What an app is
An app is an external service that the platform trusts, embeds, drives, and lets call back. Four capabilities, and you pick the ones you need:- Install lifecycle — when a merchant installs your app, the platform provisions it for their workspace; when they uninstall, it tears down. You never ask them for an API key.
- Embed UI — your web UI runs right inside the dashboard, in an iframe (or a native WebView on mobile).
- Public API — you call Sentralbee back with a per-workspace key the platform hands you on install.
- Webhooks — you receive platform events like
order.paid, signed so you can trust them.
app on a workspace, carrying the scopes the merchant
consented to. The difference is that the platform mints and delivers that key for you — the merchant clicks
Install, not “create a key and paste it into a form.”
Why there’s an SDK
The trust between the platform and your app rests on some security-critical machinery: verifying signed platform tokens, encrypting the key you’re given, checking webhook signatures, calling the API as the right workspace. You should never hand-roll that. So the@sentralbee/app-sdk package does it for you. Your app
logic and UI stay in your own code; the SDK owns the protocol. Everything in this tab is built around it.
What you’ll need
- Bun (the SDK, the CLI, and the starter are all Bun/Hono + React).
- A few minutes. The Quickstart builds and runs a working app end-to-end without any Sentralbee infrastructure, using a local mock-platform harness.
Start here
- Quickstart — build and run your first app in a couple of minutes.
- Concepts & lifecycle — the trust model and what happens on install.
- The manifest — the one file that declares what your app is and may do.
Building with an AI agent? Point it at the Build with an AI agent page — it’s written
to teach a coding agent the app model and the seams in one pass.

