Square App Marketplace

Ecommerce

Block / Square · Ecommerce & storefront platforms

Best for: SaaS vendors serving Square sellers in retail, restaurants, services, e-commerce, payments, accounting, inventory, scheduling, delivery, loyalty, and operational automation, especially teams prepared to support OAuth-connected merchant accounts and formal quality review.

Overview

Square App Marketplace connects sellers with third-party software that extends or synchronizes Square data and functionality. The catalog covers accounting and tax, booking and scheduling, delivery and orders, e-commerce, restaurants, loyalty, healthcare, inventory, and related commerce operations. Listed examples include QuickBooks Online, Acuity Scheduling, and WooCommerce. Publishers build with relevant Square APIs, connect seller accounts through OAuth, apply for Square app-partner approval, complete API-specific requirements, submit through the Developer Console, undergo Square QA, prepare listing content, and submit the listing for review. Square states that approved apps are generally published within several business days. Commercial listings may show free plans, trials, monthly prices, or custom pricing, while standard fees and marketplace commercial arrangements are not publicly specified.

How to build & ship

  1. 1Create a Square Developer account and build the integration with the relevant Square APIs.
  2. 2Implement OAuth so a seller can authorize the app and grant scoped access to the seller’s Square account.
  3. 3Apply for Square app-partner approval and complete the API-specific App Marketplace requirements checklists.
  4. 4Create an App Marketplace submission in the Developer Console, select the app and supported countries, accept the applicable partner agreement, and submit for Square QA.
  5. 5Address QA feedback, complete the seller-facing listing details, submit the listing for review, and await publication, which Square says normally occurs within several business days after approval.

Key APIs & SDKs

OAuth API
Payments API
Orders API
Catalog API
Inventory API
Webhooks API

Authentication & security

  • Primary auth: OAuth 2.0 through Square’s OAuth API, using seller authorization to obtain scoped access and refresh tokens.
  • Also supports: OAuth authorization-code flow for confidential server applications, OAuth PKCE flow for public clients such as mobile, desktop, and single-page applications, API credentials for app-owned or non-connected-account API calls
  • Security review: Required
  • Square requires app-partner approval, API-specific technical requirements, and technical and quality QA before publication. Production OAuth integrations require HTTPS redirect URLs, scoped seller permissions, and secure handling of confidential client secrets. The reviewed sources do not identify a separate public security certification or fixed security-control checklist for marketplace publishers.
  • Eligibility requires Square app-partner approval and compliance with technical and quality requirements. Publishers submit through the Developer Console, complete a requirements check based on API usage, and queue the submission for Square review. Square performs QA and may return issues for correction and resubmission. Listing content is completed and submitted separately for review; publication follows QA and listing approval and normally occurs within several business days.
  • The reviewed public marketplace and API materials do not specify one current numeric API rate limit for marketplace apps.

Monetization

Onboarding
Not publicly specified
Commission
Not publicly specified
Merchant of Record
Not publicly specified

Pros & cons for builders

Pros

  • Official distribution inside Square’s established seller and point-of-sale ecosystem.
  • Broad coverage across payments, retail, restaurants, e-commerce, inventory, scheduling, delivery, loyalty, and back-office workflows.
  • Documented OAuth connected-account model with authorization-code and PKCE options, plus API-specific requirements checklists and QA.

Cons

  • Publishing is curated and requires partner approval, technical requirements, QA, and listing review.
  • Square does not publicly specify a standard onboarding fee, universal commission, or merchant-of-record arrangement in the reviewed sources.
  • The reviewed public materials do not provide one current numeric API rate-limit figure, and OAuth token lifecycle and permission scoping add operational complexity.

Frequently asked questions

How do I get my app approved on Square App Marketplace?

Eligibility requires Square app-partner approval and compliance with technical and quality requirements. Publishers submit through the Developer Console, complete a requirements check based on API usage, and queue the submission for Square review. Square performs QA and may return issues for correction and resubmission. Listing content is completed and submitted separately for review; publication follows QA and listing approval and normally occurs within several business days.

What authentication does Square App Marketplace use?

Square App Marketplace apps primarily authenticate with OAuth 2.0 through Square’s OAuth API, using seller authorization to obtain scoped access and refresh tokens., also supporting OAuth authorization-code flow for confidential server applications, OAuth PKCE flow for public clients such as mobile, desktop, and single-page applications, API credentials for app-owned or non-connected-account API calls.

How is Square App Marketplace monetized?

Square App Marketplace supports Free, Paid app. Typical commission: Not publicly specified. Onboarding fee: Not publicly specified.

Is a security review required to list on Square App Marketplace?

Yes, Square App Marketplace requires a formal security or listing review before apps go live. Square requires app-partner approval, API-specific technical requirements, and technical and quality QA before publication. Production OAuth integrations require HTTPS redirect URLs, scoped seller permissions, and secure handling of confidential client secrets. The reviewed sources do not identify a separate public security certification or fixed security-control checklist for marketplace publishers.