Developer program
Developer rules
Every app on Kweko runs inside someone's business: their customers, their leads, their messages. These rules keep that trust. By publishing an app, you agree to them.
Ask only for what you use
Request the smallest set of scopes your app needs to do what its listing says. Each scope is shown to the workspace owner in plain language when they install, and reviewers check that every one is justified.
- If a feature only reads leads, ask for
leads:read, notleads:write. - Don't request a scope "for later". Add it when you ship the feature that uses it.
- An app that asks for much more than it needs is sent back for changes.
Customer data stays the customer's
The data you reach through Kweko belongs to the workspace that installed your app. You may use it only to provide your app's features to that workspace.
- No scraping. Don't copy contacts, conversations or deals out of Kweko beyond what your feature needs to work.
- No reselling or sharing. Don't sell, rent, trade or give customer data to anyone, and don't use it to build lists, train models for other customers, or advertise.
- Delete on uninstall. When a workspace uninstalls your app (the
app.uninstalledwebhook), delete or anonymize what you stored for it, unless the law requires you to keep it. - Say what you keep. Your privacy policy must say what you store, where, and for how long.
No dark patterns in frames
Frames and Blocks appear inside Kweko's own screens, so people trust them like Kweko. Keep that trust:
- Don't imitate Kweko's sign-in, billing, settings or system messages, and don't ask for Kweko passwords.
- No fake urgency, hidden costs, pre-ticked consent or "confirmshaming" buttons.
- Upgrades and payments are clearly labeled as yours, with the price shown before anyone pays.
- Frames load over https only and never cover Kweko's navigation.
Support answers within 2 business days
Your listing names a support email or link. Someone has to read it:
- Reply to support requests within 2 business days.
- Keep the support contact in your vendor profile current.
- If you stop supporting the app, tell us first so we can help workspaces move off it.
Report security issues within 24 hours
If you find or suspect a security issue that affects Kweko data (a leaked client secret, unauthorized access, a vulnerability in your app or in Kweko), report it to [email protected] with "Security" in the subject within 24 hours.
- Rotate a leaked client secret right away from the developer console.
- Tell affected workspaces, with us, when their data was involved.
- Don't test vulnerabilities against workspaces that aren't yours. Use your test workspace.
New scopes need consent again
A new version that asks for more scopes doesn't get them silently. Each workspace that installed your app has to approve the new scopes before your app can use them. Plan for that: features that need a new scope should explain what's missing instead of failing.
Kweko may suspend apps
To protect workspaces, Kweko may suspend an app, without notice when needed, for abuse, security risk, or breaking these rules. A suspension stops the app everywhere at once: frames close, tokens are revoked, and each workspace is told why. We'll tell you the reason and what to fix; once it's fixed, we can lift the suspension.
Serious or repeated abuse can also end your developer access.
Questions
Write to [email protected]. These rules apply together with the Kweko terms and may be updated; we'll tell registered developers about changes before they take effect.