# Changelog

This page lists dated changes to the DZBuild developer platform. Changes to the merchant REST API that do not concern apps are listed in the [API changelog on dzbuild.com](https://dzbuild.com/api-docs/changelog).

## 2026-09-26: platform launch[​](#2026-09-26-platform-launch "Direct link to 2026-09-26: platform launch")

Third-party apps are open to developers. This release contains:

* **Developer console** at `https://dzbuild.com/dashboard/developer`. Register an app, get a `client_id`, a client secret and a signing secret, rotate both secrets, test on your own stores and submit the app for review.
* **Install flow**: OAuth 2.0 authorization code with PKCE `S256` only. `GET /oauth/apps/authorize` shows the consent screen, `POST /oauth/apps/token` returns the install tokens. One consent covers up to 10 stores owned by the merchant. See [OAuth](https://dzbuild.dev/oauth.md).
* **Install tokens**: one `dzpk_live_` bearer token per store, limited to the approved scopes, with no expiry. Uninstalling the app revokes it. Any store plan can install an app; set `min_plan` to require a higher one.
* **19 scopes** for apps, covering the store, products, orders, delivery, customers, landing pages, promo codes, pixels, shipping, analytics and WhatsApp. `ai:generate` is not available to apps. See [Scopes](https://dzbuild.dev/scopes.md).
* **App object in `GET /v1/whoami`**: `app_id`, `client_id` and `install_id` for calls made with an install token.
* **Per-install rate limit** of 120 requests per minute, checked before the store's shared limit. See [Rate limits](https://dzbuild.dev/rate-limits.md).
* **App errors**: `403` with `app_uninstalled`, `app_suspended`, `app_not_approved` or `app_plan_required`. Install tokens get `403` on `/v1/keys`, `/v1/webhooks` and `/v1/changes`.
* **Webhooks for apps**: order events and `app.uninstalled`, signed with `X-DZ-Signature`. Order events need the `orders:read` scope. See [Webhooks](https://dzbuild.dev/webhooks.md).
* **Launch link**: the merchant's Open button redirects to your launch URL with a signed HS256 token in `dz_launch`, valid for 5 minutes.
* **WhatsApp API**: `GET /v1/whatsapp/templates`, `GET /v1/whatsapp/balance`, `GET /v1/whatsapp/messages` and `POST /v1/orders/{id}/whatsapp`, with the scopes `whatsapp:read` and `whatsapp:send`. See [WhatsApp API](https://dzbuild.dev/whatsapp.md).
* **OpenAPI description** of the public `/v1` API, downloadable from the [API reference](https://dzbuild.dev/api-reference.md).
