Back to overview

Improved API authorization for SSO integrations

Placed on:8 September 2026

Starting September 8, we are introducing an improved authorization flow for API integrations that use Single Sign-On (SSO). From now on, partners, advertisers and suppliers decide for each integration which data and functionalities they share with their integration partner. Users no longer grant access to the entire API, but only select the necessary components. This way, control over data is maintained and API access is better aligned with the services provided by each integration partner.

What is changing?
Previously, integrations using SSO automatically received access to the full API after authorization.

With the new authorization flow, users will select:

  • Which API components (resources) the integration partner can access
  • Which permissions are granted: read-only or manage

The API components relevant to the selected integration partner will be pre-selected by default. Users need to review the selection and, if necessary, deselect specific components before completing the authorization.

Who is affected?
This change applies to:

  • New API integrations via SSO
  • Existing SSO integrations that need to be re-authorized

Existing integrations will continue to function until their authorization expires. When creating a new integration or renewing an existing one, users will go through the updated authorization flow.


What does this mean for API users?

When creating or renewing an integration, users will now explicitly choose which API components and permissions are granted.

For a detailed explanation of the new authorization experience, including a step-by-step guide, please refer to the article on the Partnerplatform.


What does this mean for integration partners?
No technical changes are required for integration partners or intermediaries. To help users complete the authorization correctly, we recommend clearly documenting which API components and permissions are required for specific functionalities within your integration.

Requests to API resources for which the required permission has not been granted will return a 403 Forbidden response. Granted permissions can be inspected by decoding the token, making it easier to identify missing permissions.

Permission overview

A complete overview of the available API scopes and permissions can be found in the permissions overview.

Rollout planning
The renewed authorization flow will be rolled out in phases.

September 8
The new flow will go live for the following integration partners:

  • EffectConnect
  • ESS
  • FiveX
  • GoedGepickt
  • Staxxer
  • ChannelEngine*
  • MarktMentor*
  • Productsup*

* These integration partners already went live as part of a pilot on August 25.

September 22

The new authorization flow will go live for all other integration partners.

Client Credentials flow
This change currently applies only to integrations that use Single Sign-On (SSO). Integrations using the Client Credentials flow are not affected at this time. More information about Fine-Grained Access for Client Credentials integrations will be shared in Q4 2026.