On Kuudo Pro and Kuudo Scale, your agents reach Amazon Ads through Kuudo's managed, verified Amazon Ads app, so you never register an Amazon Ads API app of your own. The account owner grants consent to that app once, with Login with Amazon, and the authorization becomes a remote identity: a stored grant your agents and tools reference instead of asking again.
One authorization point for many accounts
The app is the authorization nexus. Each Amazon Ads account an agent works on is authorized once, by someone who can grant access to it, and then sits beside every other authorized account. An agent connected to Kuudo reaches every account and advertising profile it has been authorized for from one connection, the way single sign-on lets one sign-in reach many applications.
This is what changes for teams that run more than one account:
- Agencies bring each client's account in with that client's one-time consent, then run every client from the same agent and the same Skills, without a separate app, credential set or connection per client.
- Brands with several accounts or marketplaces authorize each one once and work across them in one conversation.
- Scale is part of the design: the authorization point is built to hold thousands of account authorizations, not a handful.
Invite an account owner to grant access
An agency does not need its client's login to bring an account in. It creates an authorization invitation for the client's Amazon Ads account, or Selling Partner account, and Kuudo returns a secure, time-limited link. The agency sends that link to the client, the client opens it and grants consent to Kuudo's app, and the account joins the agency's authorizations. The client grants access directly to the app, and the agency never handles the client's Amazon sign-in.
Other tools and developers can use the same authorizations
Platforms, tools and developers do not have to register their own Amazon Ads app or build their own consent flow to work with these accounts. Kuudo Pro and Kuudo Scale include the developer surface for it, API, OAuth and MCP: a tool sends the account owner through Kuudo's consent flow, gets the remote identity back, and works through the accounts it was granted.
The same authorizations serve the Amazon Ads MCP in your AI client and any other tool your team connects, so an account is authorized once for all of them.
Bring your own Amazon app on Community
Kuudo Community connects with your own public or private Amazon app credentials instead (bring your own app, BYOA). The managed, verified apps for the Amazon Ads API and the Selling Partner API (SP-API), with no app registration and no compliance overhead, are part of Kuudo Pro and Kuudo Scale.
Related
- MCP Client Configuration: how your AI client authenticates to your Kuudo MCP server, which is separate from how Kuudo is authorized on Amazon.
- Amazon Ads MCP tools reference: the operations an authorized agent can call.