REST · JSON · CORS

Sites.Reviews Trust API

Trust Score, reviews, and company verification — right in your product, extension, or AI assistant. Public API without a key in 30 seconds, Authenticated API by key for partners.

Without a key — 60 req/min Read-only CORS * MCP for AI
Two tiers

Choose the appropriate access

The same data is available for free without a key and with a key with increased limits. Start with Public, switch to Authenticated when you need volume.

Tier 1 · Public

Public API — no key required

For AI assistants, browser extensions, and quick integrations. Connect without registration.

  • Base: https://sites.reviews/api/public/v1
  • No authorization, read-only
  • 60 requests per minute per IP
  • CORS * — works from the browser
  • check · business · reviews · search
Tier 2 · Authenticated

Authenticated API — by key

For partners: the same dataset, individual limits, and priority. Key issued in the personal account.

  • Base: https://sites.reviews/api/v1
  • Header Authorization: Bearer sr_…
  • or X-API-Key: sr_…
  • Individual limit per key
  • check · search · business · reviews
Quick Start

First request in 30 seconds

Check any domain right now — no key needed. Response in JSON, accessible from the browser thanks to open CORS.

Request
curl "https://sites.reviews/api/public/v1/check?domain=ozon.ru"
Response 200 OK
{
  "id": 1101,
  "name": "OZON",
  "slug": "ozon-ru",
  "website": "https://www.ozon.ru",
  "trust_score": 8.4,
  "avg_ratings": 4.2,
  "total_reviews": 1247,
  "is_verified": true,
  "url": "https://sites.reviews/businesses/ozon-ru",
  "logo": "https://sites.reviews/storage/logos/ozon.png"
}
Tier 1

Public API

Open read-only access without authorization. Base URL https://sites.reviews/api/public/v1. Limit — 60 requests per minute per IP, CORS *.

GET /check?domain={domain}

Quick domain check: Trust Score, rating, and number of reviews. Perfect for extensions and AI assistants.

ParameterTypeDescription
domainstringDomain without protocol, e.g. ozon.ru

The domain matches exactly: protocol, www, and trailing slash are ignored, and a subdomain is a different company. shop.example.com and example.com never respond for each other.

Response — company found
{
  "found": true,
  "id": 1101,
  "name": "OZON",
  "slug": "ozon-ru",
  "website": "https://www.ozon.ru",
  "trust_score": 8.4,
  "avg_ratings": 4.2,
  "total_reviews": 1247,
  "is_verified": true,
  "url": "https://sites.reviews/businesses/ozon-ru",
  "review_url": "https://sites.reviews/businesses/ozon-ru/review",
  "logo": "https://sites.reviews/storage/logos/ozon.png"
}
Response — not in the directory
{
  "found": false,
  "domain": "unknown-shop.com",
  "submit_url": "https://sites.reviews/businesses/add?domain=unknown-shop.com"
}
POST /check-batch

Up to 100 domains per call — a showcase with fifty stores doesn't need to make fifty requests and waste the entire minute limit. The response is grouped by the domain you sent.

curl -X POST "https://sites.reviews/api/public/v1/check-batch" \
  -H "Content-Type: application/json" \
  -d '{"domains":["ozon.ru","unknown-shop.com"]}'
{
  "count": 2,
  "results": {
    "ozon.ru": { "found": true, "trust_score": 8.4, "total_reviews": 1247, "...": "..." },
    "unknown-shop.com": { "found": false, "submit_url": "https://sites.reviews/businesses/add?website=unknown-shop.com" }
  }
}
GET /badge?domain={domain}&theme=light|dark

Trust badge as an image (SVG). The simplest integration: one line in HTML, no scripts or iframes. While the company has no ratings, the badge honestly says 'no ratings' — we don't draw a zero rating.

<a href="https://sites.reviews/businesses/ozon-ru">
  <img src="https://sites.reviews/api/public/v1/badge?domain=ozon.ru" alt="Sites.Reviews" width="196" height="48">
</a>
GET /business/{domain}

Full company profile: descriptions, AI summary, social media, address, category, and tags.

Response 200 OK
{
  "id": 1101,
  "name": "OZON",
  "slug": "ozon-ru",
  "website": "https://www.ozon.ru",
  "trust_score": 8.4,
  "avg_ratings": 4.2,
  "total_reviews": 1247,
  "is_verified": true,
  "url": "https://sites.reviews/businesses/ozon-ru",
  "logo": "https://sites.reviews/storage/logos/ozon.png",
  "short_description": "Маркетплейс №1 в России",
  "description": "OZON — один из крупнейших маркетплейсов...",
  "ai_about": "Компания работает с 1998 года...",
  "ai_summary": "Покупатели хвалят скорость доставки и...",
  "social_links": {
    "instagram": "https://instagram.com/ozonru",
    "vk": "https://vk.com/ozon"
  },
  "address": "Москва, Пресненская наб. 10",
  "category_id": 3,
  "tags": ["marketplace", "ecommerce", "retail"],
  "created_at": "2024-11-02T09:14:00Z"
}
Response 404 Not Found
{ "error": "not_found" }
GET /reviews/{domain}

Paginated list of reviews with pros/cons and English translation of the body (body_en).

ParameterTypeBy defaultDescription
pageint1Page number
per_pageint20Reviews per page
Request
curl "https://sites.reviews/api/public/v1/reviews/ozon-ru?page=1&per_page=20"
Response 200 OK
{
  "business": {
    "id": 1101,
    "name": "OZON",
    "slug": "ozon-ru",
    "trust_score": 8.4
  },
  "page": 1,
  "per_page": 20,
  "total": 1247,
  "reviews": [
    {
      "id": 58213,
      "title": "Быстрая доставка",
      "body": "Заказ приехал за один день, всё в порядке.",
      "body_en": "The order arrived in one day, everything is fine.",
      "stars": 5,
      "pros": "Скорость, упаковка",
      "cons": "Нет",
      "author": "Ирина М.",
      "created_at": "2025-12-18T11:42:00Z"
    }
  ]
}
Tier 2

Authenticated API

The same dataset with individual limits. Base URL https://sites.reviews/api/v1. Each request is signed with a key sr_… one of two headers:

Option 1 — Bearer token
curl "https://sites.reviews/api/v1/check?domain=ozon.ru" \
  -H "Authorization: Bearer sr_live_8f2c91a4e7b0d36f"
Option 2 — X-API-Key
curl "https://sites.reviews/api/v1/check?domain=ozon.ru" \
  -H "X-API-Key: sr_live_8f2c91a4e7b0d36f"
The key is issued in the personal account — no emails or applications required. Log in, to create a key.

Endpoints /v1

Behavior, parameters, and response format are identical to the Public API — only the base URL, key authorization, and limits differ. Profile and reviews are addressed by slug.

MethodPathPurpose
GET/v1/check?domain={domain}Domain check
POST/v1/check-batchUp to 100 domains per call
GET/v1/search?q={query}Company search
GET/v1/business/{slug}Full profile
GET/v1/reviews/{slug}List of reviews
POST/v1/businessCreate a card by domain — scope write:business

The key is passed only in the header. The key in the query string is not accepted: it settles in logs, browser history, and the Referer header.

Key rights are explicit: by default, it is granted public (read). Scopes write:business and quests are granted separately — a key without scopes opens nothing.

Webhooks

To avoid polling us on a timer: when a review is published for the domain of interest, we will call your HTTPS endpoint ourselves. The subscription is tied to the key — the review of the key disables it.

POST {ваш URL}
X-SR-Event: review.published
X-SR-Timestamp: 1772457600
X-SR-Signature: sha256=<hmac_sha256("{timestamp}.{тело}", secret)>

{
  "event": "review.published",
  "business": { "domain": "example.com", "trust_score": 8.4, "total_reviews": 12, "...": "..." },
  "review":   { "id": 5512, "stars": 5, "title": "…", "author": "…", "url": "…" }
}

Check the signature against the raw body and reject requests with X-SR-Timestamp older than 5 minutes — otherwise, an intercepted call can be replayed. Connection is through us: let us know which domain and URL.

Reference

Limits and headers

ParameterPublic APIAuthenticated API
Authorizationnot requiredBearer sr_… or X-API-Key
Rate limit60 req/min per IPindividually per key
Accessreading + quick-add cardreading; writing — by scope
CORS**
Response cacheup to 60 secondsup to 60 seconds

As you approach the limit, monitor the standard response headers:

X-RateLimit-Limit: 60
X-RateLimit-Remaining: 58
Retry-After: 31          # только в ответе 429

Errors

CodeWhenResponse body
404 Company not found { "error": "not_found" }
422 Parameter failed validation (e.g. q < 3) { "error": "validation_error", "message": "…" }
429 Rate limit exceeded { "error": "rate_limited", "retry_after": 31 }
Integrations

For AI assistants

Connect Sites.Reviews to Claude, Cursor, and other AIs via the MCP server — the assistant can check companies and read reviews directly in the chat.

Launch MCP server
npx -y @sitesreviews/mcp
MCP server

Ready-made tools check / search / reviews for AI assistants. Install with one command.

sites-reviews-mcp
OpenAPI and documentation

Full OpenAPI specification, SDK examples, and a reference for all endpoints.

sites-reviews-api

Ready to build trust?

Start with the Public API without a key right now, and create a key in your personal account in a minute for increased limits.