Marketplace changes

Walmart Delegated Access keys stop working: how sellers reconnect apps with OAuth 2.0

Kraft mailer packages arcing in from several directions into one white tray, a picture of orders from many channels arriving in one place
Short answer

Walmart retired the creation of new Delegated Access keys on July 30, 2026, and existing keys work only until the end of September 2026. To keep orders, stock and prices syncing, reconnect every app that uses one: in Seller Center, open Apps, find the provider in App Listings, select Connect and authorize it with OAuth 2.0. Then revoke the old key and test order and inventory sync.

  • Walmart stopped approved Solution Providers from creating new Delegated Access keys on July 30, 2026 (Walmart Developer Portal, checked September 25, 2026).
  • Existing Delegated Access keys keep working until the end of September 2026. After that, Walmart says all of them stop functioning.
  • Sellers reconnect in Seller Center: Apps, then App Listings, then Connect, then Authorize on the provider's site. The connection uses OAuth 2.0.
  • An App Store authorization lasts 12 months. Sellers renew it, or revoke an app, from Connected Apps in Seller Center.
  • Walmart's notice covers Delegated Access keys only. It does not mention the seller's own API keys on the Developer Portal's API Keys page.
  • Walmart will remove the Delegated Keys section from the Developer Portal, so record which providers hold keys before it goes.

If a repricer, order tool, listing app or agency reaches your Walmart account through a Delegated Access key, that connection has days left. Walmart's developer docs say existing keys work only until the end of September 2026. After that, orders, stock, prices and tracking stop moving between Walmart and the tool, while shoppers keep buying and Walmart keeps measuring how you ship. This post is a checklist for the next few days: find every connection, reconnect it through the Walmart App Store with OAuth 2.0, revoke what is left and test the syncs that matter.

If you are not selling on Walmart yet, start with how to sell on Walmart as an Amazon brand. This post is for sellers already running there, and for the agencies and developers who connect to their accounts. Sellers get the checklist, the tests and the Seller Center stopgaps; providers get Walmart's migration steps in the section for agencies and developers.

What is changing, and when?

Delegated Access let a seller create a separate Client ID and Client Secret for each provider the seller worked with, in Walmart's Developer Portal, with permissions set per area such as items or orders. The provider used those keys to call Walmart's APIs on your behalf. Walmart is replacing them with OAuth 2.0 seller authorization through the Walmart App Store in Seller Center, which it calls a more secure and scalable model (Walmart's Delegated Access notice, checked September 25, 2026).

WhenWhat happensWhat it means for you
July 30, 2026Approved Solution Providers can no longer create new Delegated Access keysNew connections already go through the App Store
Until the end of September 2026Existing Delegated Access keys keep workingReconnect every provider that still uses one
After September 30, 2026Walmart says all Delegated Access keys stop functioningAnything not reconnected loses its API access
No date givenThe Delegated Keys section is removed from the Developer PortalWrite down which providers hold keys now
12 months after you authorizeThe App Store (OAuth 2.0) authorization needs renewingRenew it from Connected Apps before it lapses

One trap: Walmart's seller guide to connecting a provider in Seller Center still tells sellers they can keep using delegated keys "for now" (checked September 25, 2026). That guide gives no dates. The developer notice does: its FAQ says existing keys work until September 2026 and all Delegated Access keys stop functioning after that. If a provider quotes the seller guide to you, point them to the developer notice and ask for their migration date.

Who is affected?

Every seller who created a key for a provider in the Developer Portal, and every provider that still calls Walmart with one. Walmart's notice covers Delegated Access keys only. It does not mention your own seller API keys (the Client ID and Client Secret on the Developer Portal's API Keys page), and it does not touch apps you already connected through the App Store. Many accounts have a mix, so sort each connection by how it got into your account.

How the tool got inHow to recognize itHit by the September cutoff?What to do
A Delegated Access key you created for a Solution ProviderYou used "Add New Key For A Solution Provider" in the Developer Portal and sent the provider a Client ID and Client SecretYesReconnect through the App Store, then revoke the key
An app connected through the App StoreIt is listed under Connected Apps in Seller CenterNoNote its 12-month renewal date
Your own API keys, shared with a developer or toolThey use the Client ID and Client Secret from your API Keys pageNot named in Walmart's noticeWalmart advises against sharing them; move the job to an App Store app or an integration you control
Your own in-house integrationYour team calls the API with your own keysNot named in Walmart's noticeNothing for this deadline; confirm it refreshes its access tokens
An agency that works inside Seller Center with no API accessIts staff sign in as users on your accountNoNothing

The third row deserves a closer look. Walmart's OAuth FAQ tells sellers not to give their API keys directly to Solution Providers. It says seller credentials grant full access and are shared by every user on the account, so whoever resets them cuts off every integration that uses them (checked September 25, 2026). Walmart's Delegated Access notice puts no date on that pattern, but it is the next thing to fix once the Delegated Access keys are gone.

How do you reconnect an app with OAuth 2.0?

The seller does this, not the provider: the point of OAuth is that you approve access while signed in to your own account, and the provider never sees your password. Walmart's steps, from its guide to connecting a provider in Seller Center (checked September 25, 2026):

  1. In Seller Center, open Apps in the left-hand navigation and select App Listings (direct link, sign-in required).
  2. Find the provider you already use and select Connect. Walmart sends you to the provider's site, where you create an account or log in.
  3. Read the authorization screen. The data the app asks for is listed there.
  4. Tick the box if you agree to the provider's privacy policy, then select Authorize (or Decline to stop).
  5. Back in Seller Center, open Connected Apps and check the app is listed.
  6. Tell the provider you have authorized, and ask them to confirm in writing that your account now runs on the new connection.

Behind the scenes, Walmart sends the provider an authorization code, which it exchanges for an access token that lasts 15 minutes and a refresh token that stays valid for one year (Walmart's OAuth 2.0 authorization guide, checked September 25, 2026). Walmart's Seller Academy lesson says your authorization lasts 12 months and asks you to renew it before it lapses (checked September 25, 2026). The Seller Center guide adds that renewing from Connected Apps extends it for another year from the day you confirm.

If your provider is not in App Listings, ask why today. Walmart says not every provider on its approved list can be connected through the App Store yet, and a provider outside Walmart's approved list must apply for Marketplace verification first. Walmart says approval and publication may take three to five weeks (Get started as an approved Solution Provider, checked September 25, 2026), so a provider that has not started is unlikely to be listed by October 1.

Checklist: find every tool that uses your Walmart API access

Work through it in order. Finding the connections is in your hands; reconnecting and testing depend on how fast each provider answers and moves your account, so send the questions in step 1 first.

1. Find every connection

  • List every tool, agency and developer that touches Walmart data: repricers, order and shipping tools, inventory and listing software, multichannel platforms, accounting connectors, analytics dashboards, and Amazon's new multichannel tools in Seller Central if you connected Walmart there (Amazon is rolling them out gradually to US sellers, checked September 25, 2026).
  • In the Developer Portal, open My Account and the API Keys page, and write down every provider you created a Delegated Access key for. Walmart is removing the Delegated Keys section, so take a screenshot now.
  • In Seller Center, open Connected Apps and list what already runs on OAuth. Anything there you no longer use goes on the revoke list.
  • Ask every provider one question in writing: are you calling Walmart with a Delegated Access key, with our own API keys, or through an App Store connection?
  • Note anyone outside your company who holds your own API keys.

2. Reconnect

  • For each provider on a Delegated Access key, find its app in App Listings, then Connect and Authorize.
  • Before you authorize, compare the data the app asks for with the job it does for you. If it asks for more, ask why.
  • Get each provider's written confirmation, with the date, that your account has switched.

3. Revoke

  • Once a provider confirms it runs on OAuth, revoke its Delegated Access key in the Developer Portal rather than waiting for Walmart to switch it off. Walmart lists revoking a specific provider's access as a Delegated Access feature.
  • Revoke apps under Connected Apps that you no longer use. Walmart's advice is to check that page regularly.
  • If an outside party holds your own API keys, move that job to an App Store connection or to an integration you control, then reset the keys. A reset needs admin access and cuts off everything still using the old pair, so reset only when nothing you need depends on them.

4. Test, then set reminders

  • Run the tests in the table below within a day of each reconnection.
  • Put each app's renewal date, 12 months after you authorize, in the team calendar.
  • On October 1 and 2, confirm that Walmart orders still import and stock still updates. Later that week, check the Performance dashboard in Seller Center.

Walmart orders move from Created to Acknowledged to Shipped to Delivered (Walmart's Orders Management API overview, checked September 25, 2026), so those statuses are your test for the order flow.

SyncTestIt passes when
Order importWatch the next seller-fulfilled order after you reconnectIt reaches your tool or 3PL and moves from Created to Acknowledged in Seller Center
Shipping confirmationShip that order as usualSeller Center shows it as Shipped, with a tracking number that works
InventoryChange the quantity of one slow-moving SKU in your toolSeller Center shows the new quantity within the tool's normal sync interval
PricesPush one price change you planned anywayThe new price shows in Seller Center with no error
ItemsSend one content updateThe feed shows as processed with no errors
ReportsOpen your dashboards the next dayWalmart figures include sales from after the reconnection

What breaks if you miss the deadline, and how do you fix it?

Losing a key cuts a tool's API access; it does not stop shoppers ordering. The tool can no longer read orders or send stock, prices and tracking, and Walmart keeps measuring you in the meantime. Its seller performance standards ask for a cancellation rate of 2% or below, on-time delivery of 90% or above, valid tracking of 99% or above and late shipments of 5% or below, measured over 30 or 60 days. Missing them can lead to suppression, suspension or termination (checked September 25, 2026).

What stopsWhat happens nextStopgap in Seller Center
Order import and acknowledgmentOrders wait in Created and never reach your warehouse or 3PL. Missed ship dates can end in auto-cancellations, which count toward the 2% cancellation rateAcknowledge orders in Seller Center and send them to your warehouse by hand
Shipping and tracking uploadOrders ship but are not marked shipped, which hurts late-shipment and valid-tracking ratesSelect Ship item on each order and add its tracking
Inventory syncWalmart keeps showing the last quantity your tool sent: you oversell items that ran out, and Walmart lists out-of-stock as a seller-accountable cancellation driver, or you miss sales on items you restockedUpload the Inventory template from Catalog, Update Items, Update with file
Price updates and repricingPrices freeze at their last valueEdit prices in Seller Center
Item and content feedsNew items and edits stop publishingHold changes, or set items up in Seller Center
WFS itemsWalmart fulfills WFS orders itself, so they keep shipping. Tools that read WFS stock or plan WFS inbound stop updatingCheck WFS stock in Seller Center

Walmart says a bulk inventory file can take from 15 minutes to four hours to show (Update seller-fulfilled inventory in bulk, checked September 25, 2026), so the stopgap is slower than a sync. If you route Walmart orders to a 3PL or to Amazon Multi-Channel Fulfillment, the whole order-routing chain starts with that import, and a dead connection stops every step after it.

Walmart's docs do not say which error a retired key returns. Its authentication FAQ explains the two codes to look for in a tool's sync log (checked September 25, 2026): 401 means the access token is missing, malformed, expired or from the wrong environment, and 403 means the token is valid but lacks permission for that call. If either starts showing up on October 1 on a connection you have not moved, check that connection's key first.

If it has already broken, fix it in this order. Keep orders moving in Seller Center first, because cancellations and late shipments are what Walmart measures. Then reconnect the app through App Listings, ask the provider to re-sync orders and stock from the day it stopped, and check the Performance dashboard for orders that went late or were canceled during the gap.

What should agencies and developers do?

If you are an approved Solution Provider with sellers still on Delegated Access, Walmart's instruction is to migrate them to OAuth 2.0 by asking them to reauthorize with the Connect button. In practice: send each seller the App Listings steps above, store the refresh token against the sellerId that comes back with each authorization code (Walmart's OAuth 2.0 authorization guide), refresh the 15-minute access token before it expires, and move every scheduled job off the old key by September 30. Walmart points providers who need help to a support case in the Solution Provider Center.

If you are not on Walmart's approved list, the App Store route starts with an application. Walmart's process runs from sandbox testing to app registration in the Solution Provider Center (a callback URL, a login URL and the API scopes you need), then a kickoff call, a demo and a review before you can publish (Register and publish on the Walmart App Store, checked September 25, 2026). Agencies that work without API access can register an Agency listing instead.

If you built a seller's integration on the seller's own keys, Walmart's Delegated Access notice does not name those keys, but its OAuth FAQ tells sellers not to give their API keys directly to Solution Providers. Decide with the seller whether the integration becomes an App Store app, or the seller's own integration with the keys held in the seller's systems rather than yours.

Amazon's Selling Partner API uses a similar pattern. Public apps are authorized by the seller with OAuth 2.0 through Login with Amazon, and Amazon's documentation says reauthorization is required annually (Amazon's SP-API authorization docs, checked September 25, 2026). If you maintain both, one renewal calendar covers Walmart and your Amazon SP-API integrations. Our SP-API glossary entry explains the Amazon side.

Who can help you check your Walmart connections?

Ecomsellertool is a tech agency that builds marketplace integrations and operations software on brands' own accounts. We have built on Amazon's seller APIs since 2017 and shipped integrations for 20+ marketplaces, Walmart among them. For this deadline, we list every app that touches your Walmart data, work through the reconnection with each provider, and test orders, stock and prices end to end.

We are not on Walmart's list of approved Solution Providers and have no App Store app of our own, so this work runs alongside the providers you already use. When a brand needs a Walmart integration of its own, we build it on Ecomsellertool Growth OS, deployed on your own accounts; our Walmart Marketplace API integration page covers what that involves, and the Amazon and Walmart sales and advertising dashboard we built for IVCSR is one example. You keep your accounts, your data and the custom code we build; the Growth OS base is licensed to you.

A dead connection is easy to miss for a day. A simple rule catches it: Walmart items still published, but no orders imported for longer than your slowest selling hours. That is the kind of rule we build into the multichannel operations agent we build and deploy on your own accounts, where the rule raises the alert and a person decides what to do.

If you want a second pair of eyes before September 30, schedule a call from the card below. If Amazon is your main channel, the free 24-hour diagnostic connects through Login with Amazon, with no password shared, and reports within 24 hours of connecting, on business days. We only read data; we never change listings, prices, stock or ads.

  • Walmart Marketplace
  • Walmart API
  • OAuth 2.0
  • Integrations

Frequently asked questions

Do I need to do anything if my apps already connect through the Walmart App Store?

Not for this deadline. Apps listed under Connected Apps in Seller Center already use OAuth 2.0. Walmart says that authorization lasts 12 months, so note each app's renewal date and renew it from Connected Apps before it lapses.

Will my Walmart listings or orders disappear when the old keys stop working?

Walmart's notice says the keys stop functioning and says nothing about listings or orders. A key only controls a tool's API access. Shoppers can keep ordering while the tool that imports orders, updates stock and uploads tracking has lost access, and that gap is what hurts your cancellation and tracking rates.

My provider is not in the Walmart App Store. What can I do before the cutoff?

Ask the provider for its migration date in writing today. Walmart says not every provider on its approved list can be connected through the App Store yet, and that approval and publication for a new provider may take three to five weeks. If there is no date before October 1, plan to run that job in Seller Center for a while, or move it to a provider that is already listed.

Can I give my own Walmart API keys to a tool instead of reconnecting it?

Walmart advises against it. Its OAuth FAQ tells sellers not to give their API keys directly to Solution Providers, says seller credentials grant full access, and says they are shared by every user on the account. Resetting them later cuts off every integration that uses them, including your own.

How do I prove to myself that a reconnection worked?

Three checks. The app appears under Connected Apps in Seller Center. The provider confirms in writing that your account now runs on the new connection. And the next seller-fulfilled order moves from Created to Acknowledged to Shipped with valid tracking, while a stock change you make in the tool shows up in Seller Center.

Does this change affect my Amazon apps?

No. The Delegated Access retirement is Walmart's and covers only Walmart connections. Amazon apps follow a similar yearly cycle, though: public Selling Partner API apps are authorized by the seller through Login with Amazon, and Amazon's documentation says reauthorization is required annually. One renewal calendar can cover both channels.

How we research, fact-check and compare: our editorial standards. Spot an error? Email hello@ecomsellertool.com and we will correct it.

Jaimin Dholakia, founder of Ecomsellertool
Jaimin Dholakia · Founder
Schedule a call

Turn what you just read into a plan for your brand.

Enter your email, connect your Amazon account with Login with Amazon, on Amazon’s own consent screen (we only read data; we never change listings, prices, stock or ads), and get a free report of what is going wrong within 24 hours of connecting, on business days. Prefer to talk it through? Schedule a call with the team that built these systems.

Free · 30 minutes · Pick any open slot