Connect Amazon Ads to Rig

    Requirements
    • An Amazon Developer account with a Login with Amazon security profile (your developer app)
    • An Amazon Ads account
    • Amazon Ads API access, approved for that security profile
    Time required
    About 20 mins of setup, plus 24 to 72 hours for Amazon to approve API access

    Prerequisites

    1. Create a Developer account and security profile

    1. Sign in at developer.amazon.com, or create a free Amazon Developer account if you do not have one.
    2. Open the Login with Amazon console and click Create a New Security Profile. Give it a name, a short description and a privacy notice URL (your own privacy page will do), then save.
    3. Click the gear icon next to the profile and choose Web Settings, then Edit.
    4. Under Allowed Return URLs, add https://rig.so and save. It has to match exactly: no trailing slash, no www.
    5. Copy the Client ID and the Client Secret. Treat the secret like a password: if you share it with us, use a password manager rather than a chat window, because chat history outlives the call.

    2. Apply for API access

    1. Go to advertising.amazon.com/about-api and click to request API access. Amazon moves this page around: if it has moved again, scroll to the footer of advertising.amazon.com and follow Amazon Ads API.
    2. Sign in with the same email address as your Developer account.
    3. Choose Direct advertiser, then Sponsored ads.
    4. Fill in the form and submit it. It asks what your business does and how you plan to use the API, and you confirm you comply with Amazon's licence agreement and data protection policy. If it offers to create a new advertiser account, pick your existing one instead.
    5. Wait for approval. Direct advertisers usually hear back in 24 to 72 hours, by email.

    3. Connect your security profile to the API

    1. Open the link in Amazon's approval email, in a browser signed in to the same Amazon account you applied with.
    2. Check the page shows the client ID from step 1. If you have more than one security profile, pick that one.
    3. Click Submit.

    Open the email link as it is
    The link is long and easy to break. Copying it across a line wrap, forwarding the email, or letting a mail scanner rewrite it all corrupt it, and the page then errors or shows no client ID. If that happens, go back to the original email and click it again rather than pasting it. Skipping this step entirely leaves you approved on paper with credentials that still fail, and Amazon's fix is under assign API access.

    Not the same as Seller Central
    Amazon Ads and the Selling Partner API are separate products with separate credentials. If you already connected Amazon Seller Central to Rig, none of it carries over, and there is no Connect with Amazon button on this one.

    Get the refresh token

    For technical audiences

    Rig will run this for you
    If you are not familiar with OAuth or the command line, skip this section. Ask in your shared Slack channel and we will run it with you: we send you a link, you sign in and click Allow, you paste back the address you land on, and we do the rest. We can book a call instead if you would rather.

    The client ID and secret identify your security profile. The refresh token says whose advertising data it may read, and no Amazon screen shows you one: you generate it by authorising the profile against an account. Sign in as the account that can see the advertisers you want, because that is what fixes which advertisers the token can ever read.

    1. Check https://rig.so is in Allowed Return URLs on the security profile's Web Settings, exactly as written in step 1.
    2. Open this link with your client ID in place, and click Allow. For advertisers in Europe, swap www.amazon.com for eu.account.amazon.com, and in the Far East for apac.account.amazon.com.
    Consent link
    https://www.amazon.com/ap/oa?client_id=YOUR_CLIENT_ID&scope=advertising::campaign_management&response_type=code&redirect_uri=https://rig.so
    1. Amazon sends you to rig.so/?code=…. Copy the value of code straight away: it is single use and expires within minutes.
    2. Exchange the code for a refresh token. Use api.amazon.co.uk for Europe or api.amazon.co.jp for the Far East:
    Exchange the code
    curl -X POST https://api.amazon.com/auth/o2/token \
      -d grant_type=authorization_code \
      -d code=THE_CODE_FROM_THE_ADDRESS_BAR \
      -d redirect_uri=https://rig.so \
      -d client_id=YOUR_CLIENT_ID \
      -d client_secret=YOUR_CLIENT_SECRET

    Keep refresh_token from the response. That is the value Rig stores, and it is long lived. The access_token next to it lasts an hour, which is long enough for the check below.

    1. List the profiles the token can see. Use advertising-api-eu.amazon.com or advertising-api-fe.amazon.com outside North America:
    Check the profiles
    curl https://advertising-api.amazon.com/v2/profiles \
      -H "Authorization: Bearer YOUR_ACCESS_TOKEN" \
      -H "Amazon-Advertising-API-ClientId: YOUR_CLIENT_ID"

    You should see one entry per advertiser and marketplace. An empty list means the wrong Amazon account signed in at the consent link: the token works, it just has nothing to read. Run the consent link again as the right account.

    Connect it in Rig

    1. In Rig, open Connections and go to Sources & actions.
    2. Search for Amazon Ads and open the card.
    3. LWA client ID and client secret: from your security profile's Web Settings.
    4. Refresh token: the token from the exchange above, or the one Rig generated with you.
    5. Profile IDs (optional): leave blank to sync every profile the account can see. A profile is one advertiser in one marketplace, so an account selling in five countries has at least five.
    6. Region (optional): leave blank to let Rig search all three regions, na, eu and fe. If you do set it, note the UK is served by eu and the US by na.
    7. DSP advertiser IDs (optional): only for the ADSP Reports link path.
    8. Click Test, then Sync.

    What Rig pulls in

    Amazon Ads lands in its own amazon_ads schema:

    • Profiles, one per advertiser and marketplace
    • Sponsored Products structure: campaigns, ad groups and keywords
    • Sponsored reporting: daily performance for Products, Brands and Display

    Rows carry their profile, country and currency, because Amazon reports in each profile's native currency. US rows arrive in dollars and UK rows in pounds, so any blended total needs converting rather than summing.

    How far back reporting goes

    Amazon retains report data for different periods per ad product, and no tool can reach past those limits:

    • Sponsored Products: about 95 days
    • Sponsored Brands: about 60 days
    • Sponsored Display: about 65 days

    Rig syncs roughly 93 days and keeps up daily from there, so history accumulates in your warehouse well beyond what Amazon itself will hand back. That is a good reason to connect earlier rather than later: the window you miss is not recoverable.

    Troubleshooting

    • The consent link says the client ID is unknown: the client ID was mis-copied, usually a character short. Copy it again, whole, from the security profile's Web Settings.
    • The consent link says an unknown scope was requested: Amazon does not yet recognise your security profile for advertising::campaign_management. Either API access has not been approved, or the client ID was never connected from the approval email. Finish prerequisites 2 and 3. The same cause shows up later as The LWA client ID is not approved to use the requested scope.
    • It authenticates but sees no advertisers: the credentials are valid and the access is not, and this is the failure this connector produces most. The account that clicked Allow needs either a Manager Account with Admin permission over the advertisers, or, for read-only DSP, an approved ADSP Reports link. Generate the token again signed in as an account that has one.
    • A profile is missing: check the region. UK profiles live under eu, not a separate UK region, and setting the region filter too narrowly hides the rest.
    • Sponsored Brands or Display reports are empty: those products are not sold in every marketplace, and an advertiser with no campaigns for a product returns nothing.
    • Totals look wrong across countries: you are probably summing mixed currencies. Group by currency_code first.
    • DSP data is missing entirely: either the account has no DSP access, or you need the ADSP Reports link approved by the advertiser's admin. Request it in Manager Accounts under Accounts → Add account → Link existing account → Request access. There is no API for this: a person has to approve it, so start it early.

    What people use this for

    • Manage ACOS and ad-attributed sales
    • Find wasted spend across keywords and campaigns
    • Compare performance across campaign types
    • Track spend pacing against budget

    More ideas for using Amazon Ads

    Was this guide helpful?