Skip to content
Extensions

Ecommerce extensions, scanned before they reach your store

Upload a Magento extension and its code is scanned before it is built into your store. Install admin apps from a link.

Every uploaded extension is security-scanned before it builds.

MAGENTO EXTENSIONUploadFrom your adminCode scanChecked before it buildsBuilt into your storeAfter the scan passesADMIN APPInstall linkFrom the app's developerOwner approvesBefore it gets accessRuns sandboxedInside your admin
Who it's for

Upload it, install it, or build it

  • A store that needs one more feature

    Upload the Magento extension your store needs, and its code is checked before it goes live.

  • A team with its own tools

    Install an admin app from its developer's link, and approve what it can see first.

  • A developer or an agency

    Build admin apps with the Stoily extension SDK, and connect other systems through the API.

Checked first

More features, scanned or approved before they run

An extension changes your store, and an admin app adds a tool beside it. Extensions are scanned, and apps wait for the owner to approve them.

  1. Add features without a server

    Upload an extension and it is built into your store. There is nothing for you to host.

  2. Check code before it runs

    Every uploaded extension is security-scanned before it builds. Some extensions need changes to pass.

  3. Keep apps in their lane

    Admin apps run in a sandbox and ask the store owner before they get any access.

Features

Extensions, admin apps and the API

Two ways to add features to your store, and an API for everything else.

  • Extension upload

    Upload a Magento extension package from your admin.

  • Code scan

    Every uploaded extension is security-scanned before it is built into your store.

  • Install by link

    Install an admin app from the link its developer gives you.

  • Owner approval

    The store owner approves what an app can access before it gets anything.

  • Sandboxed admin apps

    Each app runs in its own sandbox inside your admin.

  • Extension SDK and App Bridge

    Build admin apps on the Stoily extension SDK and talk to the admin through App Bridge.

  • REST API

    Manage products, orders, customers and settings through a REST API with an OpenAPI specification.

  • Scoped API tokens

    Create API tokens limited to the scopes you choose.

  • Webhooks

    Send order, customer and catalog events to your own systems.

  • GraphQL storefront API

    Build your own front end on the storefront GraphQL API.

  • OAuth for apps

    Third-party apps connect through an OAuth consent screen.

  • Store settings by API

    Read and change your store's configuration through the API.

How it works

Add an extension or an app in two steps

  1. Step 01

    Upload or install

    Upload a Magento extension in your admin, or open an admin app's install link.

  2. Step 02

    Pass the check, then use it

    Uploaded code is scanned, then built into your store. An app opens in its sandbox once the owner approves its access.

FAQ

Questions about ecommerce extensions

Two kinds. A Magento extension adds code to your store, and it is scanned before it is built in. An admin app is a separate tool that runs in a sandbox inside your admin.

Yes. Upload a Magento extension from your admin, and it is security-scanned and built into your store before it goes live. The admin and the default storefront are Stoily's own, so an extension written for the stock Magento admin or a Luma theme may need rework.

It depends on what the extension changes. One written for the stock Magento admin or a Luma theme may need rework, because Stoily has its own admin and storefront. Some extensions also need changes to pass the scan.

Open the install link the app's developer gives you. The store owner reviews what the app asks to access and approves it, and the app then opens inside your admin.

Only what the store owner approves. Each app runs in a sandbox inside your admin and asks for access before it gets any.

Yes. Build it with the Stoily extension SDK and App Bridge. The developer docs cover the API, the app contract and how an install link works.

Yes. The REST API, webhooks and scoped API tokens let your systems read and change store data, and the GraphQL storefront API serves your own front end.

Add what your store needs

Upload a Magento extension for a security scan, or install a sandboxed admin app from its link.