Changelog
This page lists dated changes to the DZBuild developer platform. Changes to the merchant REST API that do not concern apps are listed in the API changelog on dzbuild.com.
2026-09-26: platform launch
Third-party apps are open to developers. This release contains:
- Developer console at
https://dzbuild.com/dashboard/developer. Register an app, get aclient_id, a client secret and a signing secret, rotate both secrets, test on your own stores and submit the app for review. - Install flow: OAuth 2.0 authorization code with PKCE
S256only.GET /oauth/apps/authorizeshows the consent screen,POST /oauth/apps/tokenreturns the install tokens. One consent covers up to 10 stores owned by the merchant. See OAuth. - Install tokens: one
dzpk_live_bearer token per store, limited to the approved scopes, with no expiry. Uninstalling the app revokes it. Any store plan can install an app; setmin_planto require a higher one. - 19 scopes for apps, covering the store, products, orders, delivery, customers, landing pages, promo codes, pixels, shipping, analytics and WhatsApp.
ai:generateis not available to apps. See Scopes. - App object in
GET /v1/whoami:app_id,client_idandinstall_idfor calls made with an install token. - Per-install rate limit of 120 requests per minute, checked before the store's shared limit. See Rate limits.
- App errors:
403withapp_uninstalled,app_suspended,app_not_approvedorapp_plan_required. Install tokens get403on/v1/keys,/v1/webhooksand/v1/changes. - Webhooks for apps: order events and
app.uninstalled, signed withX-DZ-Signature. Order events need theorders:readscope. See Webhooks. - Launch link: the merchant's Open button redirects to your launch URL with a signed HS256 token in
dz_launch, valid for 5 minutes. - WhatsApp API:
GET /v1/whatsapp/templates,GET /v1/whatsapp/balance,GET /v1/whatsapp/messagesandPOST /v1/orders/{id}/whatsapp, with the scopeswhatsapp:readandwhatsapp:send. See WhatsApp API. - OpenAPI description of the public
/v1API, downloadable from the API reference.