Your store backend authenticates with a merchant API key. Keep it server-side; never expose it in browser JavaScript, mobile apps, checkout pages, or client storefront code.
API key header
x-api-key: lma_... Use ratings:read and ratings:write for protected integration calls.
02 / Private signals
Ratings
Storefront backend submissions create private buyer-risk ratings. They never affect your public merchant score; verified public reviews come from the invitation flow.
POST/ratingsAPI key: ratings:write
Record a buyer interaction for your own risk screening. Scores are optional and range from 0 to 5.
List ratings with pagination and optional from / to date filters.
GET/ratings/buyer-riskAPI key: ratings:read
Get the buyer's cancellation and return rates with a low, medium, or high risk band.
03 / Public reviews
Review invitations
Create one invitation per delivered order, then print the returned QR code on a receipt or parcel insert. The buyer opens a LMA39OL-hosted form and submits an order-linked public review.
Publish the LMA39OL verification mark in your storefront. Every official format links customers to a canonical profile with the independently aggregated score and confidence level.