Platforms

Which review platforms actually connect by API, and which ones vendors quietly import

We wrote a guide telling you to ask vendors this question and then did not answer it about ourselves. Here is the answer.

Justin Ciappara

Co-founder, Revify11 min read

Review management tools list the same six or seven platform logos, and behind those logos sit four completely different things: an official API that can read and reply, an official API that can only read, a file the property uploads itself, and a browser robot driving the property’s own login. Only the first two are connections in any meaningful sense, and only the first lets a tool answer a review for you.

In an earlier guide we told readers to ask vendors exactly this, per platform, for reading and replying separately, and then did not answer it about ourselves. This is that answer.

Why the distinction matters to you

It looks like a technical detail and it is not. It determines three things you will notice within a month of buying.

  1. Whether the data is current. An API connection is as fresh as its last sync. A CSV import is as fresh as the last time somebody remembered to export a file, which in practice means it goes stale quietly and nobody notices until a complaint is three weeks old.
  2. Whether you can actually reply from one place. The entire promise of a unified inbox is that you answer everything in it. Where there is no reply API, the honest version is that the tool drafts and you paste, which is still useful and is not what “reply from one inbox” implies.
  3. Whose account carries the risk. If a tool holds your platform password and automates your session, the suspension lands on your listing, not on the vendor’s.

The four questions to ask any vendor

Ask these per platform, and insist on separate answers for reading and for replying, because the answers genuinely differ.

  • Is this an official API, and which one? A named API is checkable. “We integrate with them” is not.
  • How do I authorise it, OAuth or my password? If the answer involves your password, stop.
  • How fresh is the data, and what happens when it stops arriving? Ask whether you are told when a sync fails, or whether it just goes quiet.
  • What happens if the platform withdraws access?Platform terms change, programmes close to new partners, APIs sunset. Ask what the product does the day after.

Our own answers, platform by platform

This is the current state of Revify, as the product is configured today. It includes the rows that are not flattering, because a matrix with no awkward rows in it is not evidence of anything.

Revify platform connections: how reviews arrive and how replies are posted, as at September 2026
PlatformReading reviewsReplyingHow it connects
GoogleAutomatic syncPosted by RevifyBusiness Profile API, OAuth. The one fully closed loop
TripAdvisorAutomatic sync, recent reviews onlyDrafted by Revify, posted by youContent API with a location ID. There is no reply API to use
Booking.comCSV import you uploadDrafted by Revify, posted by youExtranet. API access is partner-only and we do not have it
ExpediaCSV import or incoming webhookDrafted by Revify, posted by youPartner Central
InstagramComments, automaticPosted by Revify once approvedMeta OAuth, pending Meta App Review
FacebookComments, automaticPosted by Revify once approvedMeta OAuth, pending Meta App Review

Four of those six rows are not the thing a marketing page would say. Taking them in turn:

TripAdvisor has no reply API. The Content API reads ratings, reviews and existing owner responses, and returns only the most recent handful per property. It cannot post. Any tool that claims to reply to TripAdvisor on your behalf is either automating your Management Centre login or describing a draft-and-paste flow in stronger words than it deserves. Ours is draft and paste, with a deep link. More in TripAdvisor review management.

Booking.com is CSV. A Guest Reviews API exists and it can post replies, but it is available only through the connectivity partner programme, which has not been open to us. Until that changes, a property exports its reviews and uploads the file, which means the data is exactly as fresh as the last upload and we would rather say so than let a logo imply otherwise.

Expedia arrives by file or webhook, and replies are written in Partner Central. See Expedia reviews.

Instagram and Facebook are built and waiting. The connection is real and the reply path is a genuine API, but the permissions that let an app read and reply to comments require Meta App Review, and ours is pending. Until it is approved those two rows describe something that works in our own testing and is not yet switched on for clients.

A tablet propped on a desk showing an indistinct arrangement of colour blocks.
Every integrations page is a cover plate. The question is what is behind it.

How to read a vendor’s integrations page

Some reliable tells, none of which require technical knowledge.

What the wording on an integrations page usually means
What it saysWhat it often means
“Connects with”, no detailRead-only, or an import. If it were an API with replies, they would say so
“Sync your reviews”Reading only. Note that replying is not mentioned
“Reply from one inbox” for every platform listedAlmost certainly not literally true. Ask which ones post via API
“We support 50+ platforms”Most are aggregated or imported. Ask about the four you actually use
Named APIs and scopesA good sign. Specific claims are checkable claims
Asks for your platform passwordWalk away

The single most revealing question is the narrow one: “can your product post a reply to a TripAdvisor review through an official API?” The answer is no, for everyone, because that API does not exist. It is a good test of whether you are being told how things work or how they are being sold.

The risk nobody puts on the pricing page

There are two ways to make a tool appear to do more than the platforms permit: store the property’s credentials and drive its logged-in session, or scrape public pages. Both are common, both breach the platforms’ terms, and in both cases the exposure sits with the property.

What is at stake is the listing itself: suspension, loss of owner access, and in the OTA case a commercial relationship with a contract behind it. A review tool is not worth that, and a vendor asking for your password is telling you which corner they have chosen to cut.

The sanctioned pattern is the one every major platform publishes: you authenticate on the platform’s own page, grant a scoped token, and revoke it whenever you like. Google documents its own version in the Business Profile API documentation. If a connection does not look like that, ask what it looks like instead.

For what this category of software is for in the first place, and what it can and cannot fix, see what hospitality review software actually does.

Common questions

Do review management tools really connect to every platform they list?

Rarely in the same way. A logo on an integrations page can mean an official API connection with reply capability, a read-only feed, a CSV import the property uploads itself, or a browser automation running on the property's own login. Those are very different products and the page usually does not distinguish them.

Which review platforms have an official API for posting replies?

Google's Business Profile API supports posting a reply to a review programmatically. Booking.com offers reply capability through its Guest Reviews API but only to accepted connectivity partners. TripAdvisor's Content API is read-only and does not post owner responses at all, so any tool replying there is doing it another way.

Is it safe for a review tool to log into my TripAdvisor or Booking.com account?

No. Handing over platform credentials so a tool can automate your logged-in session breaches those platforms' terms, and the account at risk is yours rather than the vendor's. The sanctioned pattern is OAuth, where you authenticate on the platform's own page and grant a scoped token that you can revoke.

What should you ask a review management vendor before buying?

Ask, per platform and separately for reading and for replying: is this an official API, does it use OAuth or my password, how fresh is the data, and what happens if the platform withdraws access. A vendor who cannot answer those four for each logo on their site is describing a roadmap rather than a product.

See your own reviews this way

Every platform in one inbox, the themes pulled out for you, and a reply drafted in your voice waiting for approval.

Start free for 14 days

14 days · No card required · Cancel anytime