Skip to main content
POST
Post a traveler review on behalf of a completed booking

Authorizations

Authorization
string
header
default:sk_test_DEMO0000_replace_with_your_sandbox_key
required

API key authentication. Issued by the Safariat admin or via the partner portal. The secret is shown only once at generation.

Production sk_live_* keys must additionally sign every write request (POST/PUT/DELETE) with the X-Timestamp and X-Signature headers. Sandbox sk_test_* keys are exempt from request signing: X-Signature and X-Timestamp are not required for writes in the sandbox (so the developer-portal "Try it" playground works end to end). The Idempotency-Key header remains required on writes in both environments.

Headers

Idempotency-Key
string
required

Opaque, client-generated string unique per logical operation (a UUID v4 is recommended but any non-blank value up to 255 chars is accepted). Same key + same body = the cached response is returned with the Idempotent-Replayed: true header. Same key + different body = 409 Conflict. Retained for 24 h.

Maximum string length: 255
X-Timestamp
integer<int64>
required

Unix timestamp in seconds at the time the request is issued. Validity window ±5 minutes — beyond that the request is rejected. Required for production sk_live_* keys only; not required for sandbox sk_test_* keys.

X-Signature
string
required

hex(HMAC_SHA256(secret, "{X-Timestamp}\n{METHOD}\n{path}\n{body}")). The path includes the query string. The body is the exact JSON representation sent — any reformatting invalidates the signature. Required for production sk_live_* keys only; not required for sandbox sk_test_* keys.

Pattern: ^[a-f0-9]{64}$

Body

application/json
booking_number
string
required

Number of a completed booking owned by the calling partner.

Pattern: ^MV-[A-Z0-9]{6,}$
Example:

"MV-20260714-AB7X92"

rating
integer
required
Required range: 1 <= x <= 5
Example:

5

comment
string
required
Required string length: 10 - 4000
title
string

Optional short headline shown above the comment.

Maximum string length: 200
author_name
string

Optional override for the displayed traveler name. When omitted, Safariat uses the lead traveler's first name captured at booking time.

Maximum string length: 200
photo_urls
string<uri>[]

Up to 10 photo URLs previously issued by POST /files/presigned-upload for this partner. Each URL is verified server-side: any URL that does not scope to this partner's namespace or does not match an uploaded file returns 422 partner.review.photo.not.found.

Maximum array length: 10
Pattern: ^https://

Response

Review created

id
string<uuid>
required
reviewable_type
enum<string>
required
  • EXPERIENCE / TRIP: reviewable_id is the adventure id.
  • AGENCY: reviewable_id is the agency id.
Available options:
EXPERIENCE,
TRIP,
AGENCY
reviewable_id
string<uuid>
required
rating
integer
required
Required range: 1 <= x <= 5
comment
string
required
author_name
string
required

Traveler display name as shown on the public Safariat site.

verified_booking
boolean
required

true when the review is tied to a confirmed Safariat booking.

helpful_count
integer
required
Required range: x >= 0
created_at
string<date-time>
required
title
string | null
author_avatar
string<uri> | null
photo_urls
string<uri>[] | null

Up to 10 traveler-uploaded photos.

agency_reply
string | null
agency_replied_at
string<date-time> | null