create-tanqory-app
v0.3.3
Published
Scaffold a Tanqory marketplace app: an embedded page, a verified webhook handler, and a manifest, ready to submit.
Maintainers
Readme
create-tanqory-app
npx create-tanqory-app order-notifierScaffolds a Tanqory marketplace app. You host it; Tanqory frames it, routes its API calls, and tells it which store it is looking at.
What you get
order-notifier/
├── tanqory.app.json handle, appUrl, devUrl, scopes, webhooks
├── next.config.mjs frame-ancestors, and no X-Frame-Options
└── src/app/
├── embed/page.tsx the page the dashboard frames
└── hooks/orders/route.ts a webhook handler that verifies its signatureThe last two lines are the reason this exists. They are what Tanqory's preflight
checks hardest, and both fail silently when wrong: an unverified webhook
accepts anything that guesses the URL, and X-Frame-Options produces a blank
frame with no error anywhere. Getting them right by hand is four chances to be
subtly wrong in a way nothing reports.
Run it
cd order-notifier
npm install
cp env.example .env.local # fill in from dev.tanqory.com/apps
npm run devGet it in front of a merchant
- dev.tanqory.com/apps → Create App — gives you a client ID and secret. Copy the secret now; it is shown once.
- Submit Version — paste your
appUrland the scopes fromtanqory.app.json. Every scope needs a reason: a reviewer approves permissions, not apps. - Test Install on one of your development stores. This works before any
review, and it is what makes the dashboard frame your
devUrlrather than yourappUrl— which is how you point atlocalhostwithout any localhost origin ever being trusted for a real merchant.
Three things that will cost you an afternoon
Never send X-Frame-Options. It has no allow-list form, so SAMEORIGIN
overrides your Content-Security-Policy: frame-ancestors in browsers that
still read it, and the dashboard shows a blank frame with no error.
next.config.mjs here sets frame-ancestors and nothing else — keep it that
way, and check whether your host adds the header for you.
Never redirect to a login page. You are inside an iframe. A login screen renders in a box, and if it escaped it would throw the merchant out of their dashboard. The SDK reports a dead session to the dashboard and lets it decide.
A 403 is not retryable. It means the merchant did not grant that scope. Retrying will never fix it; ask for the scope in your next manifest version.
Deploy it anywhere
Vercel, your own server, anything that serves HTTPS. Tanqory stores your URL, not your code — so a routine redeploy needs nothing from us. Only a change to the contract (a new scope, a new origin, a new webhook topic) needs a new version.
Full docs: https://docs.tanqory.com/apps/quickstart
