> ## Documentation Index
> Fetch the complete documentation index at: https://api-docs.hrizn.io/llms.txt
> Use this file to discover all available pages before exploring further.

# Submit profile testimonial

> Anonymous testimonial for a Pro Brand profile share page

Stores a testimonial submitted by a visitor on a Pro Brand profile share page. Testimonials are saved as `pending` and appear only after the profile owner approves them.

**Authentication:** none. **Origin:** requests must originate from the Hrizn app. **Rate limit:** 5 per minute and 100 per day per client IP; additionally each profile accepts at most 10 testimonials per rolling 24 hours.

## Request body

<ParamField body="profileId" type="string" required>Pro Brand profile (user) id from the share page.</ParamField>
<ParamField body="customerName" type="string" required>Filtered for inappropriate content.</ParamField>
<ParamField body="customerText" type="string" required>Max 280 chars. Filtered for inappropriate content.</ParamField>
<ParamField body="rating" type="integer">1–5.</ParamField>

<ResponseExample>
  ```json 200 theme={"theme":{"light":"github-light","dark":"github-dark"}}
  {
    "success": true
  }
  ```

  ```json 404 theme={"theme":{"light":"github-light","dark":"github-dark"}}
  {
    "error": "Profile not found."
  }
  ```

  ```json 429 theme={"theme":{"light":"github-light","dark":"github-dark"}}
  {
    "error": "This profile has received the maximum number of reviews for today. Please try again tomorrow."
  }
  ```
</ResponseExample>


## OpenAPI

````yaml POST /share/testimonial
openapi: 3.1.0
info:
  title: Hrizn Public API
  version: 1.2.0
  description: >
    The Hrizn Public API allows partners to programmatically create content,
    manage inventory descriptions, and integrate with the Hrizn platform.


    All endpoints are prefixed with `/public` and require an API key passed via
    the `X-API-Key` header (except the health check).
  contact:
    email: support@hrizn.io
servers:
  - url: https://api.app.hrizn.io/v1/public
    description: Production
security:
  - apiKeyAuth: []
tags:
  - name: Analytics
    description: >-
      Warehoused Google Search Console and GA4 reads (Teams+ API access,
      analytics:read). URL Inspection is live only on pages/performance.
  - name: IdeaClouds
    description: Create and manage AI-powered keyword research
  - name: Content Intelligence
    description: AI-powered content gap analysis and recommendations
  - name: Content
    description: Generate content from IdeaClouds
  - name: Compliance
    description: Run OEM compliance checks on content
  - name: Content Tools
    description: Generate SEO metadata, schemas, and social snippets
  - name: Inventory
    description: Access vehicle data and AI descriptions
  - name: Images
    description: >-
      Media Library images. Read the library (images:read): list and fetch
      images with alt text, AI-written title/caption/description, the generating
      prompt, dimensions, article links, and social variant cuts. Generate
      (images:write): async AI image generation returning an image_id;
      completion is delivered via image.generation.completed /
      image.generation.failed webhooks.
  - name: Market
    description: >-
      Live local market listings, days supply, competitive set, and pricing
      insights (Unlimited plan + market_data:read)
  - name: Site
    description: View dealership details and configuration
  - name: Webhooks
    description: Manage webhook subscriptions for real-time events
  - name: Reference
    description: Look up available types, scopes, and events
  - name: Social
    description: >-
      Social Hub posting and reviews across all connected platforms (X,
      Facebook, Instagram, LinkedIn, Google Business Profile)
  - name: Health
    description: Health check (no authentication)
  - name: Share
    description: >-
      Anonymous share-page routes (no API key). Called by Hrizn share pages
      (/s/{publicId}) on behalf of shoppers who are not signed in. Requests must
      originate from the Hrizn app origin (CORS is origin-checked, never
      wildcard) and are rate limited per client IP. Responses use a flat `{
      error }` / `{ success }` body, not the `{ error: { code, message } }`
      envelope of API-key routes.
paths:
  /share/testimonial:
    post:
      tags:
        - Share
      summary: Submit a profile testimonial
      description: >-
        Submits an anonymous testimonial for a Pro Brand profile from its share
        page. Stored as pending until the profile owner approves it. Each
        profile accepts at most 10 testimonials per rolling 24 hours (429). Rate
        limit: 5 per minute and 100 per day per client IP. Origin must be the
        Hrizn app.
      operationId: submitShareTestimonial
      requestBody:
        required: true
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/ShareTestimonialRequest'
      responses:
        '200':
          description: Testimonial stored as pending
          content:
            application/json:
              schema:
                type: object
                properties:
                  success:
                    type: boolean
                    example: true
        '400':
          $ref: '#/components/responses/ShareError'
        '404':
          $ref: '#/components/responses/ShareError'
        '429':
          $ref: '#/components/responses/ShareRateLimited'
        '500':
          $ref: '#/components/responses/ShareError'
      security: []
components:
  schemas:
    ShareTestimonialRequest:
      type: object
      required:
        - profileId
        - customerName
        - customerText
      properties:
        profileId:
          type: string
          format: uuid
          description: Pro Brand profile (user) id from the share page
        customerName:
          type: string
          minLength: 1
        customerText:
          type: string
          minLength: 1
          maxLength: 280
        rating:
          type: integer
          nullable: true
          minimum: 1
          maximum: 5
    ShareErrorBody:
      type: object
      required:
        - error
      properties:
        error:
          type: string
          example: Invalid lead submission.
  responses:
    ShareError:
      description: Share-route error (flat body, not the API-key envelope)
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/ShareErrorBody'
    ShareRateLimited:
      description: Per-IP rate limit or per-profile daily cap reached
      headers:
        Retry-After:
          description: Seconds until the window resets
          schema:
            type: integer
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/ShareErrorBody'
  securitySchemes:
    apiKeyAuth:
      type: apiKey
      in: header
      name: X-API-Key
      description: Your Hrizn API key (prefix hzk_)

````