KEYXE Security & Permissions

Account Control Is a Product Feature.

Access to a seller account is not the same as access to an advertising account. KEYXE treats each permission as an explicit choice and designs auditability into the workflow.

Conceptual illustration of layered access boundaries, keys, separated data compartments and an audit timeline.

Design controls

Six ways permission shows up in the product

These are the design rules for live Amazon integrations, which are not available yet. Today they shape the demo and the disabled Amazon routes in the KEYXE API.

Account owner authorization

Only the owner of a seller account or advertising account can authorize KEYXE, on Amazon’s own consent screen. KEYXE never collects Amazon passwords.

Least privilege

KEYXE requests only the roles and scopes a customer-facing workflow needs. Restricted buyer data is not part of the planned scope.

Tenant isolation

Each organization’s connections, reports and settings are separated, and every request is checked against the organization it belongs to.

Independent revocation

Seller access and advertising access are revoked separately. Revoking one never silently affects the other.

Audit trails

Sign-ins, connection changes, exports and reviewed proposals are designed to be logged with who, what and when.

Change approvals

Any future account-changing action requires explicit permission, a preview of the change and a person’s approval. Nothing runs unattended.

Example

A permissions matrix, illustrated

Viewer, Analyst and Admin are synthetic example roles. They show the intended model — they are not proof that a production role system exists today.

Example roles and abilities
AbilityViewerAnalystAdminAvailability
View demo dashboardsAllowedAllowedAllowedDemo only
Export synthetic reportNot allowedAllowedAllowedDemo only
Draft a reviewable proposalNot allowedAllowedAllowedDemo only
Approve account changeNot allowedNot allowedAllowedPlanned — not available
Connect or revoke an Amazon accountNot allowedNot allowedAllowedRequires Amazon approval

The public demo has no sign-in and no roles — everyone sees the same synthetic data. A role-based production system will be described here only once it exists and has been tested.

Three separate authorizations

Login, Amazon access and AI access are different things

  1. KEYXE sign-in (future) proves who a person is within an organization.
  2. Amazon authorization — one for seller data, another for advertising data — proves what KEYXE may read from Amazon for that organization.
  3. MCP client authorization (future) proves which tools an AI client may call, and is checked against data-use policy on every request.

What KEYXE will never do

  • Ask for your Amazon password or one-time codes
  • Treat seller consent as advertising consent, or the reverse
  • Pass Amazon credentials to an AI client or third party
  • Change bids, budgets or listings without a person approving it

Read what is live today.

The Security page separates safeguards running on this website from controls planned for live integrations.