Create app submission
POST/marketplace/submissions
Creates a new developer app submission for review, including the app manifest and version metadata. After submission, use the /validate and /scan endpoints to run automated checks before a human reviewer approves or rejects the submission.
Request
Request body
Content type application/json (required).
| Field | Type | Required | Description |
|---|---|---|---|
app_id | integer | Yes | ID of the marketplace app being submitted for review. |
version | string | Yes | Version string for this submission (semver format). Max length: 30 |
manifest | object | Yes | The app manifest object declaring permissions, webhook endpoints, and OAuth scopes. |
changelog | string | No | Human-readable summary of changes from the previous version. |
submission_notes | string | No | Notes to the reviewer explaining any unusual permissions or design decisions. Max length: 2000 |
Example
{
"app_id": 7,
"version": "2.2.0",
"manifest": {
"name": "Slack Notifier",
"slug": "slack-notifier",
"permissions": [
"read:crm_events",
"write:webhooks"
],
"webhook_url": "https://api.example.test/webhook/crm",
"oauth_scopes": []
},
"changelog": "Added support for Slack Connect channels.",
"submission_notes": "No changes to permission scope from v2.1.0."
}
Responses
201 Submission created in draft status
Content type application/json, object · MarketplaceSubmissionV1.
| Field | Type | Required | Description |
|---|---|---|---|
id | integer | No | Auto-incremented primary key. |
app_id | integer | No | ID of the marketplace app this submission is for. |
version | string | No | Version being submitted (semver). |
status | string | No | Current stage in the submission review pipeline. One of: |
manifest_valid | boolean, nullable | No | Whether the manifest passed automated validation checks. Null before validation is run. |
scan_risk_level | string, nullable | No | Security scan risk classification. Null before a scan is executed. One of: |
changelog | string, nullable | No | What changed in this version compared to the previous submission. |
submitted_at | string (date-time), nullable | No | |
reviewed_at | string (date-time), nullable | No | |
created_at | string (date-time) | No |
422 Validation failed — check app_id or manifest structure
Example request
curl -X POST "https://{tenant}.faciotech.net/api/v1/marketplace/submissions" \
-H "Accept: application/json" \
-H "Content-Type: application/json" \
-d '{"app_id": 7, "version": "2.2.0", "manifest": {"name": "Slack Notifier", "slug": "slack-notifier", "permissions": ["read:crm_events", "write:webhooks"], "webhook_url": "https://api.example.test/webhook/crm", "oauth_scopes": []}, "changelog": "Added support for Slack Connect channels.", "submission_notes": "No changes to permission scope from v2.1.0."}'