Skip to main content
// BFarm Insights

Developer information

Last Updated: September 29, 2026

BFarm currently has no approved or active SP-API application or production OAuth integration.

BFarm is a trading name of Maksym Lazuto, Individual Entrepreneur, registered in Ukraine.

Current delivery path

BFarm imports client-provided Search Query Performance and Sales and Traffic exports into a reporting workspace. Reports are separated by client and marketplace, show their source period, and do not make changes in Seller Central.

Managed Account Management and Advertising Optimization use seller-controlled Amazon Authorized Partners access. Clients do not create private apps or provide BFarm with API credentials or passwords.

Planned Public SP-API scope

Amazon API access remains planned. Activation requires the relevant Amazon approval, seller authorization, and verification of the live connection and its security controls.

  • One non-restricted role: Brand Analytics.
  • Search Query Performance (SQP): read-only api request.
  • Sales and Traffic: read-only api request.
  • No production Amazon callback, token exchange, or SP-API request is active today.

Implemented reporting and connection status

The reporting workspace is in use with manual imports. An owner sign-in with multi-factor authentication, access to the selected reports, and automatic startup after a server restart were checked in September 2026. These checks do not verify live Amazon API access.

Authorization and encrypted-credential components have been implemented, but the Amazon connection remains disabled. No seller is connected through a BFarm OAuth flow, and no production Amazon authorization code or token is processed.

An encrypted external backup was restored and checked in isolation. Running the application on that restored database, a full production recovery, and delivery of emergency notifications have not been verified.

Technical and data boundaries

The following are excluded from the planned SP-API integration. They describe the requested API scope, not the existing managed service, which is described in the Privacy Policy.

  • Buyer names, addresses, phone numbers, communications, and other buyer PII
  • Seller Central passwords, private applications, Client IDs, Client Secrets, refresh tokens, and other client API credentials
  • Orders, Listings, Pricing, Finance, FBA, and Amazon Ads API data
  • Listing, pricing, advertising, or other write operations
  • Use of Amazon Information to train, fine-tune, or evaluate any model
  • Automated or model-initiated action on a seller account without operator review and seller approval
  • External Amazon-derived datasets, resale of Amazon data access, and cross-seller pooling or aggregation

Before Amazon access is activated, BFarm must verify server-side authorization, seller-bound encrypted tokens, controls that block requests while disabled, log redaction, and revocation handling with the approved connection. Implemented components and local checks do not establish that a live Amazon connection works.

The planned SP-API scope also excludes transferring Amazon Information to language-model providers.

Planned seller authorization

These steps describe the future connection. This website has no active authorization entry point.

  1. BFarm obtains the required Amazon approval and its own Login with Amazon credentials.
  2. The seller opens a BFarm connection link and continues to Amazon.
  3. Amazon presents the approved Brand Analytics permission for seller consent.
  4. Amazon returns a short-lived authorization code to the BFarm server-side callback.
  5. BFarm exchanges the code server-side and binds the authorization to the correct seller and client scope.
  6. The seller can revoke access through Amazon; BFarm will also provide a disconnect path before activation.

Technical and security contact

Integration questions, security disclosures, and incident reports go to security@bfarm.top. General enquiries go to max@bfarm.top.

Your privacy choices

Optional analytics only after you accept.

BFarm uses optional analytics and advertising technologies only after you accept. Rejecting does not affect the website or forms. See the Privacy Policy.