Skip to content

Create app submission

POST/marketplace/submissions

Creates a new developer app submission for review, including the app manifest and version metadata. After submission, use the /validate and /scan endpoints to run automated checks before a human reviewer approves or rejects the submission.

Request

Request body

Content type application/json (required).

FieldTypeRequiredDescription
app_idintegerYes

ID of the marketplace app being submitted for review.

versionstringYes

Version string for this submission (semver format).

Max length: 30

manifestobjectYes

The app manifest object declaring permissions, webhook endpoints, and OAuth scopes.

changelogstringNo

Human-readable summary of changes from the previous version.

submission_notesstringNo

Notes to the reviewer explaining any unusual permissions or design decisions.

Max length: 2000

Example

{
  "app_id": 7,
  "version": "2.2.0",
  "manifest": {
    "name": "Slack Notifier",
    "slug": "slack-notifier",
    "permissions": [
      "read:crm_events",
      "write:webhooks"
    ],
    "webhook_url": "https://api.example.test/webhook/crm",
    "oauth_scopes": []
  },
  "changelog": "Added support for Slack Connect channels.",
  "submission_notes": "No changes to permission scope from v2.1.0."
}

Responses

201 Submission created in draft status

Content type application/json, object · MarketplaceSubmissionV1.

FieldTypeRequiredDescription
idintegerNo

Auto-incremented primary key.

app_idintegerNo

ID of the marketplace app this submission is for.

versionstringNo

Version being submitted (semver).

statusstringNo

Current stage in the submission review pipeline.

One of: "draft", "submitted", "scanning", "approved", "rejected", "published"

manifest_validboolean, nullableNo

Whether the manifest passed automated validation checks. Null before validation is run.

scan_risk_levelstring, nullableNo

Security scan risk classification. Null before a scan is executed.

One of: "low", "medium", "high", "critical"

changelogstring, nullableNo

What changed in this version compared to the previous submission.

submitted_atstring (date-time), nullableNo
reviewed_atstring (date-time), nullableNo
created_atstring (date-time)No

422 Validation failed — check app_id or manifest structure

Example request

curl -X POST "https://{tenant}.faciotech.net/api/v1/marketplace/submissions" \
  -H "Accept: application/json" \
  -H "Content-Type: application/json" \
  -d '{"app_id": 7, "version": "2.2.0", "manifest": {"name": "Slack Notifier", "slug": "slack-notifier", "permissions": ["read:crm_events", "write:webhooks"], "webhook_url": "https://api.example.test/webhook/crm", "oauth_scopes": []}, "changelog": "Added support for Slack Connect channels.", "submission_notes": "No changes to permission scope from v2.1.0."}'
Loading