Listing & review guidelines
Use this as a pre-submission checklist. Most rejections are avoidable — they’re the same handful of gaps, repeatedly.
Functional
Section titled “Functional”- The app does what its description says, end to end, tested against a sandbox business.
- Every requested scope is actually used somewhere in the
app — an unused scope is the single fastest path to
CHANGES_REQUESTED. - Errors are handled, not just the happy path: expired tokens (refresh),
429/5xx(backoff), validation failures (surfaced to the merchant, not swallowed). See Errors. - If your app declares hosted functions, they run cleanly in a test invocation and their declared egress hosts are accurate and complete.
Security
Section titled “Security”- No OneBooks credential is ever requested inside your app — session tokens replace that entirely. See Security.
- Webhook signatures are verified, including during a secret rotation
window (accept any
v1=match). - Session tokens are cryptographically verified on every request, not just decoded — and exchanged only once per business and user (Token exchange).
- Embedded pages serve
Content-Security-Policy: frame-ancestors https://app.getonebooks.com. - Client secret and stored tokens are never exposed to the browser or committed to a public repository.
Privacy
Section titled “Privacy”-
app.uninstalledandbusiness.redactare subscribed and handled — mandatory for any listed app. See Privacy & data handling. -
customer.redactandsupplier.redactare subscribed and handled if you store personal data about a business’s customers or suppliers. - Your privacy policy (the
privacyPolicyUrlon the listing) accurately describes what OneBooks data you collect and why. - Data collection matches what the description justifies — a scope with no corresponding, disclosed purpose is a privacy gap, not just a functional one.
- Your app renders correctly inside the iframe at the heights and contexts your registered extensions actually use.
- Every embedded page calls
app.ready(), and loading and error states are real UI, not a blank frame — the host only waits 15 seconds forready. - The icon and screenshots show the real app — you need an icon and at least one screenshot to submit.
- The app is usable, not just technically functional — see Design guidelines.
Localization and RTL
Section titled “Localization and RTL”- Listing content (
name,tagline,description,features) is provided in at least English; every additional language you claim support for inlanguages[]should actually be usable in the app itself, not just the listing copy. - If you claim Arabic support, the app actually renders correctly right-to-left — see Design guidelines. Claiming a language you don’t support is worse than not claiming it.
Support
Section titled “Support”-
supportEmailis monitored and responds to merchant questions about your app specifically (not a generic company inbox that never mentions OneBooks). -
supportUrl/docsUrl, if provided, are live and relevant.
Where next
Section titled “Where next”Design guidelines goes deeper on the UX and visual-fit expectations referenced above.