Ownership and partners

How to give an agency or tool access to Seller Central without giving away control

A brass key resting on a blank card in front of an open kraft envelope, with a sprig of green leaves beside it
Short answer

Never share your primary login. Invite your own staff as employees under Settings, User Permissions, with the lowest permission each job needs. Authorize agencies, freelancers and consultants as service providers from their authorization link, limited to the roles and countries they need, for 365 days. Tools connect through app authorizations you can disable in Manage Your Apps. Keep Amazon Ads Admin and the Brand Registry Rights Owner role in-house.

  • Amazon's help gives anyone outside your organization, including agencies, contractors and consultants, Service Provider access: managed under Manage Services and valid for 365 days (checked September 25, 2026).
  • Amazon is asking sellers, on a rolling basis and with a deadline, to reauthorize each service provider; the new authorization replaces all of that provider's previous access.
  • Sellers revoke an SP-API app under Apps and Services, Manage Your Apps, Disable authorization. Amazon deactivates an unrenewed app only after 365 days without any API call.
  • Amazon Ads has Admin, Editor, Viewer and Custom levels. Admin adds payment settings, user management and account linking to Editor's rights, and a third-party app gets the same access as the user who authorized it.
  • Brand Registry gives Rights Owner and Administrator to the trademark owner's account at enrollment, and Amazon says to assign protection roles only to employee or other internal accounts.
  • Every Seller Central user must have two-step verification, and the Business Solutions Agreement makes the seller responsible for any action taken under its password.

Most brands still grant access the way they did in their first year: someone asks, and someone shares a login. Amazon now has a separate route for each kind of outside help, and it is moving agencies onto a new one. This guide covers the four places access lives (Seller Central users, app authorizations, Amazon Ads and Brand Registry), what each partner should get, and a quarterly review. Every Amazon fact links to Amazon's own page, checked on September 25, 2026.

It assumes you stay the seller. If a partner would buy your stock and sell it under its own account, access works differently; our comparison with Pattern explains that model. If you are replacing an agency, how to switch Amazon agencies without losing your data covers the handover, and the permission steps live here.

What access should each kind of partner get?

Least privilege means each partner gets its own identity, only the roles its work needs, only the countries it works in, and an end date. Four things never leave your company: the primary user login and the phone or authenticator app behind its two-step verification, Admin on your Amazon Ads account, the Rights Owner and Administrator roles in Brand Registry, and the email address your seller account is registered to. The table applies that rule to the partners brands usually bring in; the sections below link Amazon's source for each cell.

Who needs accessSeller CentralAmazon AdsBrand RegistryWhen access ends
Full-service agency (listings, catalog and ads)Service Provider authorization in Manage Services, with only the roles in its scope and only the countries it runsEditor, through its manager account or as named users. Admin stays with your staffNone. It builds A+ Content in your Seller Central account and your Brand Store in your Ads accountAfter 365 days unless you reauthorize; remove it the day the contract ends
Advertising (PPC) agencyNone, or a Service Provider authorization limited to the reports it needsEditor, or Custom limited to campaign tools. No payment settings, no user managementNoneUnlink its manager account and remove its users at the end
Brand protection firmNoneNoneRegistered Agent, the role for third parties that report IP violations for a trademark ownerRemove the role when the engagement ends
Software tool (repricer, analytics, inventory app)App authorization through Login with Amazon, listed in Manage Your Apps. Choose tools that request only the SP-API roles their features use. No user loginIf it touches ads: authorized from a separate Amazon user that holds only the level the app needsNoneWhen you disable it: an app that keeps calling Amazon's API keeps its access
One-off diagnostic or auditApp authorization only, or reports your team exportsViewer, or nothingNoneDisable it when the report arrives
Freelancer or virtual assistantService Provider authorization: Amazon counts contractors as externalViewer or Editor, by taskNoneAfter 365 days, or the day the work ends
Your own employee (for comparison)Employee user in Manage Employees, set per permission areaViewer, Editor or Admin, by jobRights Owner and Administrator for trusted staff only; two AdministratorsNo expiry: remove them the day they leave

Two rows surprise people. Amazon puts freelancers on the service provider side, and a provider must be registered in Solution Provider Portal, with each person verified, before you can authorize it; if yours is not, do not work around it with your login. And an advertising agency that wants to see sales and stock needs view access to reports, not a login that can edit listings and prices.

Why should you never share your primary Seller Central login?

The primary user is the person who registered the account. Amazon calls that user the account administrator, with access to every page and feature (Set and edit user permissions, checked September 25, 2026). Share that login and you share everything: payouts, deposit methods, user permissions and the power to invite more users. The same page says a seller account cannot be transferred; if the business changes hands, the new owner should open a new account. So the primary user should be someone on your payroll, on a company email address, never an agency's inbox.

Two-step verification makes sharing worse, not safer. Amazon's two-step verification FAQ says every Seller Central user must have it enabled, that it is tied to each sign-in, and recommends a separate sign-in for everyone in the account (checked September 25, 2026). It names the risks of sharing: someone who leaves with the credentials can still reach your seller account and the buying account linked to it, including card details, and work stops whenever the person holding the code device is away.

The contract points the same way. The Business Solutions Agreement makes you "solely responsible for any use of or action taken under your password," and Amazon's Acceptable Use Policy tells developers and service providers not to request or share Seller Central usernames or passwords (section 3.3, both checked September 25, 2026). A shared login also erases the trail, because every change looks like yours. If an agency or tool asks for your password, it has not set up the routes Amazon provides. Our guide to Amazon's Agent Policy applies the same rule to AI tools.

How do you add a user with the right permissions?

Seller Central has two doors, and the right one depends on whether the person works for you. If an agency sits in Manage Employees as a secondary user today, expect that to change: Amazon's FAQ tells such providers that their sellers will reauthorize them through the new service provider flow. Amazon's page on authorizing a service provider sets out the split (checked September 25, 2026):

What differsEmployee accessService Provider access
WhoYour own staffAnyone outside your organization: agencies, contractors, consultants and service businesses
How it startsYou invite them under Manage EmployeesThe provider's authorization link, or its listing on Service Provider Network
What they getThe permissions you set, area by areaOnly the roles Amazon approved for the provider's service; you can remove roles and limit countries
How longUntil you remove them365 days, then reauthorization
Where you manage itManage EmployeesManage Services

Employees. From the Settings menu, select User Permissions, then Manage Employees and Invite Employee. The person accepts by email with their own Amazon sign-in and their own two-step verification. Set each permission area to the lowest level that lets them do the job, and raise it later if needed. Be careful with the User Permissions page itself: Amazon says an employee who gets View and edit permission there becomes an administrator who can manage other users. Setting permissions needs the Professional selling plan.

Agencies, freelancers and consultants. The provider sends you an authorization link, or you authorize it from its Service Provider Network listing. You see the roles Amazon approved for its service category, can remove any you do not want, and can limit access by country or region before you choose Authorize Provider. Only the account owner or an administrator can authorize, and a request from Service Provider Network waits for the provider to accept it. Access lasts 365 days, with reminders before it expires. If a role the agency wants is missing, Amazon's Solution Provider Portal FAQ explains why: some Seller Central roles are for employees only. Do not add the agency as an employee to get around that.

Removing a provider works from Manage Services and takes effect at once (Remove a Service Provider's account access, checked September 25, 2026). Amazon warns that the provider's automated processes and integrations stop, and that removal does not cancel your contract. It cannot be undone: to restore access, you authorize the provider again from the start. So remove access the day the contract ends, after the handover, not the day you decide to leave.

How do API apps and tools get access, and how do you review them?

Software should never sign in as you. Tools reach your data through Amazon's Selling Partner API (SP-API): you approve a public app through OAuth with Login with Amazon, from the vendor's website or the Selling Partner Appstore, and it never sees your password (Authorize Applications, checked September 25, 2026). Every authorized app is listed in Seller Central under Apps and Services, Manage Your Apps; to cut one off, choose Disable authorization and confirm. Amazon's docs say only the selling partner can revoke an app's authorization (Revoke Authorizations, updated September 9, 2026, checked September 25, 2026).

What an app can do depends on its roles, such as Product Listing, Pricing, or Finance and Accounting. A few are marked restricted because they require sensitive information, which can include buyers' personal data; Amazon says operations under the Direct-to-Consumer Shipping role use it to enable shipping (Roles in the Selling Partner API, checked September 25, 2026). The Acceptable Use Policy tells developers not to request data their app does not need (section 3.8). So ask every vendor for its role list, with one reason per role. A profit dashboard has no reason to ship orders.

Do not count on old apps to lapse. Amazon's docs say sellers must reauthorize a public app every 365 days, or whenever it adds a role, from Manage Your Apps (Renew Authorizations, updated September 15, 2026). But its Seller Authorizations FAQ says Amazon periodically deactivates only authorizations that have gone over 365 days without renewal and without a single API call (both checked September 25, 2026). A tool that keeps calling keeps its access, whether anyone still uses it or not. Software built for your company alone can run as a private app that your own organization self-authorizes, and it needs reauthorizing only when it adds a role; our SP-API MCP server guide covers AI assistants connected the same way.

How do you give an agency Amazon Ads access?

Amazon Ads has its own user list, separate from Seller Central, so an agency with tight Seller Central roles can still hold far too much on the ads side. Your Brand Store lives there too: Amazon's Brand Stores page tells brands to sign in to the advertising console to build one. So an agency that runs your ads or your Store needs a user on your Ads account, and that user's level decides what it can change. Amazon's account permissions page defines four levels for sponsored ads advertisers (both checked September 25, 2026):

LevelWhat it can doWho should get it
AdminView and change payment settings, manage users and link accounts, plus everything belowTwo people on your payroll
EditorCreate and edit campaigns, and view billing history and reportsThe agency's campaign managers
ViewerView campaigns, billing history and reportsFinance, leadership, an audit or a diagnostic
CustomAccess to specific advertising applications only, for example payment settings and billing history for financeAnyone whose job covers one tool

Agencies often work from a manager account, which lets them oversee many advertiser accounts with one sign-in (Understand manager accounts). When an agency that does not administer your account asks to link it, Amazon sends the request to your account's administrator to review and assign permissions (Add accounts to your Manager account, both checked September 25, 2026). That review is where you choose Editor, not Admin. You can also unlink a manager account yourself, under Administration, Account access and settings, Manager accounts. One exception on the same page: an Amazon DSP advertiser account created under a manager account, with Admin linking permission, cannot be unlinked. If you buy DSP, have that account created under a manager account your company controls.

Bid tools built on the Amazon Ads API are the easiest place to over-grant. Amazon says a third-party app gets the same access as the user who authorized it, across every advertiser account that user can reach. Its advice: authorize the app from a separate Amazon user that holds only what the app needs, such as Editor limited to campaign management (Manage third-party apps with the Ads API, checked September 25, 2026). Admins see each app and its authorizing user on the Third-Party Applications tab; only that user can remove the app, or you remove the user. Amazon notes you may also need to ask the vendor to delete data it already holds.

Who should hold the Brand Registry rights-owner role?

Brand Registry has two kinds of roles. The protection roles are Rights Owner, Administrator and Registered Agent; the selling roles are Brand Representative and Reseller (What are Brand Registry roles?, Amazon, April 23, 2025, checked September 25, 2026). Amazon assigns Rights Owner and Administrator automatically to the account of the trademark owner who enrolls the brand. Rights Owner gives access to the protection benefits, such as the Report a Violation tool. Administrator decides who else gets which role, from the gear icon and User Permissions in Brand Registry.

Amazon's own guidance answers the question. It says to "only assign protection roles to employee accounts, or other accounts internal to the brand," and recommends more than one Administrator. So Rights Owner belongs on the account of someone in your company, ideally whoever handles your trademarks, and two employees should be Administrators. The exception is an outside firm that enforces your trademark: Registered Agent exists for third parties a trademark owner has authorized to report suspected IP violations. An agency that builds your A+ Content needs no Brand Registry role; it works inside your Seller Central account, which should hold the Brand Representative selling role.

Two checks follow. If an agency, a former employee or a founder's personal login enrolled the brand, that login holds Rights Owner and Administrator; ask whoever controls it to add two of your employees as Administrators, who can then remove its roles. And since July 29, 2026, Administrators assign selling roles by Account ID instead of Merchant Token (Amazon's announcement, checked September 25, 2026); the same post shows the account owner listed as "Owner" under Account Role in User Permissions. Whether the trademark is registered to your company is covered in our agency switch guide.

How do you run a quarterly access review?

Access piles up quietly. Agencies change staff, tools get trialed and forgotten, and a contractor from two years ago may still hold a role. Service provider authorizations end after 365 days unless renewed, but Amazon says employee access has no expiry, and an app that keeps calling Amazon's API keeps its access. Block an hour in the first week of each quarter, and again whenever someone leaves, and walk through these six places in order. The first row comes first because every other fix depends on who controls the account.

Where to lookWhat to checkWhat to change
Seller Central: User Permissions, the user shown as Owner under Account RoleThe owner is a current employee on a company email addressFix this before anything else
User Permissions, Manage EmployeesEveryone still works for you; who holds View and edit on User Permissions, since they are administratorsRemove leavers; lower rights nobody uses
User Permissions, Manage ServicesEach provider has a live contract; its roles and countries match the scopeRemove finished engagements; reauthorize only current ones
Apps and Services, Manage Your AppsEvery app has a named owner on your team and is still in useDisable authorization for the rest
Amazon Ads: Administration, Account access and settingsAt least two employees are Admin; agencies are Editor or lower; each app's authorizing user still works for youUnlink finished agencies; remove unused apps; ask vendors to delete data
Brand Registry: gear icon, User PermissionsRights Owner and Administrator sit only on employee accounts; at least two Administrators; each Registered Agent is under contractRemove roles from anyone outside the company
  • Keep a one-page access register: who, which account, which role, why, and the end date.
  • Change the primary user's password, and check its two-step verification devices, if the login was ever shared.
  • Read Amazon's reauthorization notices inside Seller Central, and reauthorize only providers you still use.
  • Once a year, ask each app vendor which roles it uses and why.
  • Record each review: the date, who ran it and what changed.

Access is half of keeping control. The other half is noticing what goes wrong between reviews: a new seller on your listing, a lost Buy Box, stranded inventory. The quarterly review catches stale access; monitoring catches problems in between. Our account health agent page describes the monitoring we build and deploy on your own accounts, which steps follow fixed rules and which use a model, and what comes back to your team for a decision.

Who can help you set this up?

Ecomsellertool is a tech agency that grows brands through technology. We deploy Ecomsellertool Growth OS on your own seller and ad accounts and build the custom software and AI agents your operation needs on top, so you stay the seller. You keep your accounts, your data and the custom code we build; the Growth OS base is licensed to you. We have built on Amazon's seller APIs since 2017.

Hold us to this guide too: before you connect anything, ask us which access we need, at which level and why. To see where your Amazon account loses money first, start with the free 24-hour diagnostic: you connect Amazon with Login with Amazon, no password shared, and get a report within 24 hours of connecting, on business days. We only read data; we never change listings, prices, stock or ads, and you can revoke the access at any time in Seller Central. Or schedule a call from the card below.

  • Seller Central
  • User permissions
  • Amazon Ads
  • Brand Registry
  • SP-API
  • Agencies

Frequently asked questions

My agency says it needs my Seller Central password. Is that normal?

No. Amazon's Acceptable Use Policy tells developers and service providers not to request or share Seller Central usernames or passwords, and Amazon's help routes agencies, contractors and consultants through Service Provider access instead. The Business Solutions Agreement also makes you responsible for any action taken under your password. Ask the agency for its authorization link, review the roles it asks for, and authorize only those.

Amazon sent me a notice to reauthorize my agency. What happens if I ignore it?

Amazon's Solution Provider Portal FAQ describes the change: sellers get a notice with a deadline, and reauthorize each provider under User Permissions, Manage Services. If you do not reauthorize by the deadline, the provider loses access until you authorize it again. Go to Manage Services yourself rather than following a link in an email, and reauthorize only the providers you still work with.

Can I still add my freelancer or virtual assistant as an employee user?

Amazon's help says employee access is for people inside your organization, and that contractors and consultants get Service Provider access. That route needs the freelancer registered in Solution Provider Portal, and Amazon says each individual who accesses seller accounts must be verified. It takes some setup, but the access ends after 365 days unless you reauthorize it, and it sits in Manage Services, where you can see and remove it.

What happens to my data when I remove a tool or agency?

Removing a service provider in Seller Central takes effect at once: it can no longer see your data or act for you, its automated processes and integrations stop, and your contract is not canceled. Disabling an app in Manage Your Apps revokes its authorization. For data a vendor already holds, Amazon's Ads help says you may need to ask it to delete that data, so send the same written request to every tool and agency you remove.

How many administrators should my accounts have?

At least two people on your payroll in each system, so that one person leaving never locks you out. Amazon recommends more than one Brand Registry Administrator. In Seller Central, anyone you give View and edit permission on the User Permissions page becomes an administrator, so keep that list short. In Amazon Ads, keep Admin with your own staff and give agencies Editor.

Should my agency open the seller account or enroll the brand for us?

Let it help, but do the setup from your company's own login. Amazon says a seller account cannot be transferred; if the business changes hands, the new owner should open a new account. Brand Registry gives Rights Owner and Administrator to the account that enrolls the brand. Use a company email address and a company-controlled phone or authenticator app for two-step verification.

How we research, fact-check and compare: our editorial standards. Spot an error? Email hello@ecomsellertool.com and we will correct it.

Jaimin Dholakia, founder of Ecomsellertool
Jaimin Dholakia · Founder
Schedule a call

Turn what you just read into a plan for your brand.

Enter your email, connect your Amazon account with Login with Amazon, on Amazon’s own consent screen (we only read data; we never change listings, prices, stock or ads), and get a free report of what is going wrong within 24 hours of connecting, on business days. Prefer to talk it through? Schedule a call with the team that built these systems.

Free · 30 minutes · Pick any open slot