Build apps for DZBuild stores
DZBuild is the e-commerce platform for Algerian merchants. A DZBuild app is a web service you host, on your own Cloudflare account or your own server. A merchant installs it on their store, and your app reads and changes that store's orders, products, delivery, customers and WhatsApp messages through the REST API.
The merchant approves on DZBuild
Install orders-bot on your store
orders-bot asks for access to your store. Once you approve, it can only do the following.
What this app will be able to do
View orders (read only; it cannot create or change orders) orders:read
You can remove the app at any time from the Extensions page.
Your server exchanges the code for the install token
POST https://dzbuild.com/oauth/apps/token
200 OK
{
"access_token": "dzpk_live_0a1b2c3d4e5f67.9f8e...",
"token_type": "Bearer",
"scope": "orders:read",
"store_id": 141,
"install_id": 7,
"stores": [
{
"store_id": 141,
"store_name": "My test store",
"install_id": 7,
"access_token": "dzpk_live_0a1b2c3d4e5f67.9f8e..."
}
]
}How an app works
Register the app
Create it in the developer console. You get a client_id, a client secret shown once, and a signing secret for webhooks and launch links.
Get startedA merchant installs it
Send the merchant to the authorize URL with a PKCE challenge. They approve on a DZBuild consent screen, and your server exchanges the code for one install token per store.
The OAuth flowCall the API
Send the token to api.dzbuild.app/v1. Poll
WebhooksGET /v1/orders?since=for new orders, or receive signed order events on a webhook URL on a domain you own (DZBuild refuses workers.dev addresses). Test on your own store, then submit the app for review.
What your app can reach
One scope per kind of store data. The merchant sees one line per resource on the consent screen and grants only what you ask for. All scopes
- Orders
Read orders and their items. Create orders, change their status, cancel them.
orders:readorders:write - Delivery
Hand an order to the store's courier.
delivery:send - Products
Catalogue and categories, with images, variants, offers, quantity rules and stock.
products:readproducts:write - Customers
Customers and each customer's orders.
customers:read - Landing pages
Landing pages and their sections, and the check that runs before publishing.
landing_pages:readlanding_pages:write - Shipping
Rates and settings, linked couriers, coverage, the wilaya and commune lists.
shipping:readshipping:write - Store
Profile, design, home page sections and themes.
store:readstore:write - Promo codes and pixels
Discount codes and tracking pixels.
promos:readpromos:writepixels:readpixels:write - Analytics
Store analytics and KPIs.
analytics:read - WhatsApp
Approved order templates, the store's wallet balance, the message log, and sending.
whatsapp:readwhatsapp:send
Rules to build on
- One token per store
- Install tokens start with dzpk_live_, have no expiry date, and are revoked the moment the merchant uninstalls your app.
- 120 requests per minute
- Per install, checked before the store's shared budget. A 429 answer carries Retry-After.
- Idempotency-Key on writes
- POST, PATCH and DELETE need one. The response is stored for 24 hours and replayed when you retry.
- HMAC-SHA256 webhooks
- X-DZ-Signature covers the timestamp and the raw body. Reject anything older than 5 minutes. Up to 5 delivery attempts.
- Webhooks need your own domain
- DZBuild refuses webhook URLs on workers.dev. Until the app runs on a domain you own, poll
GET /v1/orders?since=once a minute. - Any store plan
- Every plan can install an app. Set a minimum plan in the console when your app needs one.
- Review before listing
- A draft app runs only on stores you own. DZBuild reviews it before other merchants can install it.
Register your first app
The developer console lives in your DZBuild dashboard. Any account that owns a store can open it, and a draft app installs on your own store right away.