API reference

JSON over HTTPS. Errors return { "error": "…" } with a 4xx status.

The flow

QR scan → POST visits → POST rate (good → Google URL + POST google) | (bad → POST feedback → manager email)

Public — powers the customer review pages

No key. Called by the review pages on every client domain (reviews.mrniceguys.com/api/… works too). Use these to build a review flow on your own stack.

GET/api/public/orgs/:site

Branding and active stores for a client. :site is the custom domain or slug.

curl https://covrreviews.com/api/public/orgs/reviews.mrniceguys.com
POST/api/public/visits

Open a visit when a QR is scanned. Returns visitId. Refreshes within 10 minutes reuse the open visit.

{ "site": "reviews.mrniceguys.com", "code": "K7Q2MX" }
POST/api/public/visits/:id/rate

Record good/bad. Returns the store's Google review URL.

{ "sentiment": "good" }
POST/api/public/visits/:id/google

Customer tapped through to Google. Safe to send with navigator.sendBeacon.

POST/api/public/feedback

File an unhappy-customer ticket and email the store's managers.

{ "visitId": "…", "name": "Dana", "phone": "503-555-0100", "email": "", "contactPreference": "text", "message": "Waited 20 minutes at pickup" }
GET/api/qr/:code?format=svg|png&size=512

QR image for an associate or counter code, encoding the client's review URL.

v1 — for integrations

Send Authorization: Bearer crv_… — create keys in Admin → Settings. Every call is scoped to the key's client.

GET/api/v1/locations· API key

Stores, with counter QR URLs, Google review URLs and manager emails.

GET/api/v1/associates?location=<id|slug>· API key

Associates with their codes, review URLs and QR image links.

POST/api/v1/associates· API key

Add an associate (HR/POS sync). Generates their code.

{ "locationId": "…", "firstName": "Jordan", "lastName": "Lee", "payrollId": "1042" }
GET/api/v1/feedback?status=new|contacted|resolved· API key

Unhappy-customer tickets, newest first.

GET/api/v1/stats?days=30&location=<id>· API key

Totals, daily series, per-store and per-associate rollups.

GET/api/v1/visits?since=<ISO>&limit=500· API key

Raw scan events for your warehouse. Page with the returned `next`.

curl -H "Authorization: Bearer $CRV_KEY" "https://covrreviews.com/api/v1/visits?since=2026-10-01T00:00:00Z"