Harpy Glossary

SP-API (Selling Partner API)

Amazon & D2C glossary · Harpy Media

SP-API (Selling Partner API) is the platform’s official programming interface for developers, replacing the older web-service model: a modern, permission-scoped way for applications to read and write business data — orders, inventory, listings, finances, advertising — without anyone logging into a dashboard.

What is SP-API?

SP-API (Selling Partner API) is the platform’s official programming interface for developers, replacing the older web-service model: a modern, permission-scoped way for applications to read and write business data — orders, inventory, listings, finances, advertising — without anyone logging into a dashboard.

It is the plumbing behind automation. Every serious tool a seller uses — repricing, inventory synchronisation, accounting integrations, advertising management — connects through it. Understanding what it is changes how you evaluate those tools and how much you trust the data flowing through them.

What it enables, and why it is built the way it is

Three properties matter. It is permission-scoped, so an application can be granted access to orders without access to finances or listings. It is authenticated properly through token-based authorisation rather than shared credentials. And it is built for scale, so a tool can process a catalogue and an order flow continuously rather than by manual export.

Those properties are what make safe delegation possible. Instead of giving a contractor the master account login — broad, shared, and hard to revoke — you authorise an integration that can do one job and be switched off. Where a seller’s account security has improved over the years, this is why.

Evaluating tools by how they connect

A tool connected properly through the official interface is one whose access can be reviewed and revoked, and whose reliability reflects an engineered integration rather than a script scraping a screen. That distinction matters in practice: screen-scraping breaks when the interface changes, and the break is usually discovered when a feed quietly stops updating.

So when choosing software, ask how it connects and what it is authorised to do. The answers tell you how much of your business is technically reachable by that vendor, how easily you could remove them, and how likely the integration is to fail silently at an inconvenient moment.

In practice

A brand connects its inventory system and its advertising tool through properly scoped authorisations rather than sharing logins. Each integration can do its job and nothing more, the access is reviewable, and when one provider is replaced the authorisation is revoked in minutes — while the rest of the stack continues untouched.

⚠️ Watch out. Sharing logins because it is quicker. A seller gives a developer the account credentials so a tool can pull reporting, the tool is later abandoned without the password being changed, and access to the entire account stays live indefinitely — unknown, unmonitored, and impossible to attribute when something changes unexpectedly.
💡 Harpy tip. Insist on proper authorisation for anything that touches your account, scope access to the job in hand, and review what is connected periodically. Then treat integrations as systems to monitor — quiet failure is the characteristic risk of automation.

How Harpy Media helps

Systems integration is part of how we set brands up to scale: tools connected through scoped access, credentials kept out of circulation, and the connected stack reviewed rather than accumulated.

SP-API FAQ

What is the Selling Partner API?

The platform’s official interface for applications to access seller and vendor data programmatically — orders, inventory, listings, finance, and advertising — using secure, permission-scoped authorisation.

Why not just share a login?

Because shared credentials give full access, cannot be scoped or attributed, and are difficult to revoke reliably. Proper authorisation limits each tool to what it needs and can be switched off cleanly.

How do I know if a tool uses it?

Ask the provider how they connect. Tools built on the official interface can describe exactly what permissions they require and can be reviewed in your account’s authorised-applications settings.

Want these numbers watched for you, every week?

Book Free Consultation

New guides, straight to your inbox.

Practical D2C playbooks as we publish them. No fluff, no spam — unsubscribe anytime.