trustpilot.com
Trustpilot is an online review platform for businesses and consumers. Its products include business review-management APIs and a Data Solutions product for accessing business profiles and review data.
Trustpilot exposes three documented REST API surfaces on trustpilot.com-owned hosts: the core `api.trustpilot.com/v1` APIs, a separate invitations API on `invitations-api.trustpilot.com/v1`, and the Data Solutions API on `datasolutions.trustpilot.com/v1`; authentication is via `apikey` headers for public/data products and OAuth bearer tokens for private business APIs, sometimes plus `x-business-user-id`.
- Trustpilot Core REST APIsdiscovered
- Trustpilot Invitations REST APIdiscovered
- Trustpilot Data Solutions REST APIdiscovered
For Trustpilot APIs, the API key is your Client ID. For Data Solutions, sign in to Data Solutions, select Create new key, then copy the key; Trustpilot notes the full key is only shown once. For other Trustpilot API products, Trustpilot’s auth docs refer to the API key as the Client ID; obtain it as part of your Trustpilot API access/setup described in Authentication overview and the relevant product onboarding pages.
Use one of Trustpilot’s OAuth 2.0 flows documented in Authentication overview:
- Server-to-server: use Client credentials with your API key and API secret to mint an access token.
- User-delegated: use Authorization code or Implicit if your app needs a business user to sign in.
Trustpilot returns an access token for use as Authorization: Bearer .... Access tokens expire after 100 hours; refresh tokens are available for some flows per the auth docs.
Some private Trustpilot endpoints need the business user ID in addition to an OAuth access token when the token was minted with the client_credentials flow. Trustpilot says to open the user’s Trustpilot Business profile page, copy the User ID, and send it either in the x-business-user-id header or request body depending on the endpoint; see Client credentials and endpoint docs such as Invitation API.
conventions · 0/8 published
- integrations.json✗
/.well-known/integrations.json - llms.txt✗
/llms.txt - API catalog✗
/.well-known/api-catalog - OpenAPI document✗
/api/schema/, /openapi.json, /swagger.json, /api/openapi.json, or /v1/openapi.json - MCP server card✗
/.well-known/mcp/server-card.json - OAuth protected resource✗
/.well-known/oauth-protected-resource - Agent card✗
/.well-known/agent-card.json - Agent skills✗
/.well-known/agent-skills/index.json
Publish these signals → /publishing