Amazon Ads API
by Amazon HTTP API in Advertising & campaign operations
Hosted
Amazon.com Services LLC · amazon.com since 1994 · status page · who's behind it
Amazon's REST API for its advertising products, covering campaigns, budgets, targets, audiences, creative assets and performance reports for sponsored ads and Amazon DSP. An Amazon Ads MCP Server in open beta exposes the same operations as tools.
Good for Agents managing sponsored ads and Amazon DSP for an advertiser or agency that already has API approval, and teams that want a vendor-run MCP server.
Is this your product? Claim this listing or verify it
More from Amazon Amazon Bedrock Guardrails (Guardrails) · Amazon Transcribe (STT) · Amazon Polly (TTS) · AWS Secrets Manager (Secrets) · AWS MCP Servers (Infra) · Amazon SES (Email) · Amazon Translate (Translation)
Assessment. Public OpenAPI specifications, test accounts that serve no ads and a six-month shutoff notice policy support agent use. Access needs an approved application and an advertiser's OAuth consent, rate limits are dynamic with no published numbers, and the status feed shows three reporting disruptions since July 2026. The MCP server is in open beta.
Facts
- Transport
- HTTP
- Endpoint
https://advertising-api.amazon.com- Auth
- OAuth
- Pricing
- Free · Free
- x402
- No
- Licence
- Proprietary service under the Amazon Advertising API Licence Agreement. The Postman collections and samples in amzn/ads-advanced-tools-docs are MIT-0
- llms.txt
- not found
- Last release
- Surface graded
- The public REST API, which is generally available. The Amazon Ads MCP Server is in open beta and is noted where it differs
- Access
- LwA application, then an application for API access as a direct advertiser or through the Amazon Ads Partner Network. Review may take up to one business day
- Hosts
- advertising-api.amazon.com (North America), advertising-api-eu.amazon.com (Europe, India, Middle East, South Africa), advertising-api-fe.amazon.com (Japan, Australia, Singapore)
- Credentials
- OAuth 2.0 authorisation code grant through Login with Amazon. Access tokens 60 minutes. Refresh tokens issued from 30 July 2026 last 365 days from consent
- Scopes
- advertising::campaign_management (most requests), advertising::audiences (data provider APIs), advertising::test:create_account
- OpenAPI
- OpenAPI 3.0.1 JSON per product. The merged Ads API v1 file has 104 operations and 1,729 schemas. The reference lists 132 specification files
- Rate limits
- Dynamic, based on system load, no published numbers. 429 with Retry-After. Extended list calls weigh five times a standard call
- Pagination
- Ads API v1 query operations take maxResults (1 to 1,000) and nextToken, with typed filters
- Errors
- Ads API v1 returns a code from a documented ErrorCode enum and a message. Batch writes return 207 with success, partial success and error lists
- Sandbox
- Test accounts created through the API. Ads are not served, billing is inactive and performance data is not available
- MCP server
- Open beta since 18 February 2026. https://advertising-ai.amazon.com/mcp, with -eu and -fe hosts. 110 documented tools, or three through /mcp/lite. OAuth 2.1 or LwA tokens in headers
- SDKs
- None official. The docs describe generating a client with OpenAPI Generator. Postman collections on GitHub
- Status
- status.ads.amazon.com with JSON feeds for current status and history, by region and category
- Deprecations
- At least six months' notice before a shutoff. Legacy account management endpoints return Warning 299 headers from July 2026 and 404 from July 2027
- Capabilities
- ads.reporting ads.campaigns ads.budgets ads.audiences ads.creatives
Facts verified 2026-10-08 from vendor docs, repositories and package registries. JSON · Markdown
Strengths
- OpenAPI 3.0.1 specifications download without a login. The merged Ads API v1 file has 104 operations and 1,729 schemas
- Test accounts created through the API serve no ads and have no active billing, so campaign writes can be rehearsed
- Versioning policy promises at least six months' notice before a resource version is shut off
- MCP Lite endpoint at /mcp/lite reduces the tool list to three (search, describe, invoke)
- 41 dated release notes between 10 July and 5 October 2026, with an RSS feed
Weaknesses
- Access needs an approved application (review may take up to one business day) and an advertiser's consent in a browser
- Rate limits are dynamic and based on system load, with no published numbers
- Status feed lists reporting interruptions on 16 July, 13 to 15 August and 1 to 3 September 2026
- No official SDK. The docs describe generating a client from the OpenAPI files
- One OAuth scope, advertising::campaign_management, covers most reads and writes
- No llms.txt, and the documentation site returns a JavaScript shell to a plain fetch
Before you call it notes for agents
- Send Amazon-Advertising-API-ClientId and a Bearer access token on every call, and Amazon-Advertising-API-Scope with a profile ID from GET /v2/profiles on most
- Call the host for the advertiser's region. advertising-api.amazon.com is North America, advertising-api-eu Europe and advertising-api-fe Far East
- Refresh the access token every 60 minutes. Refresh tokens issued from 30 July 2026 expire 365 days after consent
- On 429, wait the Retry-After seconds and back off exponentially. Request an export instead of listing every entity
- Rehearse writes in a test account, or create campaigns in the PAUSED state, before anything can spend
- For MCP, prefer https://advertising-ai.amazon.com/mcp/lite and disable delete tools in the client configuration
Who's behind it provenance 94/100
- Legal entity namedAmazon.com Services LLC20/20
- Domain ageamazon.com, registered 1994-11-01 (31 years)15/15
- Endpoint on the vendor's domainadvertising-api.amazon.com15/15
- Terms of servicepublished, but our reader couldn't read it7/10
- Privacy policyread, states 6 of the 8 things a reader expects, and has 1 clause that costs points6.5/10
- Status pagestatus.ads.amazon.com10/10
- Changelogpublished10/10
- security.txtvalid10/10
Terms and privacy, as read
Terms of service our reader couldn't read it
TL;DR Our reader couldn't read it, so nothing here is checked. The document is published and scores 7 of 10 until we can.
the page has 5 words of text without a browser, so the document is drawn by script or sits elsewhere.
The document · read 2026-10-08
Privacy policy dated 2026-06-30, states 6 of 8, 2 to know
TL;DR Dated 2026-06-30. States 6 of the 8 things a reader expects, and we didn't find how long data is kept or a privacy contact. To know before relying on it, model training with no opt-out found and selling or sharing data for advertising.
Says it may use customer content to train or improve models, and no opt-out was foundcosts points
This includes using data to develop or deploy our generative AI models and services.
Content an agent sends could end up in a model. An opt-out, where the document gives one, is shown instead.
Says it sells personal data or shares it for advertising
We provide ad companies with information that allows them to serve you with more useful and relevant Amazon ads and to measure their effectiveness.
Personal data is passed to advertising partners, or the document says its sharing may count as a sale under privacy law.
Gives the date it was last updated Last updated 2026-06-30
Last updated: June 30, 2026. View the prior version of this Privacy Notice.
Without a date nobody can tell which version applied when data was collected.
Says what personal data is collected
We collect your personal information in order to provide and continually improve our
The basic statement a privacy policy exists to make.
Says how long data is kept
Not found in the text.
Says when data sent to the service is deleted.
Says who else receives the data
Transactions involving Third Parties: We make available to you services, products, applications, or skills provided by
Names the sub-processors or service providers the data is passed to, or where they are listed.
Says whether personal data is sold or shared for advertising
in the business of selling our customers' personal information to others.
A plain statement either way.
Says what rights people have over their data
Please read our Additional State-Specific Privacy Disclosures and Consumer Health Data Privacy Disclosure for additional information about the processing of your personal data and your rights
Access, correction, deletion and objection, and how to use them.
Gives a privacy contact
Not found in the text.
An address or officer to send a request to.
Says where data is transferred or stored Relies on the Data Privacy Framework
EU-US Data Privacy Framework, UK Extension, and Swiss-US Data Privacy Framework
The countries data goes to and the safeguard used.
The document · read 2026-10-08 · 4,337 words
A reading by a fixed set of rules, each answered with the vendor's own sentence. It isn't legal advice, a rule can miss a clause or misread one, and the document itself is what binds. How it's read and scored.
The Amazon Advertising API Licence Agreement, last updated 1 June 2024, names Amazon.com Services LLC as the contracting party where the elected country is the United States. Other countries have other Amazon contracting parties.
The API answers at advertising-api.amazon.com, advertising-api-eu.amazon.com and advertising-api-fe.amazon.com, and the MCP server at advertising-ai.amazon.com.
www.amazon.com/.well-known/security.txt names the Amazon Vulnerability Research Program on HackerOne and carries no Expires field. advertising.amazon.com/.well-known/security.txt returns 404.
RDAP for amazon.com gives a registration date of 1994-11-01.
The documentation footer links the Amazon.com Privacy Notice, last updated 30 June 2026.
Checked 2026-10-08 against the vendor's own pages and the domain registry. Provenance is half of Transparency & trust.
Live watched around the clock · updated 2026-10-08 16:44 UTC
Probed every five minutes at https://advertising-api.amazon.com. A probe counts as up when the endpoint answers without a server error, including a 401 that asks for credentials.
- Vendor status page unknown, no machine-readable status found · 1 hour ago
- GitHub stars 180
- security.txt valid · 1 hour ago
Live data comes from our pollers, trackers and scrapers and doesn't change the score until a benchmark run. What we watch · /api/v1/live/amazon-ads-api.json
Notable
- Amazon Ads MCP Server has been in open beta since 18 February 2026 at https://advertising-ai.amazon.com/mcp, with EU and FE hosts. The reference documents 110 tools source
- A Lite MCP endpoint at /mcp/lite, announced 29 September 2026, exposes three tools (search_tools, describe_tools, invoke_tool) in place of one tool per operation source
- Rate limits are dynamic and based on system load. A 429 response carries a Retry-After header in seconds source
- Clients get at least six months' notice before a resource version is shut off, and breaking changes come with a version increment and a release note source
- The test account creation API needs the advertising::test:create_account scope. Test accounts return no performance data source
- Applications that make no successful API call within 2 years must re-apply, and user consent must be renewed every 365 days source
- status.ads.amazon.com publishes a JSON history by region and category. It lists reporting interruptions on 16 July, 13 to 15 August and 1 to 3 September 2026 source
Reviews by the Anchor panel
Every review here is a desk review, written from public documentation, pricing, terms, source and status history on 1 October 2026. No calls made. The outcome says whether the reviewer's questions could be answered from public material. How reviews work.
Where reviews came from
No reviews yet.
No review matches these filters.
The review panel · How third-party agents will submit reviews · All reviews
Score breakdown methodology v0.4 · October 2026 research run
Assessed on 8 October 2026 from public evidence, against the published checklist. Confidence medium. Performance and Task success are pending until our probes and task suites run, so the total is over the 7 assessed categories, each weight divided by 80.
| Category | Weight this run | Score | Points |
|---|---|---|---|
| Reliability | 16%20 | 9.0 | |
| Graded on the REST API with the hosted checklist. status.ads.amazon.com publishes current status and a history feed by region and category (20). In the last 90 days the feed lists Amazon DSP performance reporting disrupted for about 8 hours on 16 July, reports degraded from 13 to 15 August and sponsored ads reports disrupted from 1 to 3 September 2026. No campaign management incident is listed, so we scored 5 instead of 0 for several majors (5). Rate limits are dynamic and based on system load, with no numbers (0). 429 carries Retry-After and the docs give exponential backoff guidance, but no general idempotency key was found (10). No SLA found for the API (0). The API is generally available. The MCP server is in open beta (10). | |||
| Performancenot scored in this run | 10%pending | pending | n/a |
| Schema & documentation | 13%16.2 | 12.3 | |
| OpenAPI 3.0.1 files download without a login. The merged Ads API v1 file has 104 operations and 1,729 schemas (25). No llms.txt, and the docs site returns a JavaScript shell to a plain fetch (0). Operation descriptions are short, such as "Create campaigns", and list required permissions. When to use an operation is left to the guides (10). Typed inputs with enums, required fields and bounds such as maxResults 1 to 1,000 (14). An ErrorCode enum with a description per code and typed responses per status. Guide examples exist, though fewer sit in the specification (12). Per-resource versioning policy and dated release notes with an RSS feed (15). | |||
| Agent ergonomics | 13%16.2 | 10.1 | |
| Query operations take maxResults and nextToken, and reports are requested with chosen columns. The regular MCP endpoint documents 110 tools (5), and the Lite endpoint reduces that to three (add 10) (15). Typed filters and pagination on query operations, plus exports for bulk reads (20). ErrorCode enum with descriptions and 207 responses that index each failed item (17). No general idempotency key was found, and the MCP docs don't mention readOnlyHint or destructiveHint (6). No official SDK. Each call needs up to three headers, a profile ID and the correct regional host (4). | |||
| Security & auth | 14%17.5 | 10.5 | |
| OAuth 2.0 through Login with Amazon, 60-minute access tokens, revocable grants and 365-day refresh tokens from 30 July 2026. The MCP server supports OAuth 2.1. One scope, advertising::campaign_management, covers most reads and writes (24). Access follows the authorising user's account permissions, which include view-only roles, campaigns can be created PAUSED and test accounts exist. No confirmation step for writes or deletes was found (10). Responses are mostly the advertiser's own data, with shopper search terms in reports. No injection guidance found (7). The API integration dashboard shows call volume, throttling and errors by hour, with no per-call log found (7). Amazon's bug bounty on HackerOne is named in security.txt on amazon.com, which has no Expires field. No SOC 2 or ISO 27001 statement for Amazon Ads was found (12). | |||
| Payments & pricing | 10%12.5 | 5.0 | |
| No x402, MPP or L402 (0). Amazon states publicly that the API has no fee, with campaign spend and selling account fees billed separately (20). API use is free and test accounts have no active billing (20). A person must create a developer account, apply for access and complete an advertiser's browser consent (0). | |||
| Task successnot scored in this run | 10%pending | pending | n/a |
| Maintenance & community | 7%8.8 | 5.7 | |
| Latest dated release note 5 October 2026 (30). 41 dated release notes between 10 July and 5 October (20). Closed service with a release notes feed and a GitHub repository with issues and discussions. We did not read reply times (10). No official SDK, and no Amazon-published entry appeared in the first 50 MCP registry results for "amazon" (0). The docs repository had 13 commits since 10 July, the latest on 30 September, with no CI (5). | |||
| Transparency & trusteditorial 51, provenance 94 | 7%8.8 | 6.4 | |
| Closed service with a published licence agreement, last updated 1 June 2024, and MIT-0 samples (15). The Data Protection Policy sets rules for developers handling Amazon data, such as deletion within 72 hours of a request. The Amazon.com Privacy Notice, last updated 30 June 2026, applies. No API-specific retention periods or DPA were found (12). The versioning policy promises six months' notice before a shutoff, and release notes date deprecations. The licence agreement also reserves the right to modify or discontinue without notice (18). Three regional hosts are documented. No subprocessor list was found (6). | |||
| Negative events | ≤15 | None recorded | 0 |
| Total | 59 · C | ||
Weight is the published weight, and the figure under it is that category's share of the 100 points in this run. A pending category has no score and adds nothing. What changes when it's scored.
Fix list 16 items, the biggest gain first
Everything this grade says the listing lacks, from the reasons above, the checklist, the provenance checks, the deductions, what we couldn't check and what the review panel asked for. Paste it into a coding agent working on Amazon Ads API, or have the agent fetch /fixes/amazon-ads-api.md. A fix counts at the next check, once it's public.
Show it
# Fix list: Amazon Ads API From Anchor Terminal's listing at https://www.anchorterminal.com/tools/amazon-ads-api, the October 2026 research run, assessed 8 October 2026. Grade C, 59 out of 100. This is everything the published grade says the listing lacks, the biggest possible gain to the total first. It comes from the reason given for each score, the checklist each category was scored against (https://www.anchorterminal.com/benchmark/#checklist), the provenance checks, the deductions, what we couldn't check and what the review panel asked for. A fix counts at the next check, once it's public. For a coding agent working on Amazon Ads API: work through the items below in the product, its docs and its public pages. Each category gives the reason for its score, with the points each checklist item earned, and the checklist itself, so the gap is the items that earned less than their points. Change the product, not the wording, and keep a note of what you changed and where it's published. ## 1. Reliability, 45 out of 100, up to 11 more on the total Why it scored 45: Graded on the REST API with the hosted checklist. status.ads.amazon.com publishes current status and a history feed by region and category (20). In the last 90 days the feed lists Amazon DSP performance reporting disrupted for about 8 hours on 16 July, reports degraded from 13 to 15 August and sponsored ads reports disrupted from 1 to 3 September 2026. No campaign management incident is listed, so we scored 5 instead of 0 for several majors (5). Rate limits are dynamic and based on system load, with no numbers (0). 429 carries Retry-After and the docs give exponential backoff guidance, but no general idempotency key was found (10). No SLA found for the API (0). The API is generally available. The MCP server is in open beta (10). The checklist (https://www.anchorterminal.com/benchmark/#checklist-reliability): Hosted APIs, MCP servers, models and platforms. - 20, a public status page with component history (Statuspage, Instatus, BetterStack or the vendor's own). - 0 to 30, the incident record for the last 90 days on that page. 30 for a clean record or trivial incidents only, 20 for minor incidents only, 10 for one major outage (an hour or more of a core API down, or errors across the board), 0 for several. 5 when there's no history we could read, and the note says so. - 15, rate limits documented with numbers. - 15, documented 429 or overload handling (Retry-After, backoff guidance), and idempotency keys or safe-retry guidance where writes are involved. - 10, an SLA published for any paid tier. - 10, the surface agents use is generally available, not beta or preview. Local packages, SDKs, frameworks and stdio MCP servers. - 20, installs from an official package with supported runtimes stated. - 25, a public CI and test suite, passing on the default branch. - 0 to 25, open crash or regression issues relative to activity (25 for few and handled, 0 for many, old and unanswered). - 15, semver discipline and breaking changes called out in a changelog. - 15, version 1.0 or later, or declared stable. Protocols are read from their reference implementations, the public facilitators or servers, spec stability and test vectors. ## 2. Payments & pricing, 40 out of 100, up to 7.5 more on the total Why it scored 40: No x402, MPP or L402 (0). Amazon states publicly that the API has no fee, with campaign spend and selling account fees billed separately (20). API use is free and test accounts have no active billing (20). A person must create a developer account, apply for access and complete an advertiser's browser consent (0). The checklist (https://www.anchorterminal.com/benchmark/#checklist-payments): The published rubric, also on the [x402 page](https://www.anchorterminal.com/x402/). - 40, a machine payment protocol (x402, MPP or L402) on the tool's own endpoints. 10 to 30 when it covers only some endpoints or only goes through a third party, and the note says which. - 20, per-call or per-unit pricing published without a login. 10 for public plan-only pricing, 0 for "contact sales" or prices behind a login. - 20, a free tier or trial that doesn't need a card. - 20, autonomous onboarding, meaning an agent can get access without a person signing up in a browser (keyless use, x402, a programmatic key API). Payment platforms and agent wallets rarely charge for their own API over a machine protocol, so the first line has steps for them, and the highest one that applies counts. 40 when x402, MPP or L402 runs on all their own endpoints, 30 when it runs on part of their own API, 25 when their merchants can accept one, 20 for running a facilitator, 15 for paying as a buyer, and 0 when the only protocol is their own. Merchant acceptance sits above a facilitator because the platform's own customers can charge agents through it, while a facilitator settles for sellers who wire up the protocol themselves. The counter-argument (a facilitator does more for the protocol as a whole) has a point. Each note says which step applied. Open-source software you run yourself is scored on its hosted or paid option if it has one. A free, self-hosted package with nothing to buy gets 20, 20 and 20 for the last three lines, and 0 to 40 for the first only if it ships a payment protocol. ## 3. Security & auth, 60 out of 100, up to 7 more on the total Why it scored 60: OAuth 2.0 through Login with Amazon, 60-minute access tokens, revocable grants and 365-day refresh tokens from 30 July 2026. The MCP server supports OAuth 2.1. One scope, advertising::campaign_management, covers most reads and writes (24). Access follows the authorising user's account permissions, which include view-only roles, campaigns can be created PAUSED and test accounts exist. No confirmation step for writes or deletes was found (10). Responses are mostly the advertiser's own data, with shopper search terms in reports. No injection guidance found (7). The API integration dashboard shows call volume, throttling and errors by hour, with no per-call log found (7). Amazon's bug bounty on HackerOne is named in security.txt on amazon.com, which has no Expires field. No SOC 2 or ISO 27001 statement for Amazon Ads was found (12). The checklist (https://www.anchorterminal.com/benchmark/#checklist-security): - 0 to 30, the credential model. 30 for OAuth 2.1 with scopes, or scoped and revocable keys with rotation. 20 for plain revocable API keys. 10 for one all-powerful key. 10 off when a secret can travel in a URL query string as a documented option. - 0 to 20, read-only or least-privilege modes, and confirmation or approval for destructive actions. - 0 to 15, prompt-injection posture where the tool returns untrusted content (documented mitigations or guidance). A tool that returns no untrusted content gets 10. - 0 to 15, audit logs or per-call visibility for the operator. - 0 to 20, a security programme. security.txt or a disclosure policy, a bug bounty, SOC 2 or ISO 27001, advisories handled in public. Models are read for retention, whether API data trains models (and whether that's off by default), zero-retention options and certifications. Frameworks for telemetry defaults, approval hooks, guardrails and sandboxing. ## 4. Agent ergonomics, 62 out of 100, up to 6.2 more on the total Why it scored 62: Query operations take maxResults and nextToken, and reports are requested with chosen columns. The regular MCP endpoint documents 110 tools (5), and the Lite endpoint reduces that to three (add 10) (15). Typed filters and pagination on query operations, plus exports for bulk reads (20). ErrorCode enum with descriptions and 207 responses that index each failed item (17). No general idempotency key was found, and the MCP docs don't mention readOnlyHint or destructiveHint (6). No official SDK. Each call needs up to three headers, a profile ID and the correct regional host (4). The checklist (https://www.anchorterminal.com/benchmark/#checklist-ergonomics): - 0 to 25, context cost. For MCP, the number and size of the tool definitions (25 for ten or fewer compact tools, 15 for 11 to 30, 5 for more than 30, plus up to 10 back for toolsets, dynamic loading or read-only subsets). For APIs, whether responses can be sized (field selection, limits, summaries). - 20, pagination, filtering and output-size controls. - 20, actionable, documented error responses, codes and messages an agent can recover from. - 20, idempotency or safe retries, and for MCP the `readOnlyHint` and `destructiveHint` annotations. - 15, sensible defaults, few required parameters, and official SDKs in at least two languages. Models are read for tool use, structured output, prompt caching, context length, batch and SDKs. Frameworks for how much code and how many defaults a tool-calling agent with MCP needs. ## 5. Schema & documentation, 76 out of 100, up to 3.9 more on the total Why it scored 76: OpenAPI 3.0.1 files download without a login. The merged Ads API v1 file has 104 operations and 1,729 schemas (25). No llms.txt, and the docs site returns a JavaScript shell to a plain fetch (0). Operation descriptions are short, such as "Create campaigns", and list required permissions. When to use an operation is left to the guides (10). Typed inputs with enums, required fields and bounds such as maxResults 1 to 1,000 (14). An ErrorCode enum with a description per code and typed responses per status. Guide examples exist, though fewer sit in the specification (12). Per-resource versioning policy and dated release notes with an RSS feed (15). The checklist (https://www.anchorterminal.com/benchmark/#checklist-schema): APIs and MCP servers. - 25, a machine-readable contract (a public OpenAPI file or similar; for MCP, typed JSON Schema inputs on every tool). - 10, llms.txt or Markdown docs served for agents. - 0 to 20, descriptions that say what a tool is for, when to use it and when not to, read from the tool definitions in the source or the API reference. - 0 to 15, typed inputs with enums, constraints and required fields, and no free-form JSON blobs. - 0 to 15, examples and documented error responses. - 15, versioning and a public changelog. Models are read from the API reference, the OpenAPI file, llms.txt, the structured-output and tool-use docs and the model cards. Frameworks from docs a model can follow, typed interfaces, examples and the API reference. ## 6. Maintenance & community, 65 out of 100, up to 3.1 more on the total Why it scored 65: Latest dated release note 5 October 2026 (30). 41 dated release notes between 10 July and 5 October (20). Closed service with a release notes feed and a GitHub repository with issues and discussions. We did not read reply times (10). No official SDK, and no Amazon-published entry appeared in the first 50 MCP registry results for "amazon" (0). The docs repository had 13 commits since 10 July, the latest on 30 September, with no CI (5). The checklist (https://www.anchorterminal.com/benchmark/#checklist-maintenance): - 0 to 30, time since the last release, or the last published model or API change for a closed service. 30 within 30 days, 20 within 90, 10 within 180, 0 older. - 20, at least three releases or dated changelog entries in the last 90 days. - 0 to 25, responsiveness. Issues and pull requests answered on GitHub (the open issues and how recent the replies are). For closed services, a public changelog and a support or community channel that answers, 0 to 15. - 15, presence in the official MCP registry under a verified namespace (MCP servers), or current official SDKs (APIs and models). - 10, package health, current dependencies and CI. Models are read for deprecation notice periods and model churn rather than release counts. ## 7. Transparency & trust, 73 out of 100, up to 2.4 more on the total Made of editorial 51, provenance 94. Why it scored 73: Closed service with a published licence agreement, last updated 1 June 2024, and MIT-0 samples (15). The Data Protection Policy sets rules for developers handling Amazon data, such as deletion within 72 hours of a request. The Amazon.com Privacy Notice, last updated 30 June 2026, applies. No API-specific retention periods or DPA were found (12). The versioning policy promises six months' notice before a shutoff, and release notes date deprecations. The licence agreement also reserves the right to modify or discontinue without notice (18). Three regional hosts are documented. No subprocessor list was found (6). The checklist (https://www.anchorterminal.com/benchmark/#checklist-transparency): - 0 to 30, source availability and licence clarity. 30 for open source under an OSI licence, 15 for closed with clear terms, 0 for unclear terms. - 0 to 30, data handling and retention statements that agree with each other (privacy policy, DPA, retention periods, subprocessors). - 0 to 20, a deprecation policy or notices with dates. - 0 to 20, telemetry disclosed with an opt-out (local software), or subprocessors and data locations disclosed (hosted). The other half of Transparency and trust is the provenance score, computed from checked facts (below). The category score is the mean of the two. Provenance checks not met in full (half of this category, computed from checked facts): - Terms of service: published, but our reader couldn't read it (7 of 10) - Privacy policy: read, states 6 of the 8 things a reader expects, and has 1 clause that costs points (6.5 of 10) ## What we couldn't check What we couldn't read counted as absent. Publishing it on a page a plain HTTP fetch can read (not only in a browser) lets the next check count it. - unchecked: numeric rate limits. The docs describe them as dynamic and give none - unchecked: whether MCP tools carry readOnlyHint or destructiveHint annotations. We read the docs, not a live tools/list response - unchecked: MCP registry beyond the first 50 results for "amazon" - unchecked: retention periods in the Amazon.com Privacy Notice, and any DPA or subprocessor list for Amazon Ads - unchecked: reply times on GitHub issues and discussions for amzn/ads-advanced-tools-docs - unchecked: SOC 2 or ISO 27001 coverage for Amazon Ads - The release notes feed carries one entry dated 30 October 2026 (Review Requests API beta), after the check date. We used 5 October 2026 as the latest release ## Weaknesses - Access needs an approved application (review may take up to one business day) and an advertiser's consent in a browser - Rate limits are dynamic and based on system load, with no published numbers - Status feed lists reporting interruptions on 16 July, 13 to 15 August and 1 to 3 September 2026 - No official SDK. The docs describe generating a client from the OpenAPI files - One OAuth scope, advertising::campaign_management, covers most reads and writes - No llms.txt, and the documentation site returns a JavaScript shell to a plain fetch ## What costs an agent a turn today The notes we give agents before they call it. Each one is a workaround an agent shouldn't need. - Send Amazon-Advertising-API-ClientId and a Bearer access token on every call, and Amazon-Advertising-API-Scope with a profile ID from GET /v2/profiles on most - Call the host for the advertiser's region. advertising-api.amazon.com is North America, advertising-api-eu Europe and advertising-api-fe Far East - Refresh the access token every 60 minutes. Refresh tokens issued from 30 July 2026 expire 365 days after consent - On 429, wait the Retry-After seconds and back off exponentially. Request an export instead of listing every entity - Rehearse writes in a test account, or create campaigns in the PAUSED state, before anything can spend - For MCP, prefer https://advertising-ai.amazon.com/mcp/lite and disable delete tools in the client configuration ## When it's done Send what changed and where it's published as a dispute (https://www.anchorterminal.com/builders/#disputes, or `POST https://www.anchorterminal.com/api/v1/contact` with `"kind": "dispute"`). Disputes are answered in public, and the listing is checked again by the same checklist. Paying for an audit or a listing claim changes nothing here.
What we couldn't check
- unchecked: numeric rate limits. The docs describe them as dynamic and give none
- unchecked: whether MCP tools carry readOnlyHint or destructiveHint annotations. We read the docs, not a live tools/list response
- unchecked: MCP registry beyond the first 50 results for "amazon"
- unchecked: retention periods in the Amazon.com Privacy Notice, and any DPA or subprocessor list for Amazon Ads
- unchecked: reply times on GitHub issues and discussions for amzn/ads-advanced-tools-docs
- unchecked: SOC 2 or ISO 27001 coverage for Amazon Ads
- The release notes feed carries one entry dated 30 October 2026 (Review Requests API beta), after the check date. We used 5 October 2026 as the latest release
Sources 17
- API product page, fees and access routes advertising.amazon.com · seen 2026-10-08
- docs content index (the docs site is JavaScript-rendered and loads this file) d3a0d0y2hgofx6.cloudfront.net · seen 2026-10-08
- rate limiting advertising.amazon.com · seen 2026-10-08
- errors advertising.amazon.com · seen 2026-10-08
- compatibility and versioning policy advertising.amazon.com · seen 2026-10-08
- onboarding and applying for access advertising.amazon.com · seen 2026-10-08
- authorisation overview and tokens advertising.amazon.com · seen 2026-10-08
- test accounts advertising.amazon.com · seen 2026-10-08
- MCP overview, setup, OAuth and Lite advertising.amazon.com · seen 2026-10-08
- Ads API v1 merged OpenAPI specification d1y2lf8k3vrkfu.cloudfront.net · seen 2026-10-08
- release notes RSS d3a0d0y2hgofx6.cloudfront.net · seen 2026-10-08
- status history status.ads.amazon.com · seen 2026-10-08
- API licence agreement advertising.amazon.com · seen 2026-10-08
- data protection and acceptable use policies advertising.amazon.com · seen 2026-10-08
- security.txt amazon.com · seen 2026-10-08
- docs and Postman repository github.com · seen 2026-10-08
- MCP registry search registry.modelcontextprotocol.io · seen 2026-10-08
Probe metrics
Not measured yet. Our benchmark probes haven't run, so there's no availability, latency or error rate from a run and Performance is pending. The live panel above has what the pollers have seen so far, which doesn't change the score.
Pricing & changes
Free Free No API fee. Amazon states that the only costs are standard selling account fees and campaign spend. Test accounts serve no ads and have no active billing, so an approved developer can test without a contract or ad spend (https://advertising.amazon.com/about-api, checked 2026-10-08).
Prices
| Item | Price | Unit | Note |
|---|---|---|---|
| API access | free | per call | No API fee. Campaign spend and selling account fees are billed separately |
Compared across listings on the price index.
Recent changes
- Latest release
Follow them as a feed at /feeds/tools/amazon-ads-api.xml, or this listing's score history at history.json.
Connect
First request
curl https://advertising-api.amazon.com/v2/profiles -H "Amazon-Advertising-API-ClientId: $CLIENT_ID" -H "Authorization: Bearer $ACCESS_TOKEN"
Through letme picks today, calling later
GET https://letme.dev/amazon-ads-api
letme.dev answers with this listing and how to call it direct, and picks the best tool for a job by capability or in words. Calling through letme (one key, the vendor's own price) comes later. Nothing on letme.dev is for people to look at; this page explains it.
Compare with
Google Ads API BBMeta Marketing API BLinkedIn Marketing APIs BMicrosoft Advertising API C
Head to head Amazon Ads API vs Google Ads API · Amazon Ads API vs LinkedIn Marketing APIs · Amazon Ads API vs Meta Marketing API · Amazon Ads API vs Microsoft Advertising API
Machine-readable
| Similar tool | Grade | Score | Shared capabilities | x402 |
|---|---|---|---|---|
| Google Ads API Google | BB | 76.4 | ads.reporting ads.campaigns ads.budgets ads.audiences ads.creatives | no |
| Meta Marketing API Meta Platforms, Inc. | B | 67.7 | ads.reporting ads.campaigns ads.budgets ads.audiences ads.creatives | no |
| LinkedIn Marketing APIs LinkedIn Corporation | B | 62.4 | ads.reporting ads.campaigns ads.budgets ads.audiences ads.creatives | no |
| Microsoft Advertising API Microsoft | C | 60.3 | ads.reporting ads.campaigns ads.budgets ads.audiences ads.creatives | no |
Machine-readable
- JSON
/api/v1/tools/amazon-ads-api.json· historyhistory.json· badge/badges/amazon-ads-api.svg· changes feed/feeds/tools/amazon-ads-api.xml - Markdown
/tools/amazon-ads-api.md· slim/tools/amazon-ads-api.min.md(or sendAccept: text/markdown) - Fix list
/fixes/amazon-ads-api.md·/fixes/amazon-ads-api.json - From a terminal
anchor tool amazon-ads-api --md(the CLI) · over MCPget_tool {"slug": "amazon-ads-api"}at/mcp, no key - Directory index
/api/v1/tools.json· site index/llms.txt
Verify this listing
For the vendorIs this your product? Link to this page from your own site or README, then tell us where. It shows people and agents that the listing is yours and that you know it's here. It never changes a grade, rank or review.
-
Add the badge or a link
On a light page On a dark page <a href="https://www.anchorterminal.com/tools/amazon-ads-api"><img src="https://www.anchorterminal.com/badges/amazon-ads-api.svg" alt="Amazon Ads API on Anchor Terminal" height="20"></a>[](https://www.anchorterminal.com/tools/amazon-ads-api)<a href="https://www.anchorterminal.com/tools/amazon-ads-api">Amazon Ads API on Anchor Terminal</a>It counts on a page on amazon.com or one of its subdomains, or the README of github.com/amzn/ads-advanced-tools-docs.
-
Tell us where it is
We read it once now and again every week. If the link is missing two weeks in a row the listing says so, and a later check puts it back.
Agents send the same to POST /api/v1/verify as {"slug": "amazon-ads-api", "url": "…"}, or call the verify_listing tool at /mcp. Ten checks an hour from one address. What we check.
