Walmart Just Banned Account Brokering and Account Switching. If You Emailed Your Login to an Agency, That Is Now a Suspension Risk.
On August 18, 2026, Walmart posted a release note that runs four sentences and carries more account risk than anything else Walmart has published this quarter. The Marketplace Seller Code of Conduct now prohibits account switching, account brokering, and any activity that provides access to seller accounts in an unauthorized manner. Walmart’s stated consequence for attempting to bypass these restrictions or misrepresent account ownership is corrective action up to and including account suspension or termination.
The recommendation: run an access audit on your Walmart Seller Center account this week. Not because you are brokering accounts. Because the third clause, unauthorized access, is broad enough to cover how a large share of legitimate sellers actually operate their channel, and Q4 is the worst possible quarter to find out you were on the wrong side of it.
What actually changed
Walmart already had rules in this neighborhood. The Multiple Seller Accounts Policy prohibits running more than one account without prior approval and bars terminated sellers from opening a new one. The Business Information Policy requires accurate and current business information. The Code of Conduct required you to use a business name you are legally authorized to use.
The August 18 update adds three named prohibitions on top of that framework.
Account switching. Moving operations between accounts, most obviously to escape a performance problem or a suspension attached to the original account.
Account brokering. Buying, selling, renting, or otherwise transacting in Walmart seller accounts. This is the aged-account market, and it is real. Walmart approval takes time, and there has been a steady trade in accounts that already cleared it.
Unauthorized account access. Any activity that provides access to seller accounts outside the sanctioned path. This is the clause that reaches ordinary sellers.
The public Code of Conduct guide still shows a March 2026 revision date as of this writing, so the expanded language is live in the release note ahead of the full guide text. Treat the release note as the operative statement and expect the guide to catch up.
Why the third clause is the one that matters
Here is how a normal, honest Walmart seller ends up exposed.
The brand hires an agency, a freelancer, or an overseas VA to manage the channel. Instead of provisioning a named Seller Center user with a defined role, someone emails the primary login credentials. Or the credentials live in a shared password manager vault that four contractors can open. Or the account was set up years ago by a founder who left, and the login is now a shared team address that three people use.
None of that is brokering. All of it is providing access to a seller account outside the authorized mechanism. Walmart has a user management system with named users and permission levels, and it has a sanctioned integration path for solution providers. Credential sharing is neither.
The reason this is worth acting on now rather than treating as theoretical: Walmart wrote “misrepresent account ownership” into the same sentence. When Walmart cannot tell who is actually operating the account, the shared-credential setup and the brokered account look identical from the inside. The enforcement signal is the same in both cases.
This is not a Walmart-only pattern
Three things landed inside six weeks, all pointing the same direction.
Walmart retired the ability for approved Solution Providers to create new Delegated Access keys on July 30, 2026, with existing keys working only through the end of September. The replacement is OAuth 2.0, where access is granted to a named application with defined scope rather than to a key that can be passed around.
Amazon changed how sellers delegate Seller Central access to service providers effective August 10, 2026, replacing the old invite process with a streamlined authorization flow and giving providers until September 3 to verify role coverage.
And Amazon’s updated Business Solutions Agreement takes effect on August 24, 2026, expressly prohibiting the transfer of rights or obligations under the agreement and the pledging of those rights as collateral.
Different mechanisms, one thesis. Both marketplaces are moving from “the account holder is whoever has the password” to “the account holder is the verified entity on file, and every other party touching the account is a named, scoped, revocable identity.” Anything that obscures who is operating an account is being closed off, and the deadlines cluster in September, which puts remediation directly in the path of Q4 prep.
The access audit to run this week
1. List every human and system with access to Seller Center. Include people who left. Include the agency you stopped working with in March. Include the developer who built your integration two years ago. If you cannot produce this list from Seller Center user management in ten minutes, that is the finding.
2. Kill every shared credential. Every person who touches the account gets a named user with the minimum role that lets them do their job. This is not a Walmart-specific best practice, it is the thing that makes the rest of the audit possible, and after August 18 it has a compliance dimension it did not have before.
3. Confirm registered ownership matches operating reality. If the entity that owns the brand today is not the entity on the Walmart account, fix it through Walmart’s process, not by continuing to operate the old account. This is the “misrepresent account ownership” exposure, and it is common in businesses that have gone through an acquisition, a restructure, or a founder buyout.
4. Migrate your integrations off Delegated Access keys. Existing keys stop working at the end of September. If your feed partner, repricer, or ERP connector still runs on one, you have roughly five weeks, and the window closes right as Q4 volume starts. Confirm with each provider in writing rather than assuming they handled it.
5. Enforce offboarding. Access removal on the last day, not the following month. Most unauthorized access is not malicious, it is an account nobody remembered to close.
6. Write down who is allowed to grant access. One named owner. Every other request routes through them. Without this, the audit you just ran degrades within a quarter.
The tradeoff worth naming
Doing this properly costs you speed. Shared logins are fast. Named users with scoped roles create friction, and someone will complain that they cannot do the thing they used to do. That is the cost, and it is real.
The offsetting math is straightforward. A Walmart suspension in Q4 does not cost you the days you are down. It costs the ranking, the review velocity, and the buyer confidence you spent the year building, and the recovery runs into January. Weighed against a few hours of user provisioning in August, it is not a close call.
The broader read: the era of the marketplace account as a transferable, shareable asset is ending on both Amazon and Walmart at the same time. Sellers who built processes assuming the account is a password are going to spend the next two quarters rebuilding them. Sellers who already operate with named access and clean ownership records get to skip that and spend the quarter selling.
We operate Walmart and Amazon accounts for brands as an outsourced US team, with named users, documented access, and the offboarding discipline that keeps account health out of the risk column. If you are not sure who currently has access to your Seller Center account, that is the answer, and it is worth fixing before peak. Book a call.
More in Marketplaces
See all Marketplaces insights →