Reviews
Requires scope merchant-reviews-read.
Lists only this installed app’s imported reviews for this store, newest ingested first with cursor pagination. Approved imports remain unverified and are hidden from verified-only storefront blocks, store-wide summaries and testimonials unless the merchant opts in with verified_only=0. Customer product review lists, per-product summaries and latest-approved reviews include approved imports. Native reviews and rating aggregates are not readable through this API. Imports are capped at 30 requests/minute and 2,000/day per installation, and 5,000 pending rows per app/store; 409 conflicts may be retried after 1 second.
Authorization
merchantKey The store's private API key (sk_live_…, sk_test_… on a dev store) from Dashboard → Settings → API keys. It is bound to one store and carries the scopes the merchant granted; each operation names the scope it needs. Server-side only — never ship it to a browser or an app bundle.
In: header
Query Parameters
1 <= value <= 100length <= 255Value in
- "pending"
- "approved"
- "rejected"
Header Parameters
A private API key (sk_live_…, sk_test_… on a dev store) minted under Dashboard → Settings → API keys. The key is bound to ONE store, so no vendor header or vendor_id is sent; its scopes decide which operations it may call. pk_ public keys never reach this API. Keep it on your server.
Your own correlation id (8–128 chars, ^[A-Za-z0-9_.:-]+$). Echoed back on the response and on every log line of the request; one is generated when you omit it.
Response Body
application/json
application/json
application/json
application/json
application/json
curl -X GET "https://example.com/reviews?limit=2&starting_after=eyJjcmVhdGVkX2F0IjoiMjAyNi0xMC0wMyAwOTowMDowMCIsImlkIjoiMDE5YTFkNTItM2M4ZS03ZjQxLWIwZDItNmEzZTljMWY0YjIxIiwiX3BvaW50c1RvTmV4dEl0ZW1zIjp0cnVlfQ&status=pending" \ -H "X-Client-Key: {{merchantKey}}"{ "data": [ { "source_review_id": "chowdeck-review-2026-0042", "source": "chowdeck", "author_display_name": "Ifeoma Adebayo", "product_p_id": 20417, "rating": 5, "title": "Fresh and delicious", "description": "The jollof arrived hot.", "media": [], "status": "pending", "is_verified_purchase": false, "submitted_at": "2026-09-24T13:05:00+00:00", "created_at": "2026-10-03T08:00:00.000000Z", "edited_at": null } ], "has_more": true, "next_cursor": "eyJjcmVhdGVkX2F0IjoiMjAyNi0xMC0wMyAwOTowMDowMCIsImlkIjoiMDE5YTFkNTItM2M4ZS03ZjQxLWIwZDItNmEzZTljMWY0YjIxIiwiX3BvaW50c1RvTmV4dEl0ZW1zIjp0cnVlfQ"}Requires scope merchant-reviews-import.
Imports up to 100 reviews per request into pending moderation. Product references accept this store’s p_id, UUID or slug. The app identity and source are derived from the installation; re-import is idempotent by source_review_id. Approved imports contribute to product ratings but are not verified purchases. Limits: 30 requests/minute and 2,000/day per installation, plus 5,000 pending rows per app/store. Product resolution/mismatch, pending-cap 422 and 409 conflict attempts count toward quota; malformed payloads rejected by request validation do not. A 409 identity race includes Retry-After: 1; 429 responses include Retry-After seconds until the minute or daily window resets.
Authorization
merchantKey The store's private API key (sk_live_…, sk_test_… on a dev store) from Dashboard → Settings → API keys. It is bound to one store and carries the scopes the merchant granted; each operation names the scope it needs. Server-side only — never ship it to a browser or an app bundle.
In: header
Header Parameters
A private API key (sk_live_…, sk_test_… on a dev store) minted under Dashboard → Settings → API keys. The key is bound to ONE store, so no vendor header or vendor_id is sent; its scopes decide which operations it may call. pk_ public keys never reach this API. Keep it on your server.
Your own correlation id (8–128 chars, ^[A-Za-z0-9_.:-]+$). Echoed back on the response and on every log line of the request; one is generated when you omit it.
Retry-safe write key. The same key with the same body replays the stored response for 24h with Idempotent-Replayed: true; with a different body it is 409 idempotency_key_reuse; while the first call is still running it is 409 idempotency_key_in_progress.
Request Body
application/json
TypeScript Definitions
Use the request body type in TypeScript.
Response Body
application/json
application/json
application/json
application/json
application/json
application/json
curl -X POST "https://example.com/reviews/import" \ -H "X-Client-Key: {{merchantKey}}" \ -H "Content-Type: application/json" \ -d '{ "reviews": [ { "source_review_id": "chowdeck-review-2026-0042", "product": "20417", "rating": 5, "title": "Fresh and delicious", "description": "The jollof arrived hot.", "author_display_name": "Ifeoma Adebayo", "submitted_at": "2026-09-24T13:05:00+00:00", "media": [ "https://adeyemifoods.com/reviews/2026-0042.jpg" ] } ] }'{ "status": "success", "message": "Product reviews imported", "data": { "results": [ { "source_review_id": "chowdeck-review-2026-0042", "result": "imported", "status": "pending", "product_p_id": 20417 } ] }}