Skip to main content

Amazon Publisher Services

The Amazon Publisher Services (APS) source downloads reporting files from the SFTP server managed by APS.

Before you begin​

Generate an SSH key pair and register its public key in the APS Portal under Admin → S3 Credentials → Add Public Key. Keep the private key and its passphrase secure.

Your Publisher UUID is the UUID in the APS reporting folder name:

aps-download-publisher-<publisher-uuid>

Source setup​

Open the Amazon Publisher Services source in Extract and enter:

  1. Publisher UUID — the UUID APS uses as the SFTP username.
  2. SSH Private Key — the complete private key, including the -----BEGIN OPENSSH PRIVATE KEY----- and ending lines.
  3. SSH Private Key Passphrase — the passphrase used when the key was generated. Leave this empty only for an unencrypted key.

Extract encrypts the private key and passphrase at rest. The connector uses port 22 and only reads report files.

Connection setup​

After the source login succeeds, configure the connection schedule, destination settings, and schema migration policy. The optional Report ID Filter limits extraction to one APS report ID; leave it empty to ingest all reports.

Rotate an SSH key​

  1. Generate a new key pair.
  2. Register the new public key in the APS Portal.
  3. Replace the private key and passphrase in the existing Extract source and verify the login.
  4. Revoke the old public key in APS only after the new key succeeds.

Authentication​

This connector authenticates to Amazon Publisher Services (APS) using SFTP over SSH (not AWS access keys).

To set up authentication, you’ll need:

  • Publisher UUID (publisher_uuid)
    Your APS publisher identifier. Enter it as a UUID (the connector will normalize formatting).

  • SSH private key (ssh_private_key)
    The private key APS provides/authorizes for SFTP access. Paste the full key contents (including the -----BEGIN ...----- / -----END ...----- lines).

  • SSH private key passphrase (ssh_private_key_passphrase, optional)
    Provide this only if your private key is encrypted with a passphrase.

Optional:

  • Report ID filter (report_id_filter)
    If set, the connector will only ingest files matching that APS reportId.

After saving these values, use the connector’s Test connection action to verify the SFTP login.

Source Setup Guide​

To set up the Amazon Publisher Services source, you’ll need access to the APS SFTP endpoint and an SSH private key associated with your APS publisher account.

  • An APS Publisher UUID (from Amazon Publisher Services).
  • An SSH private key that APS accepts for SFTP access.
  • (Optional) The passphrase for the private key, if it’s encrypted.
  • (Optional) A specific Report ID to limit which reports are synced.

Configure the source in Data Pipeline​

Provide the following configuration values:

  • Publisher UUID (publisher_uuid)
    Your APS publisher identifier. Use the UUID value provided by APS.

  • SSH private key (ssh_private_key)
    Paste the full private key contents (PEM/OpenSSH format), including the BEGIN/END lines.

  • SSH private key passphrase (ssh_private_key_passphrase, optional)
    Required only if your private key is encrypted.

  • Report ID filter (report_id_filter, optional)
    If set, the connector will only sync data for the specified report ID.

Network access​

The connector connects to APS over SFTP (port 22). Ensure your network/firewall rules allow outbound connections to the APS SFTP host provided by Amazon Publisher Services.

Connection Setup Guide​

To connect to Amazon Publisher Services, you’ll authenticate via APS SFTP using your Publisher UUID and an SSH private key.

  • An active Amazon Publisher Services account with access to the APS reporting export.
  • Your Publisher UUID (from APS).
  • An SSH private key that APS accepts for SFTP access.
    • If your private key is encrypted, you’ll also need its passphrase.

Set up APS SFTP access​

  1. In Amazon Publisher Services, enable SFTP access for reporting exports (if not already enabled).
  2. Add/register your SSH public key in APS (APS uses this to authenticate your SFTP login).
  3. Keep the corresponding SSH private key available to paste into the connector configuration.

Configure the source in the UI​

Fill in the following fields:

  • Publisher UUID: Your APS publisher identifier (UUID format).
  • SSH Private Key: The full private key contents (for example, the entire -----BEGIN ... PRIVATE KEY----- block).
  • SSH Private Key Passphrase (optional): Only required if your private key is encrypted.
  • Report ID Filter (optional): If provided, the connector will only sync data for the specified report ID.

Test the connection​

After saving, run Test connection. A successful test confirms the connector can authenticate to APS over SFTP with the provided UUID and SSH key.

Troubleshooting​

  • Failed to parse SSH private key — confirm the entire OpenSSH private key was pasted and that its passphrase is correct.
  • SFTP authentication failed — confirm the matching public key is active in APS and the username is the Publisher UUID, not an email address.
  • Connection refused or timed out — verify that outbound port 22 is allowed.
  • Unexpected report layout — contact APS if CSV files are not exposed in either reportId/versionId/executionDate or streamId/versionId/date/hour folders. Extract supports both layouts, with or without the chroot-hidden aps-download-publisher-<publisher-uuid> prefix.

Data streams​

report​

Loading ....

Schema ERD​

Explore the interactive entity relationship diagram for Amazon Publisher Services.

Open page