Critical-risk tools in Ebay
35 of the 302 tools in Ebay are classified as critical risk. This page profiles those tools specifically, with recommended policy actions and the attack patterns that target them.
Every operation listed below is an action PolicyLayer recommends controlling at the transport layer. Open any tool to see the full profile, risk score, and YAML policy snippet.
Tools at critical risk
-
ebay_bulk_cancel_packagesDestructiveCancel multiple packages in one request
-
ebay_bulk_delete_ads_by_inventory_referenceDestructiveBulk delete ads by inventory reference through the eBay Marketing API.
-
ebay_bulk_delete_ads_by_listing_idDestructiveBulk delete ads by listing id through the eBay Marketing API.
-
ebay_bulk_delete_packagesDestructiveDelete multiple packages in one request
-
ebay_cancel_bundleDestructiveCancel a bundle by ID
-
ebay_cancel_packageDestructiveCancel a package by ID
-
ebay_clear_tokensDestructiveClear all stored OAuth tokens (both user tokens and client credentials). This will require re-authentication for subsequent API calls.
-
ebay_delete_adDestructiveDelete ad through the eBay Marketing API.
-
ebay_delete_ads_by_inventory_referenceDestructiveDelete ads by inventory reference through the eBay Marketing API.
-
ebay_delete_campaignDestructiveDelete campaign through the eBay Marketing API.
-
ebay_delete_email_campaignDestructiveDelete email campaign through the eBay Marketing API.
-
ebay_delete_fulfillment_policyDestructiveDelete a fulfillment policy
-
ebay_delete_inventory_itemDestructiveDelete an inventory item by SKU.\n\nRequired OAuth Scope: sell.inventory\nMinimum Scope: https://api.ebay.com/oauth/api_scope/sell.inventory
-
ebay_delete_inventory_item_groupDestructiveDelete an inventory item group
-
ebay_delete_inventory_locationDestructiveDelete an inventory location
-
ebay_delete_item_price_markdown_promotionDestructiveDelete item price markdown promotion through the eBay Marketing API.
-
ebay_delete_item_promotionDestructiveDelete item promotion through the eBay Marketing API.
-
ebay_delete_notification_destinationDestructiveDelete a notification destination
-
ebay_delete_notification_subscriptionDestructiveDelete a notification subscription
-
ebay_delete_notification_subscription_filterDestructiveDelete a subscription filter
-
ebay_delete_offerDestructiveDelete an offer
-
ebay_delete_packageDestructiveDelete a package by ID
-
ebay_delete_payment_policyDestructiveDelete a payment policy
-
ebay_delete_product_compatibilityDestructiveDelete product compatibility for an inventory item
-
ebay_delete_report_taskDestructiveDelete report task through the eBay Marketing API.
-
ebay_delete_return_policyDestructiveDelete a return policy
-
ebay_delete_sales_taxDestructiveDelete sales tax table for a jurisdiction
-
ebay_delete_sku_location_mappingDestructiveDelete SKU location mapping for a listing. Removes fulfillment center location mappings for a SKU.\n\nRequired OAuth Scope: sell.inventory\nMinimum Scope: https://api.ebay.com/o...
-
ebay_end_listingDestructiveEnd/remove an active fixed-price listing.\n\nUses the Trading API (EndFixedPriceItem).\n\nRequired: User OAuth token.
-
ebay_withdraw_offerDestructiveWithdraw a published offer
-
ebay_withdraw_offer_by_inventory_item_groupDestructiveWithdraw an offer for an inventory item group (variation listing).\n\nRequired OAuth Scope: sell.inventory\nMinimum Scope: https://api.ebay.com/oauth/api_scope/sell.inventory
-
ebay_accept_payment_disputeFinancialAccept a payment dispute and allow eBay to refund the buyer. Use this when you agree with the buyer claim.\n\nRequired OAuth Scope: sell.fulfillment\nMinimum Scope: https://api....
-
ebay_issue_refundFinancialIssue a full or partial refund for an eBay order. Use this to refund buyers for orders, including specifying the refund amount and reason.\n\nRequired OAuth Scope: sell.fulfillm...
-
ebay_register_clientFinancialRegister a third party financial application with eBay (Open Banking / PSD2). Requires valid eIDAS certificate via MTLS.
-
ebay_update_bidFinancialUpdate bid through the eBay Marketing API.
Attacks that target this class
Critical-risk tools in any server share these documented attack patterns. Each links to the full case and the defensive policy.