Documentation
Reviews
reviews.for_customer
REST
ShippingPOST /api/v1/reviews/for_customerMCP tool
Livereviews.for_customerExposed on: REST API · Shop MCP server · Claude connector · Dash (in-app copilot) · Zapier. Part of the Reviews domain.
Operating contract
EVERYTHING THIS CUSTOMER HAS SAID ABOUT THE SHOP, in both places it can land: the private ratings they gave the shop directly, and the public reviews that appear to be theirs.
READ THIS BEFORE ANY CONVERSATION THAT MATTERS. Somebody who left three stars last month is not somebody to send a cheerful upsell to, and somebody who left five is worth asking for a referral. Nothing else in the customer's file says either.
THE PUBLIC MATCHES ARE A NAME MATCH AND NOTHING MORE. name_match: true is on every one of them because that is genuinely all the link is — a public review carries a reviewer's display name and no customer id. NEVER tell a customer 'we saw your review'; a namesake exists in most books, and the response says how many were found.
A PRIVATE RATING IS NOT A REVIEW AND MUST NEVER BE ANSWERED IN PUBLIC. routed_to: private means the rating was deliberately kept away from Google — that is the mechanism working, and quoting one publicly broadcasts something the customer chose not to publish.
note on a private rating is the customer's own words to the shop. It is often the whole answer to why they have not been back.
Both lists are capped and returned in full, so nothing is truncated. An empty response means this customer has never rated or reviewed — not that they were unhappy and stayed quiet.
Who may call it
- Permission
customers.accessThe caller must hold Customers at the ACT level. A read-only dashboard grant on the same section is refused.- Plan
- Every planNo plan gate. Available on every Service VIN plan.
- Retries
naturalNaturally idempotent — running it twice leaves the same world as running it once. A retrying integration needs no key.- Rate class
readCounted against the read budget — the widest of the four.
Input
| Field | Type | Description |
|---|---|---|
| customer_idrequired | stringuuid | The customer to look up, as returned by customers.list or customers.find_by_contact. |
Output
| Field | Type | Description |
|---|---|---|
| customer_id | string | — |
| private_ratings | object[] | — |
| private_ratings[].id | string | — |
| private_ratings[].rating | number | — |
| private_ratings[].routed_to | string | — |
| private_ratings[].note | string | null | — |
| private_ratings[].rated_at | string | — |
| private_ratings[].job_id | string | null | — |
| private_ratings[].job_number | number | null | — |
| public_reviews | object[] | — |
| public_reviews[].id | string | — |
| public_reviews[].stars | number | — |
| public_reviews[].comment | string | null | — |
| public_reviews[].reply | string | null | — |
| public_reviews[].reviewer_name | string | — |
| public_reviews[].created_at | string | — |
| public_reviews[].name_match | boolean | — |
| namesakes_in_book | boolean | — |
Examples
Built from this capability's own schema — required fields and the ones carrying a default, and nothing invented. Paste one and it validates.
export SERVICEVIN_API_KEY=svk_live_…
curl -X POST https://www.servicevin.com/api/v1/reviews/for_customer \
-H "Authorization: Bearer $SERVICEVIN_API_KEY" \
-H "Content-Type: application/json" \
-d '{"customer_id":"9b2f1c6e-4a77-4d2b-9f31-0f1c9a8e5d20"}'const res = await fetch("https://www.servicevin.com/api/v1/reviews/for_customer", {
method: "POST",
headers: {
Authorization: `Bearer ${process.env.SERVICEVIN_API_KEY}`,
"Content-Type": "application/json",
},
body: JSON.stringify({
"customer_id": "9b2f1c6e-4a77-4d2b-9f31-0f1c9a8e5d20"
}),
});
// Success and failure are both envelopes. Switch on error.code, never
// on error.message — the codes are stable, the messages are for people.
const payload = await res.json();
if (!res.ok) throw new Error(payload.error.code);
const data = payload.data;import os, requests
res = requests.post(
"https://www.servicevin.com/api/v1/reviews/for_customer",
headers={"Authorization": f"Bearer {os.environ['SERVICEVIN_API_KEY']}"},
json={
"customer_id": "9b2f1c6e-4a77-4d2b-9f31-0f1c9a8e5d20"
},
timeout=30,
)
payload = res.json()
if not res.ok:
raise RuntimeError(payload["error"]["code"])
data = payload["data"]{
"jsonrpc": "2.0",
"id": 1,
"method": "tools/call",
"params": {
"name": "reviews.for_customer",
"arguments": {
"customer_id": "9b2f1c6e-4a77-4d2b-9f31-0f1c9a8e5d20"
}
}
}Refusals
The four gates run in this order on every surface, and the order is not arbitrary — see Authentication.
| Status | Code | When |
|---|---|---|
| 404 | not_found | The id is unknown, or the feature is not enabled for this account. Deliberately the same answer for both. |
| 403 | forbidden | This login does not hold customers.access. |
| 422 | validation_error | An argument was wrong. The message names the field. |
| 429 | rate_limited | Too many read calls. Back off and retry. |
| 500 | internal_error | Something failed on our side. Nothing was changed. |