App review guidelines
The checklist marketplace app reviewers walk through, and what triggers changes requested or rejection.
On this page
This page is for anyone preparing an app submission. The automated checks in Publish an app catch mechanical mistakes; this is the list the human reviewer judges by.
Least privilege#
- Every requested scope is clearly justified by the listing description; a scope without a declared function is refused.
- Sensitive scopes (
clients:read,refunds:write,fulfillments:write) explain their use explicitly in the description. -
clients:readcomes with an accepted data processing agreement and a privacy policy describing what is processed.
Security#
- HTTPS redirect URIs on a public, stable host.
- The app verifies webhook signatures and rejects stale timestamps (verification).
- No secrets or tokens in URLs or in the browser.
- The support and privacy URLs work and belong to the same party.
Data behavior#
- Every write carries an
Idempotency-Keyand the app handles409by re-reading, never by blind resubmission. - Money is integers with
decimalsfrom the response; no ISO tables, no floats. -
line_pricingis respected in any reconciliation or report. - Rate limits are respected (
429andRetry-After) without flooding.
Listing#
- Name and description in Arabic and English of equal quality; no stilted machine translation.
- No implication that the app is from Dukkan or officially endorsed; no hosts resembling
dukkan.one. - Declared features actually exist in the submitted version.
- The install URL leads straight into authorization, not a long marketing page.
Merchant experience#
- The merchant understands what the app does before consenting and can uninstall without obstacles.
- On uninstall the app stops calling and deletes the store's data (App lifecycle).
- The app's UI supports Arabic if it faces the merchant.
What triggers changes requested#
- An unjustified scope, or a description that does not match the scopes.
- A broken support or privacy URL, or a lookalike host.
- Missing signature verification, or writes without an
Idempotency-Key(visible in your sandbox's logs). - A listing that is effectively single-language (the second language is a title only).
What triggers rejection#
- Attempting to collect customer data without
clients:reador without the agreement. - An app that does something other than declared, sells data, or contacts customers without the merchant's knowledge.
- Circumventing rate limits or distribution channels.
The submission comes back with a reason and a note on the review tab; fix and resubmit. First response within 5 business days.