# Prompts for building a DZBuild app with an agent

Paste one of these into Claude Code, Codex, Cursor or ChatGPT. Each one starts by pointing the agent at
the docs, so it builds against the real contract instead of guessing. With the docs MCP installed
(`claude mcp add dzbuild-docs -- npx -y @dzbuild/docs-mcp`) the agent reads the same pages through `search_docs` and `get_document`; without it,
the two URLs on the first line do the job. Developer kit 2026.09.30.

Keep secrets out of the chat: paste the console values into `wrangler secret put` or a `.dev.vars` file,
never into the prompt.

## 1. Start from the Cloudflare starter

```text
Read https://dzbuild.dev/llms.txt and https://dzbuild.dev/skills/dzbuild-apps/SKILL.md.
Set up a DZBuild app from https://github.com/DZBuild-com/dzbuild-app-starter, folder cloudflare-basic,
with `npm create cloudflare@latest my-app -- --template DZBuild-com/dzbuild-app-starter/cloudflare-basic`.
Explain which values I must paste into the developer console (redirect URI, launch URL) and which
secrets go into `wrangler secret put`. Do not change src/dzbuild.ts.
```

## 2. Post every new order to a Telegram group

```text
Read https://dzbuild.dev/llms.txt and https://dzbuild.dev/skills/dzbuild-apps/SKILL.md.
Build a DZBuild app that posts every new order to a Telegram group. Start from the cloudflare-orders
preset of https://github.com/DZBuild-com/dzbuild-app-starter. New orders come from polling
GET /v1/orders?since= once a minute, because the app runs on workers.dev and cannot receive webhooks yet.
One Telegram message per order, never twice; the bot token is a Worker secret.
```

## 3. Export the catalog as CSV

```text
Read https://dzbuild.dev/llms.txt and https://dzbuild.dev/skills/dzbuild-apps/SKILL.md.
Build a DZBuild app that lets a merchant download their products as a CSV file. Start from the
cloudflare-catalog preset of https://github.com/DZBuild-com/dzbuild-app-starter. Follow
data.next_cursor while data.has_more is true, quote fields per RFC 4180, and keep Arabic product names intact.
Only the merchant who opened the app through the launch link may download the file.
```

## 4. Sync stock from my own system

```text
Read https://dzbuild.dev/llms.txt, https://dzbuild.dev/skills/dzbuild-apps/SKILL.md and
https://dzbuild.dev/openapi/dzbuild-apps-v1.json (operations getProductStock and setProductStock).
Build a DZBuild app that receives a stock list from my inventory software and updates each product's
stock on the store with POST /v1/products/{id}/stock. Match products by SKU, send one Idempotency-Key
per product and run, and back off on 429 using error.retry_after.
```

## 5. Send a WhatsApp message when an order ships

```text
Read https://dzbuild.dev/llms.txt, https://dzbuild.dev/skills/dzbuild-apps/SKILL.md and
https://dzbuild.dev/whatsapp.md.
Build a DZBuild app that sends the merchant's approved WhatsApp "shipped" template to the buyer when an
order moves to shipped. Use the order.shipped webhook (the app runs on my own domain), verify
X-DZ-Signature, dedupe on the envelope id, and treat 409 already_sent and 402 no_credit as final.
```

## 6. Review my app before I submit it

```text
Read https://dzbuild.dev/skills/dzbuild-apps/SKILL.md, https://dzbuild.dev/security.md and
https://dzbuild.dev/review-guidelines.md, then review this repository against them.
List every place where a secret could leak, where a webhook is accepted without a valid signature,
where a redirect URI is not compared exactly, where a write lacks an Idempotency-Key, and what the
console still needs before the app can be submitted for review.
```
