Question re security - Amazon Affiliate

2 replies
I have a website being developed by a 3rd party and part of what he needs to do is to display links to different Amazon products using the API.

It seems that in order to access the products, one need to use the Key ID and Secret Access Key. I am concerned that the 3rd party could then potentially divert any earnings I might make to his account.

So my question is, does this mean I'll have to divulge the codes to him, especially the Secret Access Key? Or could I get a way with just divulging the Access Key ID? If both codes need to be divulged, can I get a new Secret Access Key and disable the old one?


thanks...
#affiliate #amazon #question #security
  • Profile picture of the author cashcow
    You do need to give them the codes if you want them to put the Amazon stuff on there. The codes are just for communicating with the API - I dont think they would divert your earnings. If you get different codes later on, then the stuff you have developed will no longer work.

    Maybe you should hire someone you trust more?

    Lee
    Signature
    Gone Fishing
    {{ DiscussionBoard.errors[2967248].message }}
  • Profile picture of the author getsmartt
    He cannot use the codes to divert your earnings, but, he could cause you other headaches if he really wanted to. He (she) should be able to develop the application using his/her own keys and then give you a place to change them when delivered.

    If this is not possible, you could create a new set of keys for them to use during development, and replace them with you current keys upon delivery, and then deactivate the temporary keys.

    Originally Posted by all4won View Post

    I have a website being developed by a 3rd party and part of what he needs to do is to display links to different Amazon products using the API.

    It seems that in order to access the products, one need to use the Key ID and Secret Access Key. I am concerned that the 3rd party could then potentially divert any earnings I might make to his account.

    So my question is, does this mean I'll have to divulge the codes to him, especially the Secret Access Key? Or could I get a way with just divulging the Access Key ID? If both codes need to be divulged, can I get a new Secret Access Key and disable the old one?


    thanks...
    Signature

    Was mich nicht umbringt, macht mich stärker

    {{ DiscussionBoard.errors[2967507].message }}

Trending Topics