T

trustpilot.com

Trustpilot is an online review platform for businesses and consumers. Its products include business review-management APIs and a Data Solutions product for accessing business profiles and review data.

3 integrations · REST

Trustpilot exposes three documented REST API surfaces on trustpilot.com-owned hosts: the core `api.trustpilot.com/v1` APIs, a separate invitations API on `invitations-api.trustpilot.com/v1`, and the Data Solutions API on `datasolutions.trustpilot.com/v1`; authentication is via `apikey` headers for public/data products and OAuth bearer tokens for private business APIs, sometimes plus `x-business-user-id`.

discovered 2mo ago
REST · OpenAPI3
Credentials
Trustpilot API key (Client ID)api_keyGet key ↗

For Trustpilot APIs, the API key is your Client ID. For Data Solutions, sign in to Data Solutions, select Create new key, then copy the key; Trustpilot notes the full key is only shown once. For other Trustpilot API products, Trustpilot’s auth docs refer to the API key as the Client ID; obtain it as part of your Trustpilot API access/setup described in Authentication overview and the relevant product onboarding pages.

Trustpilot OAuth access token for private APIsoauth2Set up OAuth ↗

Use one of Trustpilot’s OAuth 2.0 flows documented in Authentication overview:

- Server-to-server: use Client credentials with your API key and API secret to mint an access token.

- User-delegated: use Authorization code or Implicit if your app needs a business user to sign in.

Trustpilot returns an access token for use as Authorization: Bearer .... Access tokens expire after 100 hours; refresh tokens are available for some flows per the auth docs.

Trustpilot Business user IDcompoundGet key ↗

Some private Trustpilot endpoints need the business user ID in addition to an OAuth access token when the token was minted with the client_credentials flow. Trustpilot says to open the user’s Trustpilot Business profile page, copy the User ID, and send it either in the x-business-user-id header or request body depending on the endpoint; see Client credentials and endpoint docs such as Invitation API.

conventions · 0/8 published

Publish these signals → /publishing