so before any change, have your assistant show you exactly what it is about to send. 4) Every six months Amazon makes me replace one of the strings; I'll send you the new one and you swap one line. Setup instructions and the prompt to paste into Claude are on the sheet attached."

Questions that come up

Selling From the Beach
Give your team the API · 10
The short version

Make the app. Tick the boxes. Hand over three strings.

My team's access took one sitting to set up: one app per person, three strings each, secret by text. They drive the account in plain English through an assistant, and the keys my own tools run on never left the drawer.

The blast radius is what you ticked. The money is unreachable by design. The off-switch is one delete. Compare that to the password you were about to share: every door open, everything logged as you, and a password change on every device the day they leave.

Ten minutes. Go set up the first one.

Selling From the Beach
Deep Dive · July 2026 · The companion one-pager is the version you hand your employee.
Subscribe free at www.sellingfrom.co/newsletter · 6,500+ sellers weekly
The access lives in an app you own. When someone leaves, delete their app. Their strings die that minute and nothing else you run is touched.