Connect Amazon Ads to Rig
- Requirements
- An Amazon Developer account with a Login with Amazon security profile (your developer app)
- An Amazon Ads account
- Amazon Ads API access, approved for that security profile
- Time required
- About 20 mins of setup, plus 24 to 72 hours for Amazon to approve API access
Prerequisites
1. Create a Developer account and security profile
- Sign in at developer.amazon.com, or create a free Amazon Developer account if you do not have one.
- Open the Login with Amazon console and click
Create a New Security Profile. Give it a name, a short description and a privacy notice URL (your own privacy page will do), then save. - Click the gear icon next to the profile and choose
Web Settings, thenEdit. - Under Allowed Return URLs, add
https://rig.soand save. It has to match exactly: no trailing slash, nowww. - Copy the Client ID and the Client Secret. Treat the secret like a password: if you share it with us, use a password manager rather than a chat window, because chat history outlives the call.
2. Apply for API access
- Go to advertising.amazon.com/about-api and click to request API access. Amazon moves this page around: if it has moved again, scroll to the footer of advertising.amazon.com and follow
Amazon Ads API. - Sign in with the same email address as your Developer account.
- Choose Direct advertiser, then Sponsored ads.
- Fill in the form and submit it. It asks what your business does and how you plan to use the API, and you confirm you comply with Amazon's licence agreement and data protection policy. If it offers to create a new advertiser account, pick your existing one instead.
- Wait for approval. Direct advertisers usually hear back in 24 to 72 hours, by email.
3. Connect your security profile to the API
- Open the link in Amazon's approval email, in a browser signed in to the same Amazon account you applied with.
- Check the page shows the client ID from step 1. If you have more than one security profile, pick that one.
- Click
Submit.
Open the email link as it is
The link is long and easy to break. Copying it across a line wrap, forwarding the email, or letting a mail scanner rewrite it all corrupt it, and the page then errors or shows no client ID. If that happens, go back to the original email and click it again rather than pasting it. Skipping this step entirely leaves you approved on paper with credentials that still fail, and Amazon's fix is under assign API access.
Not the same as Seller Central
Amazon Ads and the Selling Partner API are separate products with separate credentials. If you already connected Amazon Seller Central to Rig, none of it carries over, and there is no Connect with Amazon button on this one.
Get the refresh token
For technical audiences
Rig will run this for you
If you are not familiar with OAuth or the command line, skip this section. Ask in your shared Slack channel and we will run it with you: we send you a link, you sign in and click Allow, you paste back the address you land on, and we do the rest. We can book a call instead if you would rather.
The client ID and secret identify your security profile. The refresh token says whose advertising data it may read, and no Amazon screen shows you one: you generate it by authorising the profile against an account. Sign in as the account that can see the advertisers you want, because that is what fixes which advertisers the token can ever read.
- Check
https://rig.sois in Allowed Return URLs on the security profile'sWeb Settings, exactly as written in step 1. - Open this link with your client ID in place, and click
Allow. For advertisers in Europe, swapwww.amazon.comforeu.account.amazon.com, and in the Far East forapac.account.amazon.com.
https://www.amazon.com/ap/oa?client_id=YOUR_CLIENT_ID&scope=advertising::campaign_management&response_type=code&redirect_uri=https://rig.so- Amazon sends you to
rig.so/?code=…. Copy the value ofcodestraight away: it is single use and expires within minutes. - Exchange the code for a refresh token. Use
api.amazon.co.ukfor Europe orapi.amazon.co.jpfor the Far East:
curl -X POST https://api.amazon.com/auth/o2/token \
-d grant_type=authorization_code \
-d code=THE_CODE_FROM_THE_ADDRESS_BAR \
-d redirect_uri=https://rig.so \
-d client_id=YOUR_CLIENT_ID \
-d client_secret=YOUR_CLIENT_SECRETKeep refresh_token from the response. That is the value Rig stores, and it is long lived. The access_token next to it lasts an hour, which is long enough for the check below.
- List the profiles the token can see. Use
advertising-api-eu.amazon.comoradvertising-api-fe.amazon.comoutside North America:
curl https://advertising-api.amazon.com/v2/profiles \
-H "Authorization: Bearer YOUR_ACCESS_TOKEN" \
-H "Amazon-Advertising-API-ClientId: YOUR_CLIENT_ID"You should see one entry per advertiser and marketplace. An empty list means the wrong Amazon account signed in at the consent link: the token works, it just has nothing to read. Run the consent link again as the right account.
Connect it in Rig
- In Rig, open
Connectionsand go toSources & actions. - Search for Amazon Ads and open the card.
- LWA client ID and client secret: from your security profile's
Web Settings. - Refresh token: the token from the exchange above, or the one Rig generated with you.
- Profile IDs (optional): leave blank to sync every profile the account can see. A profile is one advertiser in one marketplace, so an account selling in five countries has at least five.
- Region (optional): leave blank to let Rig search all three regions,
na,euandfe. If you do set it, note the UK is served byeuand the US byna. - DSP advertiser IDs (optional): only for the ADSP Reports link path.
- Click
Test, thenSync.
What Rig pulls in
Amazon Ads lands in its own amazon_ads schema:
- Profiles, one per advertiser and marketplace
- Sponsored Products structure: campaigns, ad groups and keywords
- Sponsored reporting: daily performance for Products, Brands and Display
Rows carry their profile, country and currency, because Amazon reports in each profile's native currency. US rows arrive in dollars and UK rows in pounds, so any blended total needs converting rather than summing.
How far back reporting goes
Amazon retains report data for different periods per ad product, and no tool can reach past those limits:
- Sponsored Products: about 95 days
- Sponsored Brands: about 60 days
- Sponsored Display: about 65 days
Rig syncs roughly 93 days and keeps up daily from there, so history accumulates in your warehouse well beyond what Amazon itself will hand back. That is a good reason to connect earlier rather than later: the window you miss is not recoverable.
Troubleshooting
- The consent link says the client ID is unknown: the client ID was mis-copied, usually a character short. Copy it again, whole, from the security profile's
Web Settings. - The consent link says an unknown scope was requested: Amazon does not yet recognise your security profile for
advertising::campaign_management. Either API access has not been approved, or the client ID was never connected from the approval email. Finish prerequisites 2 and 3. The same cause shows up later asThe LWA client ID is not approved to use the requested scope. - It authenticates but sees no advertisers: the credentials are valid and the access is not, and this is the failure this connector produces most. The account that clicked Allow needs either a Manager Account with Admin permission over the advertisers, or, for read-only DSP, an approved ADSP Reports link. Generate the token again signed in as an account that has one.
- A profile is missing: check the region. UK profiles live under
eu, not a separate UK region, and setting the region filter too narrowly hides the rest. - Sponsored Brands or Display reports are empty: those products are not sold in every marketplace, and an advertiser with no campaigns for a product returns nothing.
- Totals look wrong across countries: you are probably summing mixed currencies. Group by
currency_codefirst. - DSP data is missing entirely: either the account has no DSP access, or you need the ADSP Reports link approved by the advertiser's admin. Request it in Manager Accounts under
Accounts→Add account→Link existing account→Request access. There is no API for this: a person has to approve it, so start it early.
What people use this for
- Manage ACOS and ad-attributed sales
- Find wasted spend across keywords and campaigns
- Compare performance across campaign types
- Track spend pacing against budget