Developer information

Summary

BFarm currently has no approved or active SP-API application or production OAuth integration. Planned only after the required Amazon approval, production implementation, security verification, and seller authorization. The planned scope is one Brand Analytics role and two read-only report types.

Last Updated: August 10, 2026

BFarm currently has no approved or active SP-API application or production OAuth integration.

Available today through Amazon analytics exports supplied directly by the managed-service client, with client-scoped storage and read-only reporting. Planned only after the required Amazon approval, production implementation, security verification, and seller authorization.

  • Planned role: Brand Analytics
  • Search Query Performance (SQP) (GET_BRAND_ANALYTICS_SEARCH_QUERY_PERFORMANCE_REPORT): Read-only API request after approval. Available only to eligible Brand Registry sellers.
  • Sales and Traffic (GET_SALES_AND_TRAFFIC_REPORT): Read-only API request after approval. Available to eligible seller accounts.
  • Authorization step 1: BFarm obtains the required Amazon approval and its own Login with Amazon credentials.
  • Authorization step 2: The seller opens a BFarm connection link and continues to Amazon.
  • Authorization step 3: Amazon presents the approved Brand Analytics permission for seller consent.
  • Authorization step 4: Amazon returns a short-lived authorization code to the BFarm server-side callback.
  • Authorization step 5: BFarm exchanges the code server-side and binds the authorization to the correct seller and client scope.
  • Authorization step 6: The seller can revoke access through Amazon; BFarm will also provide a disconnect path before activation.
  • The following are excluded from the planned SP-API integration. They describe the requested API scope, not the existing managed service, which is described in the Privacy Policy.
  • Buyer names, addresses, phone numbers, communications, and other buyer PII
  • Seller Central passwords, private applications, Client IDs, Client Secrets, refresh tokens, and other client API credentials
  • Orders, Listings, Pricing, Finance, FBA, and Amazon Ads API data
  • Listing, pricing, advertising, or other write operations
  • Use of Amazon Information to train, fine-tune, or evaluate any model
  • Automated or model-initiated action on a seller account without operator review and seller approval
  • External Amazon-derived datasets, resale of Amazon data access, and cross-seller pooling or aggregation
  • Primary technical contact: security@bfarm.top
  • Security incident reporting: security@bfarm.top
Explore Services See Case Studies Read Academy Book a 30-min call Get the free audit

Contact