Operations & access

How to give an agency access to Seller Central in 2026

By Founder name — TODO(owner)Updated

This guide is for the founder or operations lead who has just hired an agency, consultant or freelancer and needs to give them access to Seller Central without handing over the account. It covers how provider access works now, which access to grant, how to take it back and how to keep the owner login safe. Every Amazon fact below was last verified on October 7, 2026.

Should you share your Seller Central password with an agency?

No. Amazon tells sellers “Don’t share your password with other people” and advises giving the minimum permissions each person needs to do their job (Amazon Seller Forums, Amazon staff post, September 2024). For outside providers, Amazon’s route is authorization through its Solution Provider Portal (SPP). A shared password gives the provider everything the account owner can do.

A shared login also breaks two-step verification. To use your password, the provider needs your sign-in code too, so either someone reads codes out on request or the provider’s phone gets added to the owner login. Both leave a former provider with a way back in.

Shared password Authorization through the Solution Provider Portal
What the provider can do Everything the account owner can do, including bank, payment and user settings Only the roles Amazon approved for that provider and you confirmed
Whose name is on the work Everything looks like the owner’s activity The provider signs in with its own login
Sign-in codes Shared, or a provider device on the owner login The provider uses its own sign-in
How long it lasts Until you change the password 365 days, then you renew it or it ends
Removing it Change the password, reset two-step verification, check what was changed Revoke the provider’s access in Seller Central
Amazon’s position Advises against it The flow Amazon built for providers

What is the Solution Provider Portal, and what must an agency do first?

The Solution Provider Portal is Amazon’s registration system for developers and service providers. Amazon’s FAQ says service providers that help sellers manage their business on Amazon must register there, and that Amazon reviews the services each provider offers and approves the specific Seller Central roles that match. Amazon tells providers to plan for 5–10 business days for that review (Amazon, September 2026).

That review sets the ceiling on what a provider can ask you for. Amazon’s FAQ says only the roles a provider has been approved for appear when you authorize it. If a provider needs more, it has to qualify for the extra roles first.

In practice:

  • A registered, approved provider can send you an authorization link. If it can’t, ask why before going further.
  • A listing in Amazon’s Service Provider Network (SPN), Amazon’s public directory of providers, is a second way to start authorization. It is a separate application from SPP registration.
  • Amazon’s FAQ does not say whether an individual freelancer can register. Ask a freelancer how they will get access before you agree the work.

How do you authorize an agency from Seller Central?

You authorize a provider in two stages, according to Amazon’s documentation updated September 9, 2026. First, you start the authorization from the link the provider sends or from its listing in the Service Provider Network. Second, you review the roles the provider was approved for, adjust or remove individual roles, limit access by country or region if needed and confirm. The authorization is then good for 365 days.

Step by step:

  1. Agree the scope in writing. List the work and the access each task needs (see the role table below). This is what you will check the roles against.
  2. Sign in to Seller Central with your own login. Never sign in on the provider’s device or through a link you can’t verify.
  3. Open the authorization link or the provider’s SPN listing. Check that the provider name matches the company you signed with.
  4. Review every role. Remove anything outside the agreed scope and limit access to the marketplaces the provider works on.
  5. Confirm. If the provider is listed in the SPN, Amazon says the provider then confirms the request on its side to activate access.
  6. Record it. Note the date, the roles, who approved it and the renewal date 365 days later.

Screens change. Some guides online still describe older steps, such as inviting a provider by email. If what you see doesn’t match, follow Amazon’s own page, Learn how sellers authorize service providers.

What changed in August 2026?

Since August 2026, Amazon has run a simplified authorization flow for service providers. Amazon’s changelog says that starting August 19, 2026, providers can share an authorization link or use their SPN listing, and roles are automatically limited to the service categories each provider has qualified for (Amazon SP-API changelog, August 2026).

For a seller, three things follow. Provider access now depends on Amazon’s review of the provider, not only on your invitation. The roles you can grant are pre-filtered. And access ends after 365 days unless you renew it, which gives you a built-in yearly review.

Which roles should an account-management agency get?

Grant the smallest set of roles that covers the written scope. Amazon’s own advice to sellers is to “grant the minimum permissions required for them to do their job” and to review them regularly (Amazon Seller Forums, September 2024). Amazon groups roles by service category and shows only the ones a provider was approved for, so match each role on screen to a task in the contract.

The table below shows typical patterns by type of work. These are not Amazon’s role names. The labels you see are Amazon’s; the test is whether each one maps to work you are paying for.

Scope of work Access it usually needs Access it usually doesn’t need
Compliance and account health Account Health and performance notifications, listing and restricted-product compliance, document uploads, cases with Amazon Advertising, bank and payment settings, user management
Full account management, no pay-per-click (PPC) ads All of the above, plus catalog and variations, inventory and Fulfillment by Amazon (FBA) shipments, reports, returns and feedback Advertising management, bank and payment settings, user management
PPC advertising only Advertising and the reports the ads team needs Catalog edits outside the agreed scope, cases, payments
Reimbursement audits Inventory and FBA reports, cases Catalog edits, advertising, payments
Bookkeeping Payment and settlement reports Catalog, cases, advertising

Two roles deserve a second look on any request: anything touching bank or payment details and anything that lets the provider manage other users. Very few service scopes need either.

How do you check, renew or remove an agency’s access?

Amazon’s Solution Provider Portal FAQ says sellers manage provider access from the Manage Services page in Seller Central and can revoke it there at any time (Amazon, September 2026). Each authorization lasts 365 days. Amazon notifies both you and the provider before it expires, and if you don’t reauthorize, the provider loses access until a new authorization is started.

A simple routine covers most of the risk:

  • Every quarter, review provider access and your own user permissions. Amazon notes that users who no longer work with your business “could pose a risk to private information” in your account.
  • When a contract ends, revoke access the same day and ask the provider to confirm in writing.
  • At renewal, re-check the roles against the current scope before you reauthorize. Scopes drift over a year.
  • On the provider’s side, Amazon lets a provider’s administrator assign each employee to specific seller accounts and remove employees who leave (Amazon SPP documentation, September 2026). Ask who on the provider’s team can see your account and how they remove leavers.

What if your current agency still uses your login?

Move the agency to authorization first, then close the old route. Ask it to complete Solution Provider Portal registration if it hasn’t and to send you an authorization link. Authorize only the roles its scope needs and check that its team can work. Then change the owner password, remove any verification device that isn’t yours and delete user logins created for the provider.

The order matters. Cutting the old login first stops work mid-month, and adding authorization without closing the old route leaves two doors open.

  • Agree a switch date with the provider and put it in writing.
  • Authorize first. Confirm the provider’s team can sign in with its own access before you change anything else.
  • Close the old route the same day. New owner password, a clean list of verification devices, no leftover provider users.
  • Check the result a week later. Review your user list and provider access again, and ask the provider to confirm it no longer holds any of your credentials.

If a provider can’t or won’t move to authorization, weigh that when you decide whether to keep it.

How do you keep the account itself secure?

Provider access is only as safe as the owner login behind it. Seller Central sign-in uses two-step verification: a code from a phone or an authenticator app on top of the password. In its announcement to sellers in Europe, Amazon recommended an authenticator app for accounts with several users (Amazon Seller Forums Europe, March 2024). Keep the owner login and its verification device under company control.

  • One person, one login. Employees get their own users through User Permissions. Amazon tells sellers not to add outside service providers or developers as ordinary users (September 2024); providers get authorization through SPP.
  • Company-controlled verification. Register the owner login’s authenticator on a company device, not on the personal phone of someone who might leave.
  • Never pass on a sign-in code. Not to a provider and not to anyone who contacts you claiming to need it.
  • Check names before you confirm. An authorization link should name the provider you signed with.

Access checklist

Step What to check Done when
Before signing The provider is registered in SPP with roles approved for the services in your contract You have it in writing
Scope A written list of tasks and the access each one needs It is attached to the contract
Owner login Two-step verification is on, on a company-controlled device Checked
Authorize The link or SPN listing matches the provider; roles match the scope; marketplaces are limited Confirmed in Seller Central
Record Date, roles, who approved, renewal date Logged in your access register
Provider staff Names of the people on the provider side who can access the account Received
Every quarter Provider access and user permissions; remove anyone who has left Reviewed
Renewal Roles re-checked against the current scope Reauthorized or allowed to lapse
Offboarding Access revoked on the last day Provider confirms in writing

What are the red flags when an agency asks for access?

  • It asks for your password or a two-step verification code.
  • It asks you to add its phone or authenticator app to your owner login.
  • It can’t send an authorization link or explain its SPP registration.
  • It requests bank, payment or user-management roles “just in case”.
  • It wants to keep access after the contract ends with no written reason.

Any one of these is a reason to pause. If the provider is otherwise right for you, ask it to fix the access question before work starts.

How LIVELE handles access

We never ask for your password. We also don’t take on accounts that can only offer a shared login.

LIVELE’s Full Account Management ($4,500/month) and Compliance Management ($3,500/month) do not include PPC. We work alongside your ads agency or in-house team, and each keeps its own access. If you are comparing providers on price as well as process, read what Amazon account management costs in 2026 or compare our plans.

First published Updated

Questions about this topic

Can I give an agency access without the Solution Provider Portal?

Amazon's Solution Provider Portal FAQ says service providers that help sellers manage their business on Amazon must register in the portal and have their Seller Central roles approved. Your own employees are different. They get their own user logins through User Permissions. If a provider can't complete registration, don't fill the gap with your password.

How long does an agency's access to Seller Central last?

Each authorization is valid for 365 days. Amazon says it notifies both the seller and the provider before an authorization expires. If you don't reauthorize, the provider loses access until a new authorization is started (Amazon Solution Provider Portal FAQ, updated September 30, 2026).

Can I limit an agency to one marketplace?

Yes. Amazon's documentation says that during authorization you can use a country or region filter to limit where the provider has access, and adjust or remove individual roles before you confirm.

How do I remove an agency's access when the contract ends?

Amazon's Solution Provider Portal FAQ says sellers can revoke a provider's access at any time from the Manage Services page in Seller Central. Revoke it on the last day of the contract rather than waiting for the 365 days to run out, and ask the provider to confirm in writing that its staff no longer have access.

Is it against Amazon's rules to share my Seller Central password?

Amazon advises sellers not to share their password and to use permissions to give others access. We have not found an Amazon page that sets out a specific penalty for sharing, so we don't claim one. The practical risk is that you lose track of who can act in your account and can't remove one person without resetting everything.

Sources

  1. Solution Provider Portal FAQ · Amazon Selling Partner API documentation ·
  2. Learn how sellers authorize service providers · Amazon Selling Partner API documentation ·
  3. SP-API updates: simplified authorization for service providers · Amazon Selling Partner API changelog ·
  4. Manage users in Solution Provider Portal · Amazon Selling Partner API documentation ·
  5. Seller account user permissions · Amazon Seller Forums (Amazon staff post) ·
  6. Two-factor authentication will be required for Seller Central sign in · Amazon Seller Forums Europe (News_Amazon) ·

LIVELE Policy Watch

One email a month with the Amazon policy and fee changes we add to the tracker, each with its source.

Monthly. Unsubscribe anytime. We’ll ask you to confirm by email.

Hand over the account, keep the decisions

Tell us your catalog size, categories and what your team handles today. We'll tell you whether Full Account Management fits.