# DZBuild Developers > Developer documentation for DZBuild (https://dzbuild.com), the e-commerce platform for Algerian merchants: online stores with cash on delivery, courier delivery across the wilayas, landing pages and WhatsApp order messages. Third-party apps register in the developer console, install on a merchant's store through OAuth 2.0 with PKCE, receive one install token per store, call the REST API at https://api.dzbuild.app/v1 and receive webhooks signed with X-DZ-Signature. Every page below is also served as Markdown at the same URL plus `.md`. Arabic: https://dzbuild.dev/ar/llms.txt. French: https://dzbuild.dev/fr/llms.txt. The whole site in one file: https://dzbuild.dev/llms-full.txt. ## Start - [Home](https://dzbuild.dev/index.md): The developer platform in one page: what an app is, how registration, installation and API calls fit together, what an app can reach, and the rules to build on. - [Introduction](https://dzbuild.dev/intro.md): What a DZBuild app is, what the platform offers (apps, install flow, install tokens, REST API, webhooks, WhatsApp API, launch link, developer console) and who the docs are for. - [Get started](https://dzbuild.dev/getting-started.md): Register an app in the developer console, choose scopes, install it on your own store with PKCE and make a first call to GET /v1/whoami. - [Core concepts](https://dzbuild.dev/concepts.md): Apps and their statuses, test mode, stores, installs, plans and min_plan, the per-install rate limit and what an install token is and is not. - [Build with AI agents](https://dzbuild.dev/build-with-ai.md): Markdown pages, llms.txt, the agent skill, the AGENTS.md template and the OpenAPI description, and how to keep secrets out of the chat. - [FAQ](https://dzbuild.dev/faq.md): Short answers about apps, plans, token expiry, local testing, WhatsApp messages, webhook events, the review and AI-assisted development. ## Build - [OAuth install flow](https://dzbuild.dev/oauth.md): Every authorize and token parameter, the consent screen, PKCE S256, multi-store installs, token lifetime and every error code. - [Scopes](https://dzbuild.dev/scopes.md): The 19 scopes an app can request, the endpoints each one opens, the endpoints closed to apps and what the merchant sees. - [Webhooks](https://dzbuild.dev/webhooks.md): Webhook URL rules, the event list, the payload, delivery headers, the X-DZ-Signature scheme with Node.js, PHP and Python samples, retries and app.uninstalled. - [WhatsApp API](https://dzbuild.dev/whatsapp.md): Send the platform-approved order templates from an app, paid from the store's wallet; templates, balance, sending, error codes and the message log. - [Home page sections](https://dzbuild.dev/home-layout.md): Read and change a store's home page sections from an app: the layout, the ten section types, adding, updating, reordering, deleting and replacing sections, plan limits, undo and error codes. - [Rate limits](https://dzbuild.dev/rate-limits.md): The per-install and store buckets, the 429 and 402 answers, and the Idempotency-Key rules for writes. ## Reference - [API reference](https://dzbuild.dev/api-reference.md): Where the REST API is documented, the OpenAPI description, sending the install token, the response envelope, whoami and the endpoints closed to apps. - [Errors](https://dzbuild.dev/errors.md): Every error an app can meet in one table, whether to retry, the OAuth errors and webhook delivery failures. - [Changelog](https://dzbuild.dev/changelog.md): Dated changes to the developer platform. ## Publish - [Review guidelines](https://dzbuild.dev/review-guidelines.md): App statuses, what the console requires before submitting, what the reviewer checks, decisions and changing an approved app. - [Security requirements](https://dzbuild.dev/security.md): Redirect URIs, client secret and tokens, webhook signatures, launch token verification, data deletion after uninstall, fewest scopes, no scraping. ## For agents - [Agent skill](https://dzbuild.dev/skills/dzbuild-apps/SKILL.md): The facts, procedure, security rules and error table an AI coding agent needs to build a DZBuild app, in the Agent Skills format. - [AGENTS.md template](https://dzbuild.dev/agents/AGENTS.md): A starting AGENTS.md for an app repository. - [OpenAPI 3.1 description for apps](https://dzbuild.dev/openapi/dzbuild-apps-v1.json): Every operation an install token can call, with parameters, scopes and response shapes. - [Create an app](https://dzbuild.dev/apps/new): Pick a preset, tick what the app may read or change, name it, and get the Deploy to Cloudflare button, the commands and the developer console fields. - [Connect an agent](https://dzbuild.dev/agents/connect): Point Claude Code, Codex, Cursor or ChatGPT at the docs MCP server and the agent packs. - [Docs index (JSON)](https://dzbuild.dev/kit/docs-index.json): The docs index the @dzbuild/docs-mcp server reads: every page, operation and example in one file. - [CLAUDE.md template](https://dzbuild.dev/agents/CLAUDE.md): A starting CLAUDE.md for an app repository, for Claude Code. - [Cursor rules](https://dzbuild.dev/agents/cursor-rules.mdc): Always-on rules for a DZBuild app repository in Cursor. - [Codex MCP config](https://dzbuild.dev/agents/codex-config.toml): The config.toml table that adds the docs MCP server to Codex. - [Agent prompts](https://dzbuild.dev/agents/prompts.md): Prompts to paste into a coding agent to build, test and submit an app. ## Optional - [Example app: dzbuild-app-starter](https://github.com/DZBuild-com/dzbuild-app-starter): Three Cloudflare Worker presets and a Node.js example with no dependencies (install flow, token store, signed webhooks, launch link), each with tests. - [Developer console](https://dzbuild.com/dashboard/developer): Register apps, rotate secrets, test on your own stores, submit for review. - [Merchant documentation](https://dzbuild.com/docs/intro): How merchants use the DZBuild dashboard. - [Merchant API documentation](https://dzbuild.com/api-docs/intro): The REST API as documented for merchant API keys. - [DZBuild](https://dzbuild.com): The platform.