AWS Partner Revenue Measurement for SaaS: Choose Tagging or User Agent

AWS won't take your FTR report until the product is Partner Revenue Measurement enabled. For SaaS, that means a resource tag or a User Agent string, and the right one depends on whose AWS account your resources sit in.

Sabrina Xie
Sep 29, 2026

AWS Partner Revenue Measurement (PRM) is a set of AWS capabilities that measures the AWS consumption a partner’s product drives, in the partner’s own accounts and in its customers’. A SaaS product joins it by marking its resources with an aws-apn-id tag or its API calls with a User Agent string. Which one fits depends on whose account those resources sit in, and on how your product calls AWS.


The Validation tab on a solution in AWS Partner Central lists six prerequisites for the Foundational Technical Review, and the last one reads “AWS Marketplace product is Partner Revenue Measurement (PRM) enabled.” AWS won’t take your SOC 2 or WAFR report until all six show Complete. That line is where engineering asks which method to build, and alliances asks what to request from customers.

AWS’s onboarding guide covers each method, but the rules that decide between them are spread across its pages. This post puts them on one page: a chooser that maps your SaaS architecture to a method, then a checklist for the request a customer’s security team will review. For the stages this prerequisite sits in, see how the AWS Software Path and its FTR gate work.

A note on the acronym: AWS’s PRM is Partner Revenue Measurement, unrelated to the partner relationship management software that shares the initials.

What is AWS Partner Revenue Measurement?

AWS Partner Revenue Measurement is a set of AWS capabilities that attributes AWS service consumption to the partner product that drove it. AWS describes “precise, automated measurement of AWS consumption driven by Partner solutions,” across partner and customer accounts. You implement one or more of three methods, and every one of them needs your AWS Marketplace product code:

MethodHow it identifies your productWho can use it
Resource TaggingA tag on each resource: key aws-apn-id, value pc:<product-code>”SaaS, Professional Services, and any product type where you can tag AWS resources”
User Agent stringAPN_1.1/pc_<product-code>$ in the regular AWS API and CLI calls your product makes”Products with direct regular AWS API/CLI access”
AWS Marketplace MeteringNothing to build: attribution comes from AWS Marketplace product metadataAMI and ML products only

So a SaaS product chooses between the first two. AWS limits Marketplace Metering to AMI and ML products, whether or not your SaaS product already reports usage to AWS Marketplace. You don’t have to pick just one: AWS says you “can implement multiple methods simultaneously.”

Before any method, AWS lists four prerequisites: an AWS account linked to Partner Central, a product on AWS Marketplace, a product that uses supported AWS services, and Cost Explorer enabled. PRM is “intended to measure production workloads,” with dev and test environments for validating first, and attribution runs forward only from the day the tag or string goes in.

Take the product code from the Product Summary section of your product in the AWS Marketplace Management Portal. It is a long alphanumeric string, and AWS asks you not to use “the Product ID or the UUID formatted product ID from the AWS Marketplace listing.”

Which method fits your SaaS architecture?

Resource tagging fits long-lived resources that you, or the customer, can tag. A User Agent string fits a product that keeps calling AWS APIs, and it is the way through when a customer won’t take a tag. AWS’s guidance has a row for each architecture pattern, and splits the customer-account pattern by whether you deploy there or only read. Find your row:

Your SaaS architectureAWS’s patternResource Tagging fits whenUser Agent string fits whenWhat you need from the customer
Everything runs in your own AWS accounts, multi-tenant or a stack per customerPartner accountThe infrastructure is static: deployed once and running long-termYour product makes frequent regular AWS API or CLI callsNothing. Both methods stay in your account
You deploy and manage components in the customer’s accountCustomer account (deploy/manage)You deploy through IaC, such as CloudFormation or Terraform, and the customer allows tagsYou make ongoing API or CLI calls there, or the customer has strict tag policiesTagging: a tag on their resources. User Agent: no tags
Your product reads or accesses the customer’s account and deploys nothing thereCustomer account (read/access only)The customer is willing to tag their own resourcesYour product makes read API callsTagging: their team tags their resources. User Agent: no tags
Your control plane runs in your account, other components in theirsHybridResources in either account can be taggedYour product makes regular AWS API or CLI calls in either accountThe customer-account answer, for the part in their account

Five rules from AWS’s guide settle most close calls:

  1. CloudFormation can’t carry a User Agent string. It calls AWS “using its own service principal,” so AWS says to tag CloudFormation-deployed resources instead. A Lambda-backed custom resource can still set the string in its SDK code.
  2. Terraform can, but only while it runs. A provider_meta block sets the string for your module on AWS provider 6.27.0 or later, but Terraform typically calls AWS only during plan, apply and destroy. For static, long-running resources, AWS suggests tagging through Terraform.
  3. Only control-plane calls count. The string must be in “management or control-plane AWS API/CLI calls (i.e., calls that create, describe, modify, or delete AWS resources).” AWS doesn’t support data plane operations for attribution.
  4. Every resource needs a call every month. A resource with no qualifying call in a month contributes nothing that month. If your product calls AWS rarely, AWS allows “non-mutating, read-only calls (such as Describe* operations).”
  5. One tag, one partner. A resource can carry only one aws-apn-id tag. Where another partner works on the same resources, AWS points you to the User Agent string, where each partner sends its own, with “no conflicts.” If you must tag, agree tag ownership with the other partner and the customer first.

What do tagging and the User Agent string each require?

Each method has a few exact requirements, and missing one costs attribution.

Resource tagging

  • Exact values. The key is aws-apn-id, always lowercase, and the value is pc: followed by your product code. It is a user-defined tag, so it “counts against the 50-tag-per-resource limit.”
  • Tag through your IaC. For resources managed by CloudFormation, CDK or Terraform, AWS says to apply the tag in the IaC tool; tagging them in the console or CLI “causes drift detection on the next IaC run.” AWS recommends stack-level tags in CloudFormation and provider-level default_tags in Terraform.
  • Tag what your product uses, and what costs money. AWS’s warning: “Only tag resources that are directly used or influenced by your partner solution.” Tags on no-cost resources, such as IAM, generate no attribution.
  • Attribution lasts as long as the tag. AWS attributes revenue “until the tag is removed or the resource is shut down,” and any user with access to the account can remove it.

User Agent string

  • Exact format. APN_1.1/pc_<product-code>$, where the $ is the required end delimiter. A $ stripped by a shell or runtime is one of AWS’s listed failure causes; quote or escape it.
  • Every client, every Region. Set the string in the SDK configuration of every service client your product uses, “not just one service client,” and in every Region your product operates in.
  • Test in CloudTrail. The string appears in the userAgent field of CloudTrail events. That is how you verify it, and how a customer can audit your product’s calls.
  • Instrument every service you call. AWS recommends it because coverage keeps growing: on August 31, 2026 it went from 24 to 119 AWS services, and partners already sending the string got the new coverage “with no additional implementation needed.” Any partial spend captured on services not on the list is aggregated as “Misc.”

What should you send a customer’s security team?

A written request that names the method, the exact identifier, the resources in scope and the permissions involved, backed by AWS’s own answers on impact, access and data. Those answers come from the Customer FAQ that AWS added to its onboarding guide on August 19, 2026. Cover these ten points in the request:

  1. The method, and why. Tagging or the User Agent string, and the row of the chooser that put you there.
  2. The exact identifier. The aws-apn-id key with its pc:<product-code> value, or APN_1.1/pc_<product-code>$ in your calls, so their tag-policy owner can check it.
  3. The resources in scope. Only production resources your product directly uses or influences, listed by type or ARN.
  4. Who applies the tag, with which permissions. Either their team runs IaC templates you supply with the tag embedded, as AWS’s guide suggests where a partner’s access is limited, or you apply it yourself. AWS tells the customer: “The Partner can only apply tags using the IAM permissions you explicitly grant, and you can revoke that access at any time.”
  5. The tag budget and policy. The tag “consumes one of your fifty available user-defined tag slots.” If they enforce tag policies through AWS Organizations, they “will need a one-time update to allow for the tag key.” If another partner already holds the aws-apn-id tag on a resource, say how you’ll settle ownership.
  6. Impact and access. AWS says PRM “has no impact on your infrastructure, security posture, and billing structure,” with “no additional software to install, no performance overhead, and no changes to how workloads run.” It “does not grant AWS or a Partner access to a customer’s accounts, resources, or application code.”
  7. What AWS collects, and what you see. AWS collects the product code and resource tag, the resource ARN, the API operation, the ARN’s usage spend, the service type, the date and time of the API operation or tag creation, and the account ID hosting the resource. You don’t receive their raw billing data. AWS provides partners “only with aggregated, attributed revenue metrics across all customers,” and shares no PRM data specific to an individual customer.
  8. How they end it. The tag stays until they remove it or the resource is terminated. Anyone with the right permissions can remove it at any time, and attribution stops when they do.
  9. The no-tag alternative. If a tag or a policy change doesn’t fit, the User Agent string “requires no tags in your account.” It shows up in their CloudTrail logs, which AWS presents as an audit trail of partner activity.
  10. The Regions. PRM supports commercial Regions only, not the AWS European Sovereign Cloud or AWS GovCloud (US). A customer with workloads in commercial and government Regions can enable it for their commercial accounts now.

Link AWS’s Customer FAQ in the request itself, so their reviewer reads AWS’s wording, not yours.

What does PRM decide after it’s in place?

Three things beyond the tag: when you can request the FTR, which AWS account determines your PRM compliance for APN funding benefits eligibility, and whether AWS can attribute revenue to individual deals.

When you can request the FTR

After you enable PRM, AWS says “it can take up to 7 days for measurement data to appear,” and the FTR check completes “when the product appears in your Attributed revenue dashboard as an onboarded product.” The automated review itself returns a result within minutes, so the measurement data is the slow part. Implement PRM at least a week before you plan to submit.

The linked account and APN funding eligibility

PRM starts with the AWS account you link to Partner Central. AWS says the linked account becomes the primary account for managing all APN activities, and it will “Determine Partner Revenue Measurement compliance for APN funding benefits eligibility.” It is also the account billed the annual APN membership fee. Decide which account to link before engineering starts tagging.

Whether AWS can attribute revenue to a deal

A Revenue Attribution ID is an identifier you create in AWS Partner Central to map your already-measured product revenue to the AWS Marketplace offers and Launched-stage ACE opportunities “for which you are requesting AWS deal-level incentives.” Tags and User Agent strings that already carry your product code don’t need to change to use one. If your SaaS product is multi-tenant, you also give each deal a cost allocation percentage, month by month.

How does Suger help with the tagging step?

If you tag by hand rather than through IaC, the /aws-resource-tag skill in Suger’s Chrome extension guides you through tagging AWS resources with the aws-apn-id tag for Partner Revenue Measurement, and retrieves the product code from the AWS Partner Central SaaS products page. You’ll find it in the Suger Chrome extension’s skill catalog. For resources your IaC manages, follow AWS’s advice above and put the tag in the template.

Frequently asked questions

What is AWS Partner Revenue Measurement?

A set of AWS capabilities that measures the AWS consumption a partner’s product drives, in partner and customer accounts. A product joins it through a resource tag, a User Agent string in its API calls, or, for AMI and ML products only, AWS Marketplace Metering.

Which Partner Revenue Measurement method should a SaaS product use?

Resource tagging for long-lived resources that you or the customer can tag. A User Agent string for a product that keeps making control-plane API calls, or when a customer won’t take tags. You can run both. Marketplace Metering covers only AMI and ML products.

Does Partner Revenue Measurement give a partner access to a customer’s AWS account?

No. AWS says it grants neither AWS nor the partner access to the customer’s accounts, resources or application code. A partner can tag only with IAM permissions the customer grants, and partners see aggregated attributed revenue, never data specific to one customer.

How long does Partner Revenue Measurement take to show up for the FTR?

Up to 7 days after you enable it, according to AWS. The FTR prerequisite completes when the product appears in your Attributed revenue dashboard as an onboarded product, and AWS accepts the report only once every prerequisite is complete. Implement it at least a week ahead.

What value goes in the aws-apn-id tag?

The prefix pc: followed by your AWS Marketplace product code, the long alphanumeric string in the Product Summary section of the AWS Marketplace Management Portal. Not the product ID or the UUID-formatted product ID. Keep the key lowercase, and use only one such tag per resource.

Does Partner Revenue Measurement work in AWS GovCloud?

No. AWS supports it only in commercial Regions, not AWS GovCloud (US) or the AWS European Sovereign Cloud, and says it is working to expand coverage. A customer with workloads in commercial and government Regions can enable it for their commercial accounts now.

Takeaways

  • Choose by architecture: an aws-apn-id tag for static, taggable resources, a User Agent string for ongoing control-plane calls or customers who won’t take tags. Marketplace Metering is for AMI and ML products only.
  • Send a customer’s security team the identifier, scope, permissions, tag and policy impact, AWS’s answers on access and data, removal, and Regions.
  • Implement PRM at least a week before the FTR request, because measurement data can take up to 7 days to appear.
  • Choose the account you link to Partner Central deliberately: it determines PRM compliance for APN funding benefits eligibility.

Partner Revenue Measurement is one requirement in a longer AWS partnership. See how Suger supports the partnership around it, from marketplace listings to co-sell opportunities shared with AWS ACE from your CRM, in Suger for alliances and partnerships teams.

Sources

Primary sources for the platform rules cited above. Last verified September 29, 2026. Cloud providers change fees, eligibility, and program terms without notice — check the source before relying on a figure.

Browse every post on the Suger Blog

Stay Updated

Get the latest Cloud GTM insights, product updates, and marketplace strategies delivered to your inbox.