Developer documentation

Verified trust, built into your storefront.

Use the LMA39OL API to collect order-linked reviews and publish a trust signal customers can verify.

01 / Access

Authentication

Your store backend authenticates with a merchant API key. Keep it server-side; never expose it in browser JavaScript, mobile apps, checkout pages, or client storefront code.

API key header

x-api-key: lma_...
Use ratings:read and ratings:write for protected integration calls.

02 / Private signals

Ratings

Storefront backend submissions create private buyer-risk ratings. They never affect your public merchant score; verified public reviews come from the invitation flow.

POST/ratingsAPI key: ratings:write

Record a buyer interaction for your own risk screening. Scores are optional and range from 0 to 5.

curl -X POST http://localhost:3001/ratings \
  -H "x-api-key: lma_..." -H "Content-Type: application/json" \
  -d '{"orderReference":"ORD-1042","productQuality":5,"deliveryTime":4,"comment":"Smooth transaction"}'
GET/ratings?page=1&limit=20API key: ratings:read

List ratings with pagination and optional from / to date filters.

GET/ratings/buyer-riskAPI key: ratings:read

Get the buyer's cancellation and return rates with a low, medium, or high risk band.

03 / Public reviews

Review invitations

Create one invitation per delivered order, then print the returned QR code on a receipt or parcel insert. The buyer opens a LMA39OL-hosted form and submits an order-linked public review.

POST/review-invitationsAPI key: ratings:write
curl -X POST http://localhost:3001/review-invitations \
  -H "x-api-key: lma_..." -H "Content-Type: application/json" \
  -d '{"orderReference":"ORD-1042","buyer":{"firstName":"Amina","lastName":"K.","email":"amina@example.com"},"expiresInDays":14}'

The response includes reviewUrl and a printable PNG qrCodeDataUrl. A repeated order reference returns 409.

GET/review-invitations?page=1&limit=20API key: ratings:read

List invitations created by your store.

04 / Public proof

Trust badge

Publish the LMA39OL verification mark in your storefront. Every official format links customers to a canonical profile with the independently aggregated score and confidence level.

Web Component

Recommended for stores that allow custom HTML.

GET/trust/badge.js

Hosted iframe

For builders that restrict scripts.

GET/embed

SVG image

For emails, receipts, and image-only surfaces.

GET/badge.svg

Web Component

<script async src="http://localhost:3001/trust/badge.js"></script>
<lma39ol-trust-badge merchant-id="MERCHANT_ID" variant="standard" theme="light"></lma39ol-trust-badge>

Use variant="compact" for dense layouts and theme="dark" on dark storefronts. The script also accepts data-merchant-id for the shortest installation.

Iframe and SVG

<iframe src="http://localhost:3001/trust/merchants/MERCHANT_ID/embed?variant=standard&theme=light"
  title="LMA39OL verified trust score" loading="lazy" style="border:0;width:290px;height:84px"></iframe>

<img src="http://localhost:3001/trust/merchants/MERCHANT_ID/badge.svg" alt="LMA39OL verified trust score">
GET/trust/merchants/:merchantIdPublic JSON

Use the raw aggregate, dimension scores, and confidence band only when you need a fully custom storefront presentation.

05 / Reliability

Errors and limits

Every API response includes a success boolean. Failures may contain an errorCode, a message, and per-field errors.

{ "success": false, "errorCode": "A0013", "message": "unauthorized !" }
Protected rating endpoints allow 100 requests per hour per API key. A rate-limited request returns 429.