Skip to main content

Review guidelines

Every app starts in test mode, where only you can install it, on stores you own. Before any other merchant can install it, DZBuild reviews it. This page lists the app statuses, what the console requires before you submit, and what the reviewer checks.

App statuses​

StatusMeaningWho can installExisting installs
draftNew app. You can edit everything.Only you, on stores you own.Calls from your own stores work.
in_reviewSubmitted and waiting for a decision. Editing is locked.Only you, on stores you own.Calls from your own stores work. If the app was approved before, every existing install keeps working.
approvedListed for every merchant.Any store owner whose plan meets the app's minimum plan.Work normally.
rejectedDZBuild sent the reasons by email. You can edit and submit again.Nobody, you included.Every call gets 403 app_suspended.
suspendedDZBuild stopped the app. Editing is locked.Nobody.Every call gets 403 app_suspended. The merchant cannot open the app.

You can rotate the client secret and the signing secret in every status.

Before you submit​

The console's Submit button refuses the app with the list of what is missing until all of these are in place:

  • a logo in PNG, JPEG or WebP, at most 1 MB and at least 128 by 128 pixels;
  • a description in English, in Arabic and in French, each at least 20 characters (500 at most);
  • at least one redirect URI;
  • a launch URL on https;
  • a support email address;
  • at least one scope;
  • a verified webhook URL, when you set a webhook URL;
  • at least one install of the app on one of your own stores.

The console also holds these rules when you save:

  • The app name is 3 to 60 characters and must not contain "dzbuild".
  • The developer name is 2 to 80 characters.
  • Up to 5 redirect URIs, https only.
  • Changing the webhook URL clears its verification, so verify it again.
  • One DZBuild account can register up to 10 apps.

What DZBuild checks​

The reviewer sees your whole registration and your developer account. The review covers:

  • The listing. Name, developer name, logo, homepage, support email and the three descriptions. Merchants read these descriptions before they install, so each one should say what the app does with store data.
  • Redirect URIs. Every URI is listed, and a URI whose host differs from your homepage host is flagged. Use your own domain for both.
  • Scopes. Grouped into read and write per resource, and compared with what the descriptions say the app does. See scopes.
  • Webhook URL. Checked again against the platform's URL rules, together with the verification state of your test install.
  • Your account. Your identity, account history and your other apps.
  • Test installs. The stores where the app is installed.
  • The security rules. Redirect URIs, secrets, signature checks, data deletion, scraping and support, as listed on the security page.

Decisions​

DZBuild answers each submission by email: in French when your DZBuild account language is French, in Arabic otherwise.

  • Approved. The app becomes available to every merchant whose plan meets its minimum plan.
  • Rejected. The email carries the reviewer's notes. Fix the points, then submit again from the console.
  • Suspended. An approved app can be suspended, with a note that explains why. Its API calls are refused from the next request. Reply to the email to discuss it. When the suspension is lifted, the app is approved again and calls work.

Changing an approved app​

Saving any change to an approved app, the logo included, sends it back to in_review after you confirm. Stores that already installed it keep working while it waits; other merchants cannot install it until DZBuild approves the change. Group your edits into one save. Rotating a secret or verifying the webhook URL does not start a review.

This page for AI toolsView as MarkdownOpen in ChatGPTOpen in Claude