GetRating developer docs
Everything you can build on today: a REST API for reviews, signed webhooks and Zapier-compatible endpoints. All requests go to https://getrating.co over HTTPS.
Authentication
Create an API key in the dashboard under Integrations. The full key is shown once, so store it securely. Send it in the X-API-Key header. Revoked, expired or suspended-account keys return 401 or 403.
curl -H "X-API-Key: $GETRATING_API_KEY" \
"https://getrating.co/api/v1/reviews?locationId=LOCATION_ID&page=1&limit=20"REST API
GET /api/v1/reviews
Returns approved public reviews for one of your locations, newest first. Query parameters: locationId (required), page (default 1) and limit (1–100, default 20). Requires an API key.
{
"reviews": [
{
"id": "clx...",
"stars": 5,
"feedback": "Great service",
"reviewerName": "Anna",
"publishedAt": "2026-09-30T12:00:00.000Z"
}
],
"pagination": { "page": 1, "limit": 20, "total": 42, "totalPages": 3 },
"summary": {
"avgRating": 4.7,
"totalReviews": 42,
"distribution": { "1": 0, "2": 1, "3": 2, "4": 8, "5": 31 }
}
}GET /api/v1/reviews/public/{slug}
The same review list for a location's public slug, without an API key. Limited to 30 requests per minute per client; over the limit returns 429 with a Retry-After header.
Webhooks
Add webhook endpoints under Dashboard → Integrations. Each webhook subscribes to one or more events:
new_feedback: a customer submitted feedbacklow_rating: a low rating was receivedfeedback_resolved: feedback was marked resolvedweekly_summary: weekly performance summary
Deliveries are JSON POST requests with the headers X-Webhook-Event, X-Webhook-ID and, when you set a secret, X-Webhook-Signature (sha256= followed by the hex HMAC-SHA256 of the raw body). Requests time out after 10 seconds and failed deliveries are retried up to 3 times. You can send a test event and inspect recent deliveries in the dashboard.
import { createHmac, timingSafeEqual } from "node:crypto"
export function isValidSignature(rawBody: string, header: string, secret: string) {
const expected = "sha256=" + createHmac("sha256", secret).update(rawBody).digest("hex")
const a = Buffer.from(expected)
const b = Buffer.from(header)
return a.length === b.length && timingSafeEqual(a, b)
}Zapier endpoints
These endpoints follow Zapier's REST hook pattern and use the same X-API-Key header.
POST /api/zapier/authwith{ "api_key": "..." }tests a key.POST /api/zapier/webhookssubscribes atarget_urlto anevent_type(new_feedback, low_rating, feedback_resolved, weekly_summary, external_review_received, alert_triggered), optionally for onelocation_id.DELETEwithwebhook_idunsubscribes.GET /api/zapier/triggers/reviews,/triggers/locationsand/triggers/alertsreturn sample and polling data. Reviews acceptlocation_id,since,status,min_stars,max_starsandlimit(max 100).POST /api/zapier/actions?action=…runscreate_review,update_review_status(open, in_progress, resolved),send_reply(records a reply on the feedback; it does not send a message) orcreate_alert.
Not sure where to start? The integrations page explains what each connection does.
What the API does not cover
- No endpoints for creating or editing locations, campaigns or billing.
- No access to reviews on Google or other sites through the reviews API; it returns reviews collected in GetRating.
- No official SDKs. Use any HTTP client.
Frequently asked questions
Does GetRating have an API?
Yes. A REST API returns the approved public reviews collected through GetRating for your locations, authenticated with an API key. Webhooks and Zapier endpoints cover events and actions.
Which plans include API access?
API keys, webhooks and the Zapier endpoints are available on every plan, including Free.
Can the API post reviews to Google?
No. Nothing in GetRating writes reviews to Google or other review sites. The API reads reviews collected through GetRating, and the Zapier create-review action records feedback inside GetRating only.