Queek docs
Merchant endpoint reference

Reviews

GET
/reviews

Requires scope merchant-reviews-read.

Lists only this installed app’s imported reviews for this store, newest ingested first with cursor pagination. Approved imports remain unverified and are hidden from verified-only storefront blocks, store-wide summaries and testimonials unless the merchant opts in with verified_only=0. Customer product review lists, per-product summaries and latest-approved reviews include approved imports. Native reviews and rating aggregates are not readable through this API. Imports are capped at 30 requests/minute and 2,000/day per installation, and 5,000 pending rows per app/store; 409 conflicts may be retried after 1 second.

Authorization

merchantKey
X-Client-Key<token>

The store's private API key (sk_live_…, sk_test_… on a dev store) from Dashboard → Settings → API keys. It is bound to one store and carries the scopes the merchant granted; each operation names the scope it needs. Server-side only — never ship it to a browser or an app bundle.

In: header

Query Parameters

limit?|
Range1 <= value <= 100
starting_after?string|null
product?string
Lengthlength <= 255
status?string

Value in

  • "pending"
  • "approved"
  • "rejected"

Header Parameters

X-Client-Key*string

A private API key (sk_live_…, sk_test_… on a dev store) minted under Dashboard → Settings → API keys. The key is bound to ONE store, so no vendor header or vendor_id is sent; its scopes decide which operations it may call. pk_ public keys never reach this API. Keep it on your server.

X-Request-Id?string

Your own correlation id (8–128 chars, ^[A-Za-z0-9_.:-]+$). Echoed back on the response and on every log line of the request; one is generated when you omit it.

Response Body

application/json

application/json

application/json

application/json

application/json

curl -X GET "https://example.com/reviews?limit=2&starting_after=eyJjcmVhdGVkX2F0IjoiMjAyNi0xMC0wMyAwOTowMDowMCIsImlkIjoiMDE5YTFkNTItM2M4ZS03ZjQxLWIwZDItNmEzZTljMWY0YjIxIiwiX3BvaW50c1RvTmV4dEl0ZW1zIjp0cnVlfQ&status=pending" \  -H "X-Client-Key: {{merchantKey}}"
{  "data": [    {      "source_review_id": "chowdeck-review-2026-0042",      "source": "chowdeck",      "author_display_name": "Ifeoma Adebayo",      "product_p_id": 20417,      "rating": 5,      "title": "Fresh and delicious",      "description": "The jollof arrived hot.",      "media": [],      "status": "pending",      "is_verified_purchase": false,      "submitted_at": "2026-09-24T13:05:00+00:00",      "created_at": "2026-10-03T08:00:00.000000Z",      "edited_at": null    }  ],  "has_more": true,  "next_cursor": "eyJjcmVhdGVkX2F0IjoiMjAyNi0xMC0wMyAwOTowMDowMCIsImlkIjoiMDE5YTFkNTItM2M4ZS03ZjQxLWIwZDItNmEzZTljMWY0YjIxIiwiX3BvaW50c1RvTmV4dEl0ZW1zIjp0cnVlfQ"}
POST
/reviews/import

Requires scope merchant-reviews-import.

Imports up to 100 reviews per request into pending moderation. Product references accept this store’s p_id, UUID or slug. The app identity and source are derived from the installation; re-import is idempotent by source_review_id. Approved imports contribute to product ratings but are not verified purchases. Limits: 30 requests/minute and 2,000/day per installation, plus 5,000 pending rows per app/store. Product resolution/mismatch, pending-cap 422 and 409 conflict attempts count toward quota; malformed payloads rejected by request validation do not. A 409 identity race includes Retry-After: 1; 429 responses include Retry-After seconds until the minute or daily window resets.

Authorization

merchantKey
X-Client-Key<token>

The store's private API key (sk_live_…, sk_test_… on a dev store) from Dashboard → Settings → API keys. It is bound to one store and carries the scopes the merchant granted; each operation names the scope it needs. Server-side only — never ship it to a browser or an app bundle.

In: header

Header Parameters

X-Client-Key*string

A private API key (sk_live_…, sk_test_… on a dev store) minted under Dashboard → Settings → API keys. The key is bound to ONE store, so no vendor header or vendor_id is sent; its scopes decide which operations it may call. pk_ public keys never reach this API. Keep it on your server.

X-Request-Id?string

Your own correlation id (8–128 chars, ^[A-Za-z0-9_.:-]+$). Echoed back on the response and on every log line of the request; one is generated when you omit it.

Idempotency-Key?string

Retry-safe write key. The same key with the same body replays the stored response for 24h with Idempotent-Replayed: true; with a different body it is 409 idempotency_key_reuse; while the first call is still running it is 409 idempotency_key_in_progress.

Request Body

application/json

TypeScript Definitions

Use the request body type in TypeScript.

Response Body

application/json

application/json

application/json

application/json

application/json

application/json

curl -X POST "https://example.com/reviews/import" \  -H "X-Client-Key: {{merchantKey}}" \  -H "Content-Type: application/json" \  -d '{    "reviews": [      {        "source_review_id": "chowdeck-review-2026-0042",        "product": "20417",        "rating": 5,        "title": "Fresh and delicious",        "description": "The jollof arrived hot.",        "author_display_name": "Ifeoma Adebayo",        "submitted_at": "2026-09-24T13:05:00+00:00",        "media": [          "https://adeyemifoods.com/reviews/2026-0042.jpg"        ]      }    ]  }'
{  "status": "success",  "message": "Product reviews imported",  "data": {    "results": [      {        "source_review_id": "chowdeck-review-2026-0042",        "result": "imported",        "status": "pending",        "product_p_id": 20417      }    ]  }}