The API is in pilot and Enterprise-only: keys must be pilot-enrolled and belong to a store on an active Enterprise plan, or every call returns 403, and https://api.dzbuild.app is the only supported host.
v1.3 — 2026-08-13 (pilot)
✨ Self-service key management — Enterprise store owners can now generate and revoke API keys from the merchant dashboard at Settings → API (
/dashboard/api). Secrets are shown once, at creation.⚠️ The per-minute rate limit is now enforced per store, shared across all of the store's keys (previously per key). The Enterprise ceiling is unchanged at 600 requests/minute.
⚠️ A store can now hold at most 3 active keys (down from 20), on every mint path — dashboard,
POST /v1/keys, and support-issued. Revoking a key frees its slot.
v1.2 — 2026-08-13 (pilot)
⚠️ The API is now Enterprise-only. Keys authenticate only while their store is on an active Enterprise plan; every other plan — and an expired Enterprise subscription — gets
403 forbidden("API access requires an active Enterprise plan"). New keys can be minted for Enterprise stores only. Existing keys on non-Enterprise stores stop working immediately but are not deleted: they resume the moment the store moves to (or renews) Enterprise, with nothing to re-issue.⚠️ The legacy Free / Pro / Unlimited rate-limit tiers are retired. The Enterprise ceiling stays 600 requests/minute per key with no monthly cap; per-store overrides from support still apply.
v1.1 — 2026-08-12 (pilot)
✨ Product images over the API —
POST /v1/products/{id}/imagesadds an image from a publichttpsURL (DZBuild downloads, optimises and hosts it),PATCH .../images/{image_id}sets alt text / display order / primary,DELETE .../images/{image_id}removes one. Duplicate URLs are de-duplicated, the first image becomes primary automatically, max 20 images per product.✨
PUT /v1/products/{id}/variants— create and manage variant groups, options and per-combination stock in one call (full replace). Per-optionprice_adjustment,stock,sku,image_idandshow_as_cardare now writable, and the stock mode flags are set for you.✨
GET /v1/products/{id}now returns thecombinationsblock plus the full option fields (price_adjustment,sku,show_as_card,sort_order,is_active) and imagealt_text.⚠️ Breaking-ish:
primary_imageandimages[].urlnow return full CDN URLs instead of bare filenames. If your code prefixes them manually, remove that logic.
v1.0.1 — 2026-05-02 (pilot)
✨
POST /v1/orders— create orders via API. Designed for custom themes, headless storefronts, mobile apps, and reseller automation. Server-authoritative line pricing; full variants support; idempotent.📚 New guide: Custom themes & storefronts — end-to-end build, including catalog rendering, variants UI, cart, checkout, and webhook integration.
📚 New guide: For resellers — manage multiple client stores, bulk operations, white-labeling, billing models.
📚 New guide: Environment & .env setup — safe credential storage across Node, Python, PHP, Go, Vercel, Cloudflare, AWS, Docker/k8s, GitHub Actions.
📚 Expanded
Ordersreference — full variants documentation including per-variant stock, per-combination stock, cascading variants, image-text variants, multi-piece offers.
v1.0 — 2026-04-30 (pilot)
🎉 Initial pilot launch.
Per-key authentication, rate limiting and read caching.
Read endpoints for store / products / orders / customers / landing-pages.
Write endpoints with idempotency for products / orders / landing-pages.
/v1/signupsand/v1/eventsasynchronous ingest (202 Accepted).Outbound webhooks with automatic retries.