Authorize a published marketplace app, persist an active installation, mint a short-lived authorization code, then exchange it for a scoped app access token.
Build on LetBuyy.
A docs-first workbench for the platform as it exists today: the versioned /v1 gateway, app OAuth and app bridge, lifecycle webhooks, and Liquid plus JSON-contract themes. Every page states whether a surface is a live contract or a recorded gap.
POST /v1/app-store/apps/:id/oauth/authorize
{
"store_id": "site_uuid",
"redirect_uri": "https://partner.example/oauth/callback",
"code_challenge": "base64url_sha256_of_pkce_verifier",
"code_challenge_method": "S256",
"scopes": ["read_products"],
"state": "opaque-csrf-state",
"webhook_url": "https://partner.example/webhooks/letbuyy"
}Apps
Authorize a marketplace app with authorization-code OAuth and PKCE, hold a scoped access token, and receive HMAC-signed lifecycle webhooks.
Build your first appThemes
Ship a JSON-contract theme bundle with grouped settings, per-template editor drafts, and Liquid sections rendered by the tracked theme engine.
Build a themeAPIs
Read the curated /v1 gateway surface — 8 route groups across commerce, storefront, themes, apps, and operations, with query-cost rate limits.
Read the API referenceShip against stable contracts first
The active path is marketplace app registration, scoped install OAuth, lifecycle webhooks, theme package upload, and dashboard visibility. SDK and backend gaps are marked before they surprise a partner.
Curated from the Hono gateway routes, schemas, auth middleware, and query-cost rate limiter.
Authorization-code install, token exchange, app bridge tokens, HMAC signatures, and compliance webhook topics.
JSON-contract theme bundles, app manifests, extensions, scopes, app blocks, and honest SDK/CLI gaps.
Developer apps, themes, API keys, installs, analytics, and earnings surfaced as real contracts or backend skips.
Truth source, not aspirational docs
Every page in this portal is backed by tracked gateway, webhook-service, auth-core, app-platform shared contract, or theme-engine source. Missing data and tooling are visible as skips.
8 route groups
7 groups shipping
66 endpoints
What works, and what does not
Three contracts a partner can depend on today, and the one piece of tooling that does not exist yet.
Storefront GraphQL cart reads use a persisted cart token backed by the storefront cart REST contract. Cart mutations stay on REST so clients share the same server-side cart before checkout.
Deliveries are signed v1=<hex-hmac> over timestamp and raw body, carry event, request, and trace ids, and must target HTTPS in staging and production.
No active @letbuyy/cli, app SDK package, theme CLI, or create-letbuyy package exists yet. The portal documents the contract and keeps CLI commands planned.