OAuth authorization
Amazon access is granted through the relevant OAuth flow and scopes. Users do not paste Seller Central passwords or raw credentials into ChatGPT or Claude.
Vendooly is designed to give an AI assistant only the Amazon tools and context needed for the requested operation. Amazon authorization, stored tokens, tenant boundaries and write approvals remain outside the model.
Amazon access is granted through the relevant OAuth flow and scopes. Users do not paste Seller Central passwords or raw credentials into ChatGPT or Claude.
Amazon refresh tokens are encrypted at rest and are handled by the connector layer, not inserted into prompts or returned to the browser.
Every request is checked against the authorized org, user, seller account and marketplace so that one tenant cannot select another tenant’s context.
Tools return the operating context required for the requested task. Vendooly does not treat a full seller-account export as the default model context.
Writes to listings, prices, feeds, bids, budgets or campaigns require an explicit confirmation. Vendooly is not presented as an unattended autopilot.
Operational and administrative actions are logged so activity can be reviewed. Sensitive customer data is not used as public proof without documented consent.
The assistant requests a defined tool. Vendooly validates authorization, calls the relevant Amazon API and returns the minimum result needed. Amazon tokens remain in the connector environment.
The user signs in and operates within an org. Access to seller accounts is checked on the server.
The connector resolves the authorized seller account, marketplace and API region before making a request.
The assistant receives the tool result. If a write is proposed, the responsible user reviews the exact scope before confirmation.
Connect the Seller API and Ads API capabilities required for the workflow and review access when responsibilities change.
Check the seller account, marketplace, affected records and operating constraints before approving a write.
Remove users who no longer need access and contact support promptly if you suspect an authorization issue.
Security questions and responsible disclosure: security@vendooly.com. Privacy and processing terms are maintained in the Privacy Policy and Data Processing Agreement.
Review the authorization model, tenant boundary and write-confirmation flow, then start with one bounded operating question.