saleor-app

v2026.09.24

Universal Saleor app development patterns. Covers the app protocol (manifest, registration, webhooks, authentication), payment processing, SDK abstractions, settings persistence, and Dashboard integration. Framework-agnostic with Next.js examples.

GitHub
安装命令
npx skhub add saleor/saleor-app
Markdown
SKILL.md

Saleor App

Guide for building apps that extend Saleor via webhooks and the GraphQL API. Framework-agnostic protocol documentation with Next.js examples using @saleor/app-sdk.

When to Apply

  • Defining an app manifest or registering webhooks
  • Handling async/sync webhook events from Saleor
  • Building payment apps with the Transaction API and provider webhooks
  • Authenticating requests (registration handshake, JWT, signature verification)
  • Storing app settings in Saleor metadata
  • Building Dashboard UI inside the iframe
  • Making GraphQL calls with app tokens
  • Debugging webhook failures, auth errors, or permission issues
  • Deciding who can view the app and what they should see (user vs app scope)

Rule Categories by Priority

PriorityCategoryImpactPrefix
1ProtocolCRITICALprotocol-
2PermissionsCRITICALpermissions-
3Payment AppsCRITICALpayment-
4WebhooksHIGHwebhook-
5Data & SettingsHIGHdata-
6Dashboard UIMEDIUMdashboard-
7DevelopmentMEDIUMdev-

Quick Reference

1. Protocol (CRITICAL)

  • protocol-manifest — App manifest, required endpoints, permissions, extensions
  • protocol-auth — Registration handshake, APL, token scopes, JWT/signature verification

2. Permissions (CRITICAL)

  • permissions-access-scopes — Define per-feature permissions; guard user JWT on every API route; baseline + per-route meta; UI mirrors server

3. Payment Apps (CRITICAL)

  • payment-app — Financial truth, stable references, unknown outcomes, refunds, and reconciliation

4. Webhooks (HIGH)

  • webhook-async — Async event handling, payload typing, retry policy, signature verification
  • webhook-sync — Sync event handling, response schemas, performance constraints
  • webhook-external — Receiving webhooks from external services, multi-tenant routing

5. Data & Settings (HIGH)

  • data-graphql — GraphQL from apps: client setup, auth headers, codegen, app vs user tokens
  • data-settings — MetadataManager, EncryptedMetadataManager, domain-scoped persistence

6. Dashboard UI (MEDIUM)

  • dashboard-appbridge — AppBridge iframe protocol, actions, events, theme/locale sync

7. Development (MEDIUM)

  • dev-debug — Common errors, webhook dry runs, tunnel setup, debugging checklist
发现
标签

此技能尚未发布标签。

版本
最新版本元数据

版本

v2026.09.24

发布时间

2026年9月24日

分类

未分类

许可证

NOASSERTION

源路径

skills/saleor-app

默认分支

main

最新提交

fb1a572

Tree SHA

6419ad8