Amazon SP-API OAuth

What is Amazon SP-API OAuth?

Amazon's Selling Partner API (SP-API) uses OAuth 2.0 to securely authorize third-party applications to access seller data. When you connect your Amazon account to Pilot Partners S.L., you go through a secure authorization flow managed by Amazon.

How it works:

1. You click "Connect Amazon Account" on our platform.

2. You are redirected to Amazon's login page (you never share your password with us).

3. Amazon shows you the permissions we are requesting.

4. You approve or deny the request.

5. If approved, Amazon sends us a secure token that allows limited access to your data.

6. We never see or store your Amazon password.

Permissions We Request

We request only the minimum permissions needed to deliver our services. Each permission (role) is listed below with its purpose:

PermissionWhat it accessesWhy we need it
Inventory and Order TrackingOrders, history and stock levelsAnalyse sales performance, prevent stock-outs and support inventory management
Product ListingProduct listings, catalogue and A+ ContentOptimise titles, bullets, keywords and A+ Content with our Listing Builder
PricingOwn and competitor pricingPricing strategy, Buy Box tracking and deviation detection
Amazon FulfillmentFBA inventory, shipments and replenishmentReplenishment forecasting and FBA stock-out prevention
Buyer SolicitationAmazon official review requestSend Amazon’s official review request after order delivery
Selling Partner InsightsAccount health and performanceProactive compliance alerts and account health monitoring
Finance and AccountingTransactions, fees and settlementsBuild the real P&L of the channel
Brand AnalyticsSearch Query Performance and market dataCompetitive position analytics, estimated share and repeat purchase behaviour
Buyer CommunicationBuyer messagingManage post-purchase communication and buyer support on behalf of the selling partner
Direct-to-Consumer Shipping (restricted)Order shipping addressGenerate labels and manage FBM order shipping on behalf of the selling partner
Tax Invoicing (restricted)Buyer tax dataConnect the selling partner’s invoicing system with Amazon to issue and upload compliant invoices

Three of these permissions (Buyer Communication, Direct-to-Consumer Shipping and Tax Invoicing) involve access to buyer personal data. We request only those matching functionality we actually deliver, we access such data through short-lived Restricted Data Tokens, we process it solely on behalf of the selling partner, and we delete it within a maximum of 30 days from order delivery. We never use it for our own purposes nor share it with unauthorised third parties.

What We Do With Your Data

Listing optimization: We analyze your product data and generate optimized listing content using AI.

Image generation: We use your product information to create professional product images.

Analytics: We aggregate your sales, advertising, and inventory data to provide actionable insights.

AI Processing: Some product data (titles, descriptions, images) is processed by our AI providers (OpenAI, fal.ai) to generate content. We only send the minimum data required and never share personally identifiable or financial information with AI providers.

We do not use your data for any purpose other than providing our services to you.

Your Control

You have full control over your Amazon connection at all times:

Revoke access: Go to Amazon Seller Central > Apps & Services > Manage Your Apps. Find "Pilot Partners S.L." and click "Revoke".

What happens when you revoke: We immediately invalidate your tokens. All Amazon SP-API data is deleted from our systems within 30 days. Your Pilot Partners S.L. account and contact information remain unless you request deletion.

Request data deletion: Email hello@pilot-partners.com with subject "Data Deletion Request". We process all deletion requests within 30 days.

Security Measures

We take the security of your Amazon data seriously:

  • Token encryption: All OAuth tokens (access and refresh) are encrypted at rest using AES-256.
  • TLS encryption: All data in transit uses TLS 1.2 or higher.
  • Access controls: Only authorized personnel can access token storage, with role-based access control (RBAC).
  • Audit logging: All access to SP-API data is logged for security review.
  • Token rotation: Access tokens are automatically refreshed per Amazon's guidelines; we never store expired tokens.
  • Secure infrastructure: Our backend runs on SOC 2 certified infrastructure providers (Google Cloud Platform and Vercel). Pilot Partners S.L. does not hold its own SOC 2 certification.