Skip to content

Support

Where to get help, what to include in a report, and how to disclose a security vulnerability.

Updated 2 Sept 20262 min read
On this page

This page is for anyone who is stuck. Before you write to us, collect what makes the answer faster: the request id, the verbatim error, and what you expected.

Before you report#

  • API errors: include the X-Request-Id from the response, the status, error.code, the path and the UTC time. Never include access tokens or secrets.
  • Webhooks: include X-Dukkan-Delivery-Id and the envelope id; check the app page in the portal first, where you see every delivery's state and can replay.
  • Themes: include the full output of theme check --remote, the printed bundle hash, and the sandbox store's name.
  • CLI: include the command, its full output and the version (npx @dukkan.one/theme-cli --version).

Support channels#

  • From the portal: the account page carries your team's support channel; use it for program, review and earnings questions.
  • Review: questions about a specific review decision go on the review tab of that listing, where the reviewer sees them.

Status and changes#

  • Ongoing incidents are announced in the dashboard as they happen.
  • Every change to the Platform API or the theme contract is recorded in the changelog with its dated revision.

Report a security vulnerability#

If you find a vulnerability in the Platform API, the portal or the theme engine:

  1. Do not exploit it, access data that is not yours, or disrupt the service.
  2. Report it through the support channel in the portal with reproduction steps, and say it is a security report so it is routed immediately.
  3. Give us reasonable time to remediate before any public disclosure.

We commit to an initial response without delay and value responsible reports.

Frequently asked#

I suddenly get 401 on a token that worked. Either the hour passed (refresh with the refresh grant), the merchant uninstalled (you will find app.uninstalled), or the granting member lost access to the store.

I get 403 on an endpoint that worked. The effective scope narrowed: the granting member's permissions changed, or your team lost clients:read through an agreement version change.

Events stopped arriving. Check the subscription state with GET /webhooks; a subscription disabled by failures is re-enabled with PUT (delivery).

theme check rejects band. Validator lag in the published release.

The preview link stopped working. It is revoked by every push that changes the draft and after 24 hours; theme dev prints the new one.