Amazon Seller is connected once at the org level by an admin. The credential is shared across all groups that have been granted access — individual team members don't need to connect their own accounts.
Log in to Seller Central → Apps & Services → Develop Apps
Create a developer profile if you don't have one
In the SP-API console, register your application and generate LWA (Login with Amazon) credentials
Complete the OAuth self-authorization flow to obtain a refresh token for your own seller account
Paste your LWA Client ID, Client Secret, and Refresh Token below
Ready to connect?
Go directly to the integrations page in your dashboard.
These are the data scopes On Belay can be granted for Amazon Seller. Your org admin controls which scopes are enabled per group.
| Scope | Description | Access |
|---|---|---|
orders:read | Read orders | Read only |
inventory:read | Read inventory | Read only |
catalog:read | Read catalog items | Read only |
reports:read | Read reports | Read only |
fulfillment:read | Read fulfillment data | Read only |
Double-check that you copied the full key without any leading/trailing spaces. Some platforms show a truncated preview — make sure to copy the full token. If the key was generated with restricted scopes, verify it includes the permissions listed above.
Check that your group has been granted access to this integration in On Belay → Groups → [your group] → Integrations. Also verify the specific scopes your group is permitted to use match what your query requires.
Some API keys have expiration policies. Generate a new key in Amazon Seller and update it in On Belay → Integrations → Amazon Seller → Update key. Consider creating a dedicated service account or machine user for On Belay so the key isn't tied to a personal account.
Still stuck? We're happy to help.
Contact support →