Amazon Selling Partner API · without your own application

You shipped the Amazon integration. Now every server you own is in scope.

ShipStream Data Border holds the application registration and the encrypted seller tokens. Your warehouse system posts {{ship_to_name}}, we resolve the buyer address in memory, buy the label, hand you back [REDACTED] plus a tracking code, and print the real thing straight to warehouse-zebra-01.

adb.example.com/order 113-9483920-1029338
Your stackwms-app-01

request body

to_address:

name: "{{ship_to_name}}"

street1: "{{ship_to_address1}}"

city: "{{ship_to_city}}"

phone: "{{ship_to_phone}}"

parcel: { 10 × 8 × 4, 16 oz }

Systems in audit scope

0 — nothing here holds buyer PII

The bordershipstream data border
  1. POST /api/label-proxy/forward

  2. origin allow-list

  3. GET /orders/v0/orders/113-9483920-1029338/address

  4. buyer address resolved

  5. POST api.easypost.com/v2/shipments

  6. response scrubbed

  7. POST /api/print/send → device-hub

Outsidesp-api · carrier · printer

Amazon Selling Partner API

sellingpartnerapi-na.amazon.com

EasyPost

api.easypost.com/v2/shipments

Device Hub

warehouse-zebra-01 · 4×6 thermal

Audit log · adb0 events

▍ idle — press Ship one order

Runbook

The six things you will ask at 02:00.

Every answer here is the actual request, the actual response body and the page in the docs that owns it.

Pick one

Answer ▍

Request

GET /api/pii/getPII/113-9483920-1029338
  -H "x-seller-access-token: ..."
  -H "x-amazon-token-secret: ..."

Response

429 Too Many Requests
{ "error": { "message": "PII access throttled" } }

One read per order per hour, by design — retrying will not help. Post the shipment to /api/label-proxy/forward instead: it resolves the address inside the border, so your side never needs the read.

PII access limits →

The hard part

Someone still has to hold the dangerous thing.

Three mechanisms do the holding: the credentials never decrypt without your secret, the gates close by default, and every touch leaves a line you can hand to an auditor.

01 · Custody

The token in our database is useless without your secret.

Amazon refresh tokens are sealed with AES-256-GCM and a scrypt-derived key. The key material arrives on the request as x-amazon-token-secret and is never written down.

version
1 byte
salt
32 bytes
iv
16 bytes
auth tag
16 bytes
ciphertext
variable

02 · Need to know

You cannot bulk-export what you can only read once.

The limits are structural, not advisory. A compromised integration credential buys an attacker one address per order per hour — and nothing at all on shipped orders.

  • buyer address read1 / hour / order429
  • after blockPII or completeOrderterminal403
  • file operations50 / day / tenant429
  • authorization endpoints5 / 10s / IP429
  • unknown carrier originnever400

03 · Evidence

The answer to "who read this address" is a query, not a project.

Ten log types, one shape, ready for your SIEM. Every record carries the order, the seller, the tenant, the IP, the user agent and the result.

securityauthenticationamazon_apipii_accesslabel_proxyprintpassthroughconfigurationhealth_checksystem
{
  "type": "pii_access",
  "action": "getPII",
  "orderId": "113-9483920-1029338",
  "sellerId": "seller_9f2c1a",
  "ip": "203.0.113.42",
  "accessCount": 1,
  "success": true
}

Retention

One order is one address. One year is your customer list.

Same order stream, same labels, two stacks. Turn your volume up and watch which column moves.

850
day 1 of 30
0 shipped
Orders in

Your own integration

a typical stack

  • postgres-primary0

    the row your app writes

  • read replica0

    streaming, seconds behind

  • log index0

    whatever the request logged

  • nightly snapshot0

    one slab per night, kept for months

  • staging refresh0

    copied to a laptop-reachable box weekly

Buyer addresses at rest0

0 orders × 0.0 copies · nothing here expires on its own

Through the border

the same stack

  • postgres-primary0

    order id, tracking, document uuid — no PII field

  • read replica0

    nothing to replicate

  • log index0

    nothing to replicate

  • nightly snapshot0

    nothing to replicate

  • staging refresh0

    nothing to replicate

no address heldreleased after the label
Buyer addresses at rest0

one read per order per hour, released after the label · 0 labels printed

running · day 1 of 30 · drag orders per day and watch the right column not move

After day 1 of 30 at 850 orders a day: 0 copies of 0 buyer addresses in a stack without a border, and 0 in a stack with one. Both printed 0 labels.

Day two

One order, from consent to revocation.

Walk the states. The left column is what your database holds at that moment — it never changes shape.

The call

POST /api/claim-code

Audit event

{"type":"authentication","event":"seller_authorized","sellerId":"seller_9f2c1a"}

In your database

a seller id and an access token

PII fields: 0

Inside the border

the encrypted refresh token, sealed with the tenant secret

Our problem, contractually

Also true

The rest of the Selling Partner API, on the same credential.

Labels are the hard case, not the only case. Point any allow-listed Selling Partner API path at /passthrough-api/* and the border signs it, routes it and scrubs it on the way back. Orders, inventory, fees and shipping — with no application of your own to register, renew or defend.

Passthrough reference →

GET /passthrough-api/orders/v0/orders?MarketplaceIds=ATVPDKIKX0DER

  • 01access tokendecrypted per request, never logged
  • 02restricted data tokenminted only when the endpoint requires one
  • 03region routingsellingpartnerapi-na · eu · fe, from the seller record
  • 04response scrubbuyer name, address and phone stripped before you see it
{
  "payload": { "Orders": [ {
    "AmazonOrderId": "113-9483920-1029338",
    "OrderStatus": "Unshipped",
    "OrderTotal": { "CurrencyCode": "USD", "Amount": "29.99" },
    "ShippingAddress": { "City": "[REDACTED]", "PostalCode": "[REDACTED]" }
  } ] }
}

The receipt

Priced against the thing you would otherwise build.

Same line items every compliance program has. Check them against your own quotes — that is the point of publishing them.

Build it yourselfCost
Selling Partner API application registrationfree
Security assessment preparation$15K – $50K
Third-party security audit$10K – $25K
Development and integration$30K – $100K
DLP and MDM tooling$5K – $15K / yr
Vulnerability scanning and SIEM$3K – $10K / yr
Backup and audit log retention$2K – $8K / yr
Legal review and cyber insurance$5K – $20K / yr
Annual recertification$5K – $10K / yr
First year, before you ship a parcel$75K – $238K

Single app

$199/mo

2,500 labels included, then $0.02 each. One warehouse or one seller account, Device Hub printing, questionnaire support.

SaaS provider

$699/mo

$0.015 per label at any volume. Multi-tenant dashboard, white-labeled client questionnaires, full API.

You still run your own warehouse system, your own carrier accounts and your own printers. We are not trying to own those.

Full pricing and volume examples →

Move the border before the questionnaire arrives.

Create an account, connect a sandbox seller, and post your first /api/label-proxy/forward today. Nothing about your warehouse system has to change except where the address comes from.

Read the version written for your shape: 3PL · WMS / OMS vendor · Seller