Amazon Selling Partner API · KEYXE integration design

Seller Data Access with a Clear Purpose.

The Amazon Selling Partner API supports authorized software workflows for selling partners. KEYXE’s intended scope includes sales reporting, operational visibility, inventory insights, catalog context and permitted financial reporting.

Not yet approved by AmazonSeller authorization: not enabled
Illustration of seller analytics cards for sales, orders, inventory and reports, labeled as sample data.

Intended scope

What KEYXE would read, and why

API families are indicative. Roles and operations are verified against Amazon’s current documentation before implementation, and nothing is requested without a specific customer-facing use.

Planned SP-API use cases
User benefitAPI / report familyUsage purposeRead / writeSample UIStatus
Daily sales, units and traffic by productReports API — sales and traffic reportSeller Analytics dashboards and trendsReadViewNot yet approved by Amazon
Order counts, statuses and fulfillment channelOrders API (current version) — without buyer data sets; order reportsOrders & Reports overviewReadViewNot yet approved by Amazon
Available, inbound and reserved stock; stock movementsFBA Inventory; inventory ledger reportsInventory IntelligenceReadViewNot yet approved by Amazon
Product context and listing issues for the seller’s own SKUsCatalog Items; Listings Items (read only); Product Type DefinitionsCatalog & FinanceReadViewNot yet approved by Amazon
Fees, refunds and settlementsFinances API; settlement reportsGross-to-net reporting aidsReadViewNot yet approved by Amazon
Brand search insights (eligible brand owners only)Brand Analytics reportsBrand insightsReadViewNot yet approved by Amazon
Report-ready notificationsNotifications API (where the scope is valid)Timely report processingReadViewNot yet approved by Amazon
Listing or catalog changesNot requestedOut of the initial scopeWrite — not plannedViewPlanned

The minimal role set under consideration contains only non-restricted roles. Restricted roles that unlock buyer personal information are not requested.

Authorization lifecycle

From approval to disconnection

  1. Application approval. Amazon reviews KEYXE as a public developer application and approves specific roles. Not yet approved.
  2. Seller authorization. A seller starts the connection from KEYXE, signs in on Amazon’s website and grants consent. A one-time anti-forgery value protects the round trip.
  3. Server-side credentials. The authorization code is exchanged on KEYXE’s server for a refresh token that is encrypted at rest, never shown to the browser, and bound to one organization.
  4. Reconnection and revocation. Expired or revoked access is shown as disconnected. The seller can disconnect at any time; data is then deleted according to policy and Amazon’s requirements.

Amazon provides a sandbox for development. Sandbox responses are test data and are never presented as a seller’s real account. Production access is configured separately.

Seller authorization is not enabled. KEYXE does not redirect to Amazon, show a “connected” state or collect any Amazon credential until an approved, tested flow exists.

See the seller use cases.

Every row in the table above links to a working sample view built on synthetic data.