# Kudobuzz > Kudobuzz is a reviews, user-generated content (UGC) and conversion-rate-optimization (CRO) platform for ecommerce merchants. It collects, moderates and displays product and social reviews, syncs shoppable UGC video, and runs post-purchase email campaigns for stores on Shopify, Wix, BigCommerce, Shoplazza and Webflow. Generated by the API Evangelist enrichment pipeline on 2026-07-19, last refreshed 2026-08-13, from the Kudobuzz public developer surface. Kudobuzz does not publish its own /llms.txt (probed: 404 on kudobuzz.com, api.kudobuzz.com and docs.kudobuzz.com). ## About the API The Kudobuzz Developer API is gated, not self-serve. Access is granted per account to merchants on the Buffet plan and, free of charge, to third-party app developers building Kudobuzz integrations. Credentials are issued by the Kudobuzz team on request via the Developer API page. - Production base URL: https://api.kudobuzz.com/v1 - Current version: v1 (integer versions prefixed with "v", carried in the URL path) - Authentication: a secret account token (`accessToken`) for server-side calls, and a public `clientId` for browser-side calls. No OAuth, no scopes. - Credentials are found in the Kudobuzz dashboard settings. - There is no OpenAPI definition. The published documentation describes the official JavaScript client wrapper rather than the raw HTTP contract. ## Developer surface - [Developer API overview](https://kudobuzz.com/developer-api): eligibility, how to request access, FAQ - [API documentation](https://docs.kudobuzz.com/): docsify site for the Kudobuzz client wrapper - [Quick start](https://docs.kudobuzz.com/#/quickstart): install and initialize the client - [Authentication](https://docs.kudobuzz.com/#/auth): token vs client id - [Core reference](https://docs.kudobuzz.com/#/core): review creation - [APM reference](https://docs.kudobuzz.com/#/apm): After Purchase Mail — customers and orders - [API design standards](https://github.com/kudobuzz/api-standards): Kudobuzz's public REST standard covering URLs, status codes, errors, versioning, pagination, rate limiting and idempotency - [GitHub organization](https://github.com/kudobuzz) - [Client library source](https://github.com/kudobuzz/kbjs-clients) ## Official client library ```bash npm i @kudobuzz/kbclient --save-exact ``` ```javascript import makeClient from '@kudobuzz/kbclient' const client = makeClient({ accessToken: 'Your access token here', clientId: 'Your client ID here' }) ``` JavaScript is the only language with a first-party client. No PyPI, RubyGems, Packagist, Maven Central, NuGet, Go module or crate exists. ## Documented operations - `client.core.reviews.createReview(payload)` — create a review (platform, source, created_at_platform, reviewer, rating, message required) - `client.apm.customers.createOrUpdate(customer)` — upsert a customer into an APM segment - `client.apm.orders.createOrUpdate(order)` — upsert an order with line items - `client.apm.orders.fetchOrders(query)` — list orders (business_id required; limit, cursor, sort optional) - `client.apm.orders.getOrderById(id)` — fetch a single order ## Conventions an agent must respect - **Pagination is cursor-based**: `limit`, `cursor` (meaning "everything greater than this id") and `sort` (comma-separated, `-` prefix descends). Responses wrap results as `{ "metadata": { "count": N }, "data": [...] }`. - **Errors are NOT RFC 9457**. The envelope is `{ "error": { "message", "code", "details": [{param, message, value}] } }` served as application/json. `error.code` is an internal code and is explicitly not the HTTP status. - **Status codes used**: 200, 201, 400, 401, 403, 404, 422, 429. - **Rate limits** are signalled with the legacy `X-Rate-Limit-Limit`, `X-Rate-Limit-Remaining` and `X-Rate-Limit-Reset` headers plus a 429. Numeric quotas are not published; they are communicated when credentials are issued. - **Idempotency is method-level only**. GET, PUT and DELETE are guaranteed idempotent by Kudobuzz's own standard. There is NO idempotency key, so a timed-out POST (createReview, createOrUpdate) must not be blindly retried — read the record back first or you will create duplicates. - **Sparse fieldsets** are supported via a comma-separated `fields` parameter. - **Bulk writes** follow `POST /{resource}/bulk` with an array body. - Kudobuzz mirrors the merchant's commerce platform as source of truth: entities carry `external_customer_id`, `external_reviewer_id`, `external_unique_id`, `external_channel_id` and `*_at_platform` timestamps. Ids are opaque strings with no type prefixes. ## Data model `Business` is the tenant boundary (`business_id`). `Review` has one `Reviewer` and references products by `external_unique_id[]`. `Customer` and `Order` belong to a `Business`; `Order` has many `LineItem` and embeds a customer summary. ## Privacy and consequence Kudobuzz acts as Data Processor under GDPR; the merchant is the Data Controller. Writing customers via the APM API pushes PII (email, phone, name) into a marketing audience — the merchant must hold a lawful basis. Review creation publishes merchant-visible content. Both are non-idempotent writes and should sit behind human confirmation in any agent deployment. ## What Kudobuzz does not publish No OpenAPI or AsyncAPI definition. No webhooks or event surface. No MCP server. No A2A agent card (probed 2026-08-13: `/.well-known/agent-card.json` and `/.well-known/agent.json` are 404 on kudobuzz.com, api.kudobuzz.com, docs.kudobuzz.com and dashboard.kudobuzz.com). No GraphQL endpoint. No CLI. No sandbox or test credentials. No public status page (`status.kudobuzz.com` answers 308 to itself — an infinite redirect, no document). No dated API changelog. No public Postman workspace. No /.well-known/ documents, including no security.txt. No vulnerability disclosure policy, safe-harbour statement or bug bounty — the security page does publish a contact for disclosures, but it is the general `help@kudobuzz.com` address, not a program. No OAuth scopes. No SOC 2 or ISO 27001 certification of its own (those are properties of its hosting providers). ## Commercial - [Pricing](https://kudobuzz.com/pricing) — three published plans, all self-serve, USD, monthly or yearly. Product & Social Reviews: **Growth** $19.99/mo or $180/yr, the only tier carrying **API Access**. UGC & Shoppable Videos: **Starter** $9.99/mo or $99/yr, **Growth** $19.99/mo or $199/yr. - **API access is a paid feature, and Kudobuzz's two pages disagree on which plan carries it.** The pricing page puts API Access on the Reviews *Growth* tier; the Developer API page (updated August 2026) says the *Buffet* plan — a name that no longer appears on the pricing page. App developers building integrations get API access free either way. - No perpetual free plan. The free "Coffee" plan was retired on 2026-06-30 and replaced with a 14-day full-access trial; Coffee merchants keep access until 2026-08-31. - [Sign up](https://dashboard.kudobuzz.com/signup) / [Log in](https://dashboard.kudobuzz.com/login) - [Help center](https://support.kudobuzz.com/en/) - [Blog](https://blog.kudobuzz.com/) - [Terms](https://kudobuzz.com/terms) · [Privacy](https://kudobuzz.com/privacy) · [Security](https://kudobuzz.com/security) · [GDPR](https://kudobuzz.com/gdpr)