byLegit Business API

The Business API exists for one purpose: knowing whether a reviewer is a real customer, without ever exposing personal data. Two modes are available; use either or both.

1. Get a key

In the Business console, open your site page, go to the API tab and create a key. It starts with blg_ and is shown only once. A key belongs to a single site and can be revoked at any time.

curl https://bylegit.com/api/public/v1/ping \
  -H "Authorization: Bearer blg_your_key"

{ "status": "ok", "domain": "example.com", "verify_url_configured": true }

2. Push mode — you tell us about a signup

When a user signs up (or during a one-off import), send their email address. byLegit always answers the same thing: the request was accepted. Nothing is revealed about byLegit accounts.

curl -X POST https://bylegit.com/api/public/v1/customers \
  -H "Authorization: Bearer blg_your_key" \
  -H "Content-Type: application/json" \
  -d '{"email":"person@example.com"}'

202 { "status": "accepted" }

The address is never stored in clear text: we keep only a cryptographic fingerprint scoped to your site.

3. Lookup mode — we ask you yes or no

Set an HTTPS verification endpoint on your key. When someone writes a review, byLegit sends a signed request to it and expects a simple boolean.

POST https://example.com/bylegit/verify
Content-Type: application/json
x-bylegit-signature: <HMAC-SHA256(body, your_api_key)>

{ "email": "person@example.com" }

--> respond: { "registered": true }

Always verify the signature before answering: it is an HMAC-SHA256 of the raw request body, keyed with your API key. Answer within 6 seconds, and return nothing beyond registered.

// Node example
import { createHmac, timingSafeEqual } from "node:crypto";

const raw = await readRawBody(req);
const expected = createHmac("sha256", process.env.BYLEGIT_API_KEY).update(raw).digest("hex");
const given = req.headers["x-bylegit-signature"] ?? "";
if (given.length !== expected.length ||
    !timingSafeEqual(Buffer.from(given), Buffer.from(expected))) {
  return res.status(401).json({ error: "bad signature" });
}
const { email } = JSON.parse(raw);
res.json({ registered: await userExists(email) });

4. The verified customer badge

When a signal exists, the reviewer is asked explicitly before publishing. If they accept, the review carries the “Verified customer” badge. If they decline, the review is published as usual, without a badge. Anyone can also switch these verifications off, or delete the resulting data, from their privacy settings.

5. Rules and limits

  • A key grants access to a single site, never to reviews or profiles.
  • The API never reveals whether a byLegit account exists, nor any personal data.
  • Only send addresses of your own users, with a valid legal basis.
  • Revoke any compromised key from the console: revocation is immediate.