amazon
Amazon Seller Central Reauthorization 2026: What to Check
Amazon retired the old Seller Central invite process this year. If your agency, your inventory software, or a freelance PPC manager has access to your account, you're either about to get an email asking you to "reauthorize" that access, or you already have one sitting in your inbox. The short version: this is Amazon's system working as designed, not a phishing attempt, and you are not locked out of anything unless you ignore the email past the deadline Amazon gives you.
Amazon Seller Central authorization changes have been rolling out since August 2026, with seller-facing reauthorization emails going out through September. I run 85+ active Amazon accounts and I've spent the past two weeks making sure every one of them is clean on this. Here's what actually changed, why the email looks worse than it is, and the one thing worth checking carefully before you click approve, on our access or anyone else's.
What Actually Changed
For years, granting a service provider access to your Seller Central account meant a multi-step invite: you'd add a user, assign permissions individually, and hope you remembered to update them when the scope of work changed. It was clunky, and it was easy to lose track of who had what.
Amazon replaced that with a single authorization flow tied to the Solution Provider Network (SPN) and the Solution Provider Portal (SPP), the system service providers use to register and manage their access across clients. Starting August 10, 2026, for any service not listed directly on SPN, the provider generates one authorization link from their Portal account and sends it to you. You open the link, review the roles being requested, and approve or deny them in a single step, instead of assigning permissions one at a time.
Service providers had until today, September 3, 2026, to verify and update their own role coverage inside the Portal so their existing clients don't lose functionality when the new flow takes over. That part is on the provider side and doesn't require anything from you.
The part that does require something from you: through September, sellers are receiving direct communication from Amazon asking them to reauthorize every existing service provider's access under the new process. If you don't act on it, that provider's access expires. Full stop. They can't run your ads, touch your listings, or pull your reports until you go back into Seller Central and authorize them again.
Why the "Reauthorize" Email Looks Like a Scam
I get why this triggers alarm bells. An email showing up in your inbox asking you to click a link and approve access to a business account is exactly the pattern phishing has trained everyone to distrust, and rightly so. Amazon sending a wave of these out across its entire seller base at once doesn't help.
Here's how to check it without relying on the email at all. Log into Seller Central directly, not through the email link. Go to User Permissions, then Manage Services. Any pending reauthorization requests will be sitting there, tied to the actual provider name and the specific roles they're asking to keep. If what you see in the email matches what you see logged in directly under your own navigation, it's legitimate. If it doesn't match, or if a request shows up for a provider you don't recognize, that's the actual red flag, not the reauthorization process itself.
This is also a good moment to just look at who currently has access to your account. Most sellers who've been running a business for a few years have more service providers connected than they'd guess: a past agency that was never fully offboarded, a software tool nobody uses anymore, a contractor from two projects ago. The reauthorization wave forces a review that should have happened on its own a long time ago.
Aug 10, 2026
New link-based flow starts
Non-SPN services move to one authorization link from the provider's Portal account
Sep 3, 2026
Provider role-coverage deadline
Service providers verify their own role setup so existing clients don't lose access
September 2026
Seller reauthorization emails
Amazon contacts sellers directly to reauthorize each existing provider's access
Ongoing
Unreauthorized access expires
Providers lose account access until the seller authorizes again
Amazon SPN Reauthorization: What You're Actually Approving
The authorization link doesn't just ask for a blanket yes or no. It lists specific roles the provider wants: advertising, listings and catalog management, reporting, financial data, and so on, generally scoped to view, edit, or admin-level access within each category. This is the part most sellers skim past, and it's the part that actually matters.
One detail that trips people up: advertising access is often treated as a separate permission from general Seller Central access. A provider can hold broad account access and still not have advertising rights unless that box is checked specifically, and vice versa. If your agency runs PPC for you, confirm that permission is explicitly part of what you're approving, and confirm it's the only elevated permission they're asking for if PPC is the only thing they do.
That's the actual mechanic of the risk here. Not the reauthorization itself, the scope of what gets approved inside it.
The One Real Risk: Over-Scoped Access
Reauthorizing a provider you already trust and already work with is not the dangerous part of this process. The dangerous part is approving a role list wider than what that provider actually does for you, because it's easy, the link is right there, and clicking approve on everything takes ten seconds less than reading it.
Before you approve any provider's reauthorization request, run through this:
- Does the role list match the actual work. A provider handling PPC only shouldn't be holding Admin access to financial reports or account-level settings. If the roles go beyond the scope of the engagement, ask why before approving.
- Is advertising access scoped and intentional. Confirm it's checked because they need it, not bundled in because nobody looked closely.
- Do you recognize the provider and the request. Cross-reference the name and roles shown in Seller Central, not just what's in the email, against who you actually work with.
- Can you name everyone with current access. If the reauthorization list surfaces a provider you can't place, that's worth a direct call before you touch approve or deny.
- Is there a person at that provider who can explain every role they're asking for. A vague answer to "why do you need Admin on this" is itself useful information.
| Red flag | What good looks like | Risk |
|---|---|---|
| Broad Admin access for a narrow scope of work | Match roles to the actual engagement, nothing more | |
| A provider name you don't recognize in the request | Confirm identity directly with the seller-side Seller Central login, not the email | |
| Advertising access bundled in without explanation | Ask what it's for and remove it if the engagement doesn't call for it | |
| No one at the provider can explain a requested role | Treat a vague answer as the actual red flag, not the reauthorization itself |
None of this is unique to the reauthorization wave. It's the same discipline that should apply any time you grant account access to anyone. Amazon just handed every seller a forced checkpoint to actually run it.
What This Forced Us to Actually Look At
I'll be straight about this instead of pretending it was a non-event on our side. My first reaction when the role-coverage deadline showed up was the same as most agencies': one more login screen to click through before a deadline, not something that deserved real attention. That reaction is the actual problem. Access control isn't the kind of thing that stays correct on its own. Roles get granted for a project, the project ends, and nobody circles back to trim what's no longer needed, because there's no forcing function until Amazon builds one.
So we treated the deadline as the forcing function it was meant to be: every account we manage got a role review against the current scope of work, not a rubber-stamp reauthorization. That's the standard I think any agency should hold itself to on its own schedule, not just when Amazon sends everyone an email at once. I wrote separately about what changed and didn't after AMZ Advisers was acquired by Chief Media, and this is the same underlying question from a different angle: not "did anything bad happen," but "can you actually verify how your access is being handled, or are you taking someone's word for it."
What This Signals About Any Agency You're Evaluating
How an agency handles a moment like this tells you more than its pitch deck does. A provider that proactively reviews and trims its own access, that can answer exactly which roles it holds on your account and why, and that treats a reauthorization request as routine account hygiene instead of a scramble, is showing you how it operates in general, not just how it's handling one Amazon policy change.
That's the same lens I laid out in how to choose an Amazon brand management agency: ask who actually touches your account, ask what triggers an alert, ask for specifics instead of reassurance. Access control is just a narrower version of the same question. If an agency can't tell you exactly what roles it holds in your Seller Central account right now, that's worth asking about directly, reauthorization wave or not.
If you're not sure what access is currently sitting on your account, or you inherited a setup from a previous agency and have never had it reviewed, that's worth a second set of eyes. We offer a free Amazon account audit that covers this alongside the usual PPC, listing, and account health review, and if you want to see how we actually run client accounts day to day, including how we handle access and permissions, that's covered in how we work with Amazon brands.
The Bottom Line
Amazon killing the old invite process and moving everyone to a single-link SPN authorization flow is a real, dated policy change, not a rumor. The emails asking you to reauthorize your providers are legitimate, even though they read like the kind of thing your spam filter is trained to catch. Verify them by logging into Seller Central directly instead of trusting the email link, and don't let "approve" become a reflex. The reauthorization itself isn't the risk. What you approve inside it is.
Frequently asked questions
What changed with Amazon Seller Central authorization in 2026?
Amazon retired the old multi-step invite process for granting service providers access to a Seller Central account. In its place is a single authorization flow built around the Solution Provider Network and Solution Provider Portal. For services not listed on SPN, providers share one authorization link from the Portal, and the seller approves specific roles through that link instead of a chain of separate invites.
Is the Amazon reauthorize email a scam?
Not automatically. Amazon is sending real communications through September 2026 asking sellers to reauthorize existing service providers under the new process. The pattern (an email asking you to approve access to your account) matches how phishing usually works, which is why it feels alarming. Verify it by going into Seller Central directly rather than clicking the email link: User Permissions, then Manage Services, will show the same pending request.
What happens if I don't reauthorize my agency by Amazon's deadline?
Access expires. The provider loses the ability to work in your account, including running ads, updating listings, or pulling reports, until you initiate a new authorization. It is not a warning, it is a hard cutoff, and reversing it later takes another round trip through the same authorization flow.
What should I check before approving a service provider's access request?
Match the roles being requested to the actual scope of work. A provider that only runs PPC has no reason to hold Admin access to financial or account-level settings. Advertising access is frequently a separate permission from general account access, so confirm it is scoped correctly and not bundled in by default. If you cannot explain why a provider needs a role, ask them before you approve it.
Do I need to reauthorize every tool and agency connected to my account?
Yes. Any service provider that was granted access under the old invite process, agencies, software tools, freelancers, needs to be reauthorized under the new Solution Provider Network flow. Amazon is not grandfathering existing access. If it was not reauthorized, it will lapse when the old process is fully retired.

Mike Begg
E-commerce operator and business acquirer. Founder of AMZ Commerce Advisers (100+ active Amazon brands, 500+ managed since 2016) and GoAvance. Owner of Reach Social Commerce (50+ TikTok Shop launches). Amazon Ads Advanced Partner. Based in Guadalajara, Mexico.
Featured on BiggerPockets, Millionaire Interviews, Practical Ecommerce, and more about Mike Begg →