openapi: 3.2.0 info: title: SmartCustomer (Sitejabber) Business Authentication API version: v1 summary: Business review, product review, review request, messaging and privacy API for SmartCustomer (formerly Sitejabber). description: 'Transcribed by API Evangelist from SmartCustomer''s own published API reference at https://api.sitejabber.com/ (Slate source: https://github.com/smartcustomer-reviews/business-api-docs). SmartCustomer does not publish an OpenAPI definition; every path, parameter, default, enum and schema field below is copied from the provider''s published reference tables. Where the reference names an object but publishes no field table (ProductCategory, ProductAttribute) the schema is left open rather than invented. Response wrappers are modelled from the published example payloads and the documented status/success envelope. Authentication is two-part: a client_token (API key) passed as a query parameter on every call, plus a user_token request header obtained from POST /login.' contact: name: SmartCustomer API Support email: support@smartcustomer.com url: https://api.sitejabber.com/ termsOfService: https://www.smartcustomer.com/terms x-transcribed-by: API Evangelist enrichment pipeline x-transcription-source: https://api.sitejabber.com/ servers: - url: https://api.smartcustomer.com/v1 description: Production. The same reference is also served from https://api.sitejabber.com/ under the pre-rebrand Sitejabber name. security: - client_token: [] user_token: [] tags: - name: Authentication paths: /login: post: operationId: login summary: Log in and obtain a user token tags: - Authentication responses: '200': description: Successful response content: application/json: schema: allOf: - $ref: '#/components/schemas/ResponseEnvelope' - $ref: '#/components/schemas/LoginObject' '429': $ref: '#/components/responses/TooManyRequests' description: Exchanges account credentials for a user token used in subsequent calls in the user_token header. The token typically expires after 6 months. Calling login invalidates any previously generated user token. requestBody: required: true content: application/x-www-form-urlencoded: schema: type: object properties: email: type: string description: Account email password: type: string description: Account password required: - email - password security: - client_token: [] components: responses: TooManyRequests: description: Too many requests. 1000 calls per hour per unique user token; no more than 10 calls in a 10 second window. content: application/json: schema: $ref: '#/components/schemas/ResponseEnvelope' schemas: ResponseEnvelope: type: object description: Every response carries a success flag and a status key. When success is false and status is ERROR, errorCode and errorReason are present. properties: status: type: string description: OK if everything went good, ERROR if there was an error processing the request success: type: boolean description: true or false errorCode: type: integer description: Error code, only present when status is ERROR errorReason: type: string description: Error message, only present when status is ERROR LoginObject: type: object title: Login Object properties: token: type: string description: Token used in subsequent calls as user identifier expire: type: string description: When the token will expire (typically after 6 months) user: allOf: - $ref: '#/components/schemas/User' description: User logged in into the system User: type: object title: User Object required: - username - firstName - lastName - thumbnail - profilePage - numReviews - numHelpfulVotes properties: username: type: string description: Username of the user firstName: type: string description: First name of the user lastName: type: string description: First letter of last name of the user thumbnail: type: string description: Relative path of the user's thumbnail image profilePage: type: string description: Url of the user's profile page numReviews: type: integer description: Number of reviews written by the user numHelpfulVotes: type: integer description: Number of helpful votes received email: type: string description: Only available for solicited reviews and when the email of the user was provided by the business securitySchemes: client_token: type: apiKey in: query name: client_token description: API key issued to the business, passed as a query parameter on every request. user_token: type: apiKey in: header name: user_token description: User session token returned by POST /login. Typically expires after 6 months; calling login invalidates any previous token. externalDocs: description: SmartCustomer API reference url: https://api.sitejabber.com/