Amazon Selling Partner API · KEYXE integration design
Seller Data Access with a Clear Purpose.
The Amazon Selling Partner API supports authorized software workflows for selling partners. KEYXE’s intended scope includes sales reporting, operational visibility, inventory insights, catalog context and permitted financial reporting.

Intended scope
What KEYXE would read, and why
API families are indicative. Roles and operations are verified against Amazon’s current documentation before implementation, and nothing is requested without a specific customer-facing use.
| User benefit | API / report family | Usage purpose | Read / write | Sample UI | Status |
|---|---|---|---|---|---|
| Daily sales, units and traffic by product | Reports API — sales and traffic report | Seller Analytics dashboards and trends | Read | View | Not yet approved by Amazon |
| Order counts, statuses and fulfillment channel | Orders API (current version) — without buyer data sets; order reports | Orders & Reports overview | Read | View | Not yet approved by Amazon |
| Available, inbound and reserved stock; stock movements | FBA Inventory; inventory ledger reports | Inventory Intelligence | Read | View | Not yet approved by Amazon |
| Product context and listing issues for the seller’s own SKUs | Catalog Items; Listings Items (read only); Product Type Definitions | Catalog & Finance | Read | View | Not yet approved by Amazon |
| Fees, refunds and settlements | Finances API; settlement reports | Gross-to-net reporting aids | Read | View | Not yet approved by Amazon |
| Brand search insights (eligible brand owners only) | Brand Analytics reports | Brand insights | Read | View | Not yet approved by Amazon |
| Report-ready notifications | Notifications API (where the scope is valid) | Timely report processing | Read | View | Not yet approved by Amazon |
| Listing or catalog changes | Not requested | Out of the initial scope | Write — not planned | View | Planned |
The minimal role set under consideration contains only non-restricted roles. Restricted roles that unlock buyer personal information are not requested.
Authorization lifecycle
From approval to disconnection
- Application approval. Amazon reviews KEYXE as a public developer application and approves specific roles. Not yet approved.
- Seller authorization. A seller starts the connection from KEYXE, signs in on Amazon’s website and grants consent. A one-time anti-forgery value protects the round trip.
- Server-side credentials. The authorization code is exchanged on KEYXE’s server for a refresh token that is encrypted at rest, never shown to the browser, and bound to one organization.
- Reconnection and revocation. Expired or revoked access is shown as disconnected. The seller can disconnect at any time; data is then deleted according to policy and Amazon’s requirements.
Amazon provides a sandbox for development. Sandbox responses are test data and are never presented as a seller’s real account. Production access is configured separately.
KEYXE’s plans cover selling partners (third-party sellers). Vendor support is not in scope and would be considered only if a real use case and approval exist.
- Buyer names, addresses, emails or phone numbers
- Write access to listings, prices or shipments
- Every available role “just in case”
Seller authorization is not enabled. KEYXE does not redirect to Amazon, show a “connected” state or collect any Amazon credential until an approved, tested flow exists.
See the seller use cases.
Every row in the table above links to a working sample view built on synthetic data.