Set up your own
Login With Amazon app.
Create a Login With Amazon (LWA) security profile that VelaReach uses to connect your Amazon Advertising accounts — on your own credentials, your own rate limits, your own branded consent screen. Takes about 12 minutes of clicking, plus an Amazon Advertising API access review if you don’t already have one.
- · You already have Amazon Advertising API access approved on a developer account
- · You run a brand-owned ad ops team and want isolated data flow
- · You want your own Login With Amazon consent screen on the OAuth dialog
- · You operate at high volume and want your own rate-limit pool
- · You don’t have an Amazon Developer account yet
- · You haven’t been approved for Advertising API access
- · You want to be connected in the next 60 seconds
- · You only run Amazon ads in a single region and don’t need data isolation
Before you begin
- An Amazon Advertising account at advertising.amazon.com with at least one active campaign.
- An Amazon Developer account at developer.amazon.com — this is separate from your Seller / Vendor / Ads logins.
- Amazon Advertising API access approved (apply via advertising.amazon.com/API/docs/en-us/guides/onboarding/apply-for-access). Review takes 1–2 weeks if you’re not already approved.
- Knowledge of which region (NA / EU / FE) your Amazon Ads accounts live in — check the URL after you sign in to advertising.amazon.com.
- Your VelaReach workspace already created and you’re logged in as an admin.
Create a Login With Amazon security profile
Sign in to developer.amazon.com/loginwithamazon. Hover the Apps & Services menu and pick Login with Amazon. On the LWA console click Create a New Security Profile.
Name it something recognisable — this string appears on the OAuth consent screen.
Add the VelaReach redirect URL to Web Settings
On the LWA dashboard you’ll now see your new VelaReach-Ads security profile. Click the gear icon → Web Settings. Scroll to Allowed Return URLs and paste this exact URL:
Amazon is unforgiving about trailing slashes — the URL must match character-for-character.
Copy your Client ID and Client Secret
Back on the LWA dashboard, click the gear icon next to VelaReach-Ads and choose Web Settings again. At the top of the page Amazon displays your Client ID and Client Secret. Click Show Secret to reveal the secret value.
Treat the Client Secret like a password — never paste it in chat or email.
Confirm Advertising API access is approved
The LWA security profile is half the puzzle — the other half is having Amazon Advertising API access attached to your developer account. Visit advertising.amazon.com/API/docs and check whether your account shows an active API access approval.
If you see “Apply for access”, fill out the application form — you’ll be asked for a use case description, expected call volume, and the security profile you just created. Approval usually arrives within 1–2 weeks.
Identify your Amazon Ads region
Open advertising.amazon.com in another tab, sign in, and look at the URL. Amazon will redirect you to one of three regional dashboards — this tells you which region your tokens need to be issued for.
- · URL contains advertising.amazon.com with US/CA/MX/BR locale → NA (North America)
- · URL contains advertising.amazon.co.uk / .de / .fr / .it / .es → EU
- · URL contains advertising.amazon.co.jp / .com.au / .in → FE (Far East)
Note your region down — you’ll select it in the next step. If you advertise in multiple regions, you’ll need to repeat the BYO connection once per region using the appropriate Amazon Ads account.
Paste credentials into VelaReach
Back in VelaReach: Settings → Integrations → click the Amazon Ads card → Manage → Advanced tab → Set up BYO app. The wizard opens. On the credentials step:
- · Pick the region you noted in Step 5 from the Region dropdown (NA / EU / FE)
- · Paste the Client ID from Step 3 (starts with amzn1.application-oa2-client.)
- · Paste the Client Secret from Step 3
Click Test & save. VelaReach makes a live call to Amazon’s regional advertising endpoint with your credentials and runs validation checks inline.
Verify the live test passes, then reconnect
You should see green check marks next to:
- · Credentials format — Client ID and secret look well-formed
- · Redirect URL whitelisted — matches your LWA Web Settings
- · Security profile is Live — not in draft state
- · Region endpoint reachable — Amazon’s regional API responded
Click Reconnect now → to run the OAuth flow through your new security profile. The Login With Amazon consent screen will display your security profile name (VelaReach-Ads) rather than VelaReach’s shared one. After consent, VelaReach exchanges the code for a refresh token and your Amazon Ads account picker will reappear with all available accounts in the selected region.
After reconnecting, what changes?
- · All historical Sponsored Products / Brands / Display data
- · Your account picker selection (which Amazon Ads accounts are tracked)
- · ACoS / TACoS / ROAS targets and pacing rules
- · Scheduled reports and Slack notifications
- · Every keyword harvest list, negative tag, and saved view
- · OAuth refresh token revoked and re-minted via your LWA profile
- · Card shows violet BYO app pill plus region badge
- · Consent screen on future reconnects displays your security profile name
- · Audit log records who switched and when
- · API calls count against your regional rate limit pool