Public API v1 contract
The eleven current operations, authentication, pagination, errors, fixed-window rate limits, and limitations.
جارٍ التحميل…Loading…
Help us improve SaaS
We'd like to use privacy-respecting analytics to understand how the platform is used and make it better. No personal data is collected without your consent, and you can change your choice anytime. Read our privacy notice
Bilingual public contracts that distinguish CURRENT, PARTIAL, PLANNED, and DEFERRED capabilities.
18 documents
On this page
The eleven current operations, authentication, pagination, errors, fixed-window rate limits, and limitations.
Verified Authorization Code, PKCE S256, exchange, refresh rotation, storage, and revocation behavior.
App identity, version manifests, supported capabilities, and conservative extension planning.
Baseline and categories for public API, OAuth, scope, webhook, and Marketplace contract changes.
A glossary of tenant, merchant, human roles, apps, installations, tokens, webhooks, and review concepts.
Create an app safely while accounting for the current OAuth, testing, API, and webhook limitations.
Security, privacy, reliability, portability, and uninstall requirements for Marketplace apps.
Behaviors that violate the public extension boundary, merchant trust, or platform safety.
The exact current per-version review flow, responsibilities, and known review limitations.
Exact current developer, app, version, installation, and webhook-delivery state values.
The public, version-aware contract for building external apps that connect to merchant stores.
The only supported boundary between SaaS Core and an external developer app.
A conservative map of CURRENT, PARTIAL, PLANNED, and DEFERRED extension capabilities.
The ten registered scopes, their risk, real public coverage, and requestability and reviewed capability contracts.
The current local fixture model, required negative cases, and planned hosted sandbox.
Current API v1 and exact app-version behavior, with honest deprecation and migration-guide status.
Current subscription, signing, retry, SSRF, secret-return, and emitted-event truth.