Registered API access
Automation must run through registered Selling Partner API applications. Browser automation and scraping of Seller Central are reported as prohibited.
Amazon added agent rules to its Business Solutions Agreement, reported as effective 4 March 2026. They govern how automated and AI-driven tools may act on a seller account: registered API access, self-identification, audit trails, and a documented human decision before high-impact changes. This page summarises what is reported, and what it changes in practice.
As described in public reporting on the agreement update announced in February 2026.
Automation must run through registered Selling Partner API applications. Browser automation and scraping of Seller Central are reported as prohibited.
Automated systems must identify themselves as such rather than presenting as a human operator.
Records of the actions taken must be retained — reporting cites a twelve-month retention period.
Bulk listing creation above threshold, large price moves such as more than 20% in 24 hours, and account configuration changes require a documented human decision.
Reporting describes three bands, separated by how much damage an action can do.
Routine operations: inventory synchronisation, order acknowledgement, repricing inside defined parameters. Minimal restrictions beyond running on registered API access.
Catalog updates, advertising bid adjustments, replies to customer messages. Rate limiting and audit logging expected.
Bulk listing creation, large price changes, account-level configuration. A documented human authorization step is required in the audit trail.
If a tool asks for your Seller Central email and password, it is not using authorized API access. Official OAuth means you grant scoped access and can revoke it from Seller Central at any time.
"Fully autonomous" is a selling point that became a liability. For sensitive changes, the safer design is a proposal you approve, with the decision recorded.
If something goes wrong on your account, you need to reconstruct what was changed, when, and on whose authority. That is what an audit trail is for.
Vendooly was built around authorized access and human approval before the policy existed — not retrofitted to it.
Vendooly runs on Amazon's Selling Partner API and Advertising API. Access is granted through Amazon's own authorization flow. We never ask for Seller Central credentials, and no password is ever typed into an AI conversation.
Reading is free. Prices, stock, listing content, bids, budgets and campaign state are prepared as proposals and executed only after explicit confirmation. Bulk operations carry additional server-side caps.
Each request stays bound to the org, seller account and marketplace you authorized. Agencies operate several client contexts without merging them, and any authorization can be revoked from Seller Central.
This page summarises public reporting on the agreement update. The authoritative source is the current Services Business Solutions Agreement in your Seller Central account.
Vendooly is a software vendor, not your legal adviser. For obligations specific to your business, consult a qualified professional.
If Amazon updates the requirements or the effective dates, we update this page. Last reviewed 26 July 2026.
Connect one seller account, ask a bounded question, and watch the assistant propose a change instead of making one.