Connect Trustpilot to ChatGPT: Automate Review Management & Replies
Learn how to build a Trustpilot MCP server to connect ChatGPT to your reviews. Automate replies, tag negative feedback, and send review invites.
If you want to connect Trustpilot to ChatGPT so your AI agents can read reviews, draft automated replies, tag negative feedback, and trigger review invitations, you need a Model Context Protocol (MCP) server. This server acts as the translation layer between ChatGPT's JSON-RPC tool calls and Trustpilot's REST APIs.
You can either build and maintain this infrastructure yourself - handling OAuth refresh tokens, schema mapping, and rate limits - or use a managed integration platform like Truto to dynamically generate a secure, authenticated MCP server URL.
If your team uses Claude, check out our guide on connecting Trustpilot to Claude or explore our broader architectural overview on connecting Trustpilot to AI Agents.
Giving a Large Language Model (LLM) read and write access to a reputation management platform is a massive engineering challenge. Trustpilot's API surface is highly specific, requiring chained requests to resolve business unit IDs before any meaningful actions can occur.
This guide breaks down exactly how to use Truto to generate a secure, managed MCP server for Trustpilot, connect it natively to ChatGPT, and execute complex review management workflows using natural language.
Stop writing boilerplate API integration code. Let Truto generate secure, managed MCP servers for your AI agents in seconds. :::
The Engineering Reality of the Trustpilot API
A custom MCP server is a self-hosted integration layer. While the open MCP standard provides a predictable way for models to discover tools, implementing it against Trustpilot's specific API quirks is exceptionally painful.
If you decide to build a custom MCP server for Trustpilot, you own the entire API lifecycle. Here are the specific integration challenges that break standard CRUD assumptions when working with Trustpilot:
The Business Unit ID Bottleneck
Unlike generic SaaS platforms where you can simply hit /api/reviews to get all account data, Trustpilot silos almost all operations under a specific business_unit_id (a proprietary GUID). A user prompt like "Get me the latest 1-star reviews for my company" is fundamentally impossible to execute in a single API call. Your MCP server must first expose a tool to search for the domain (e.g., truto.one), parse the response to extract the business_unit_id, and then feed that GUID into the actual review listing endpoint. If you don't explicitly document this dependency in your MCP tool schemas, the LLM will hallucinate invalid IDs and fail.
Public vs. Private Review Endpoints
Trustpilot strictly bifurcates its review data. The standard public endpoints return scrubbed data - you get the star rating and the review text, but absolutely no Personally Identifiable Information (PII). If you want an AI agent to cross-reference a reviewer with your internal CRM, you cannot use the public endpoint. You must implement the private review endpoints (/v1/private/business-units/{id}/reviews), which require completely different OAuth scopes and provide access to the customer's email address and internal reference ID. These private endpoints also carry hard caps (e.g., maximum 100,000 records), requiring aggressive pagination logic.
Separated Service vs. Product Schemas
Trustpilot treats "Service Reviews" (reviews of the company) and "Product Reviews" (reviews of specific SKUs) as completely isolated domains. They do not share endpoints. If an LLM needs to send a review invitation, your MCP server must distinguish between a Service Review Invite and a Product Review Invite, as the payload schemas differ drastically (Product Invites require nested arrays of productIds or skus). Mapping these two disparate systems into a unified set of AI tools requires heavy lifting on the schema definitions.
Step-by-Step: Connecting Trustpilot to ChatGPT via Truto
To bypass these architectural hurdles, we will use Truto's SuperAI. Truto dynamically derives MCP tools directly from Trustpilot's API documentation, maintaining the complex schemas and executing requests through its proxy infrastructure.
Here is how to set up the connection.
Step 1: Connect your Trustpilot Account
First, you need to establish an authenticated connection to Trustpilot. Truto handles the OAuth 2.0 handshake and securely manages the token lifecycle.
- In your Truto dashboard, navigate to Integrated Accounts -> New Integrated Account.
- Select Trustpilot from the catalog.
- Complete the Trustpilot OAuth consent flow.
- Once connected, note your
integrated_account_id. Truto will now automatically refresh access tokens in the background before they expire.
Step 2: Generate the Trustpilot MCP Server
Next, you need to generate a scoped MCP server for this specific Trustpilot connection. You can do this via the Truto UI or programmatically via the API.
Method A: Via the Truto UI
- Navigate to the integrated account page for your new Trustpilot connection.
- Click the MCP Servers tab.
- Click Create MCP Server.
- Give it a name (e.g., "ChatGPT Trustpilot Server").
- Select your desired configuration (e.g., allow specific methods like
readandwrite, or filter by tags likereviews). - Click Create and copy the generated MCP server URL.
Method B: Via the API You can programmatically generate the server by sending a POST request to Truto. This is useful for dynamically provisioning agents for your end-users.
curl -X POST https://api.truto.one/integrated-account/<INTEGRATED_ACCOUNT_ID>/mcp \
-H "Authorization: Bearer $TRUTO_API_TOKEN" \
-H "Content-Type: application/json" \
-d '{
"name": "Trustpilot Management for ChatGPT",
"config": {
"methods": ["read", "write", "custom"],
"tags": ["reviews", "business_units", "replies"]
}
}'The response will contain the secure endpoint URL:
{
"id": "mcp-8a7b6c5d",
"name": "Trustpilot Management for ChatGPT",
"config": { "methods": ["read", "write", "custom"] },
"expires_at": null,
"url": "https://api.truto.one/mcp/e9f8g7h6i5j4..."
}Treat this URL as a secret. It encodes both the routing information for the Trustpilot instance and the cryptographic authentication required to execute tools.
Step 3: Connect the MCP Server to ChatGPT
Now, you must register this endpoint with ChatGPT so it can discover and call the Trustpilot tools.
Method A: Via the ChatGPT UI
- Open ChatGPT (requires a Pro, Plus, Business, Enterprise, or Education account).
- Navigate to Settings -> Apps -> Advanced settings.
- Toggle on Developer mode.
- Under MCP servers / Custom connectors, click Add new.
- Name the connector "Trustpilot (Truto)".
- Paste the Truto MCP
urlyou copied in Step 2 into the Server URL field. - Save the configuration. ChatGPT will immediately perform a handshake, call the
tools/listprotocol method, and populate the model's context with the Trustpilot capabilities.
Method B: Via Manual Config File (SSE Transport)
If you are running a local agent orchestration framework or using an MCP CLI testing tool, you can connect via Server-Sent Events (SSE). Create a chatgpt-config.json file (or standard MCP config file) pointing to the Truto URL:
{
"mcpServers": {
"trustpilot_truto": {
"command": "npx",
"args": [
"-y",
"@modelcontextprotocol/server-sse",
"--url",
"https://api.truto.one/mcp/e9f8g7h6i5j4..."
]
}
}
}Trustpilot MCP Hero Tools
Truto dynamically translates Trustpilot's OpenAPI specs and documentation into LLM-friendly schemas. Here are the most powerful tools available to your agent.
Find Business Unit by Domain
Tool name: trustpilot_business_units_find
As mentioned, almost all Trustpilot operations require a business_unit_id. This tool allows the LLM to dynamically look up the required GUID by passing a recognizable domain name.
"I need to manage reviews for truto.one. Find the business unit ID for this domain so we can use it in our next steps."
List Private Reviews (CRM Enrichment)
Tool name: trustpilot_business_units_list_private_reviews
This tool pulls the restricted private reviews for a business unit. It returns the reviewer's email address and reference ID (order number), allowing the AI to cross-reference the review with internal systems like Salesforce or Stripe.
"Fetch the latest 50 private reviews for our business unit. For any review under 3 stars, extract the customer's email and order reference ID so we can look them up in our CRM."
Reply to Service Reviews
Tool name: create_a_trustpilot_review_reply
Enables the AI to draft and post public replies to service reviews on behalf of a business user. It requires the review_id and the text content of the reply.
"Draft a professional, empathetic response to review ID 998877, apologizing for the shipping delay. Post the reply directly to Trustpilot."
Tag and Route Reviews
Tool name: trustpilot_review_tags_add
Allows the LLM to programmatically apply tags to a service review based on sentiment analysis. These tags are visible in Trustpilot Business and can trigger downstream webhooks or analytics.
"Analyze the sentiment of this review. Since the customer mentions a 'billing error', apply the tag 'finance-escalation' using the generic tag group."
Send Product Review Invitations
Tool name: trustpilot_product_reviews_create_invitation_link
Generates a unique product review invitation link for specific SKUs that can be emailed to consumers. The AI can format the payload with customer details and the specific product identifiers.
"Generate a product review invitation link for customer alice@example.com who just purchased SKU 'PROD-2024'. Provide me with the URL so I can include it in her receipt email."
Get Specific Private Product Review
Tool name: get_single_trustpilot_private_product_review_by_id
Retrieves the deep metadata for a specific product review, including private details, compliance labels, and exact timestamp logs.
"Pull the full private metadata for product review ID 554433 so I can see if the customer attached any images of the defective item."
To view the complete inventory of available Trustpilot tools, query schemas, and response formats, visit the Trustpilot integration page.
Workflows in Action
MCP tools become powerful when an agent chains them together to accomplish domain-specific tasks without human intervention. Here are two real-world workflows.
Workflow 1: Triage and Tag Negative Reviews
Customer Success teams spend hours reading reviews, finding the customer in their database, and routing the issue. ChatGPT can automate this triage pipeline.
"Find the business unit ID for acmecorp.com. Then, fetch the latest private reviews. For any review that is 1 or 2 stars, tag the review as 'churn-risk' and draft a polite reply asking them to confirm their order ID."
Execution Steps:
- Lookup BU: ChatGPT calls
trustpilot_business_units_findwithname: "acmecorp.com"and receives theid(e.g.,4a5b6c). - Fetch Private Data: It calls
trustpilot_business_units_list_private_reviewsusingbusiness_unit_id: "4a5b6c". - Analyze & Tag: The LLM evaluates the payload, identifies low ratings, and iteratively calls
trustpilot_review_tags_addwithtags: [{value: "churn-risk"}]. - Reply: It calls
create_a_trustpilot_review_replywith a contextual, drafted response.
sequenceDiagram
participant User as User
participant ChatGPT as ChatGPT
participant TrutoMCP as Truto MCP Router
participant Trustpilot as Trustpilot API
User->>ChatGPT: "Find recent 1-star reviews for acmecorp.com<br>and tag them 'churn-risk'"
ChatGPT->>TrutoMCP: Call "trustpilot_business_units_find"
TrutoMCP->>Trustpilot: GET /v1/business-units/find?name=acmecorp.com
Trustpilot-->>TrutoMCP: Return "business_unit_id"
TrutoMCP-->>ChatGPT: Tool Result (ID: 4a5b6c)
ChatGPT->>TrutoMCP: Call "trustpilot_business_units_list_private_reviews"
TrutoMCP->>Trustpilot: GET /v1/private/business-units/4a5b6c/reviews
Trustpilot-->>TrutoMCP: Return Review List
TrutoMCP-->>ChatGPT: Tool Result (Array of reviews)
ChatGPT->>TrutoMCP: Call "trustpilot_review_tags_add"
TrutoMCP->>Trustpilot: POST /v1/private/reviews/{id}/tags
Trustpilot-->>TrutoMCP: HTTP 200 OK
TrutoMCP-->>ChatGPT: Tool Result (Success)
ChatGPT-->>User: "Tagged 4 negative reviews as churn-risk."Workflow 2: Post-Purchase Review Generation
Marketing Operations teams want to automate review acquisition for new product lines without writing custom API polling scripts.
"We just launched SKU 'ALPHA-99'. Generate a Trustpilot product review invitation link for this SKU targeting customer bob@example.com, and return the exact URL."
Execution Steps:
- Lookup BU: ChatGPT calls
trustpilot_business_units_findto establish context. - Generate Invite: It calls
trustpilot_product_reviews_create_invitation_link, mappingbob@example.comto the consumer email field andALPHA-99to the product SKU array. - Return URL: The tool returns the
reviewUrlpayload, which the LLM outputs to the user.
Security and Access Control
Giving an AI agent access to public reputation and private customer data is dangerous. Truto's MCP architecture enforces strict constraints at the infrastructure layer, preventing prompt injection attacks from executing destructive API calls.
- Method Filtering: When creating the server via
POST /integrated-account/:id/mcp, setconfig.methods: ["read"]to entirely strip out create, update, and delete tools. The LLM simply won't know those endpoints exist. - Tag Filtering: Restrict access to specific functional areas using
config.tags: ["reviews"]. This prevents the agent from tampering with business unit settings or user directories. - Require API Token Auth: By default, possession of the MCP URL grants access. By setting
require_api_token_auth: true, you force the client (or developer) to also pass a valid Truto API bearer token in the headers, adding a secondary authentication factor. - Ephemeral Servers: Set an
expires_atISO datetime when generating the server. Truto's background cleanup alarms will automatically invalidate the URL and destroy the backend KV records once the TTL is reached, preventing stale endpoints from lingering.
Handling Trustpilot Rate Limits in Production
Trustpilot enforces strict rate limits, particularly on token refresh endpoints and high-volume data retrieval.
When connecting ChatGPT to Trustpilot via Truto, it is critical to understand that Truto does not retry, throttle, or apply backoff on rate limit errors. If your LLM attempts to fetch 100 pages of reviews concurrently and trips the limit, Trustpilot will return an HTTP 429 Too Many Requests error. Truto passes this 429 error directly back to the caller (ChatGPT).
However, Truto does normalize the upstream rate limit information. Regardless of how Trustpilot specifically formats its headers, Truto extracts the limits and injects standardized IETF rate limit headers into the response:
ratelimit-limitratelimit-remainingratelimit-reset
The caller (the AI agent framework or the end-user prompting ChatGPT) is responsible for reading these headers, waiting for the reset window, and retrying the failed tool call.
Stop managing OAuth tokens, reading OpenAPI specs, and writing custom mapping layers for every integration. Let Truto generate secure, AI-ready tools for your applications instantly.
FAQ
- How do I find a Trustpilot Business Unit ID dynamically?
- You can use the trustpilot_business_units_find endpoint. Pass the domain name as the query parameter, and it will return the corresponding business_unit_id required for subsequent API calls.
- Can ChatGPT read private customer details from Trustpilot reviews?
- Yes, provided your MCP server exposes the trustpilot_business_units_list_private_reviews tool. Unlike the public reviews endpoint, this returns private details like the customer's email and reference order ID.
- Does Truto automatically retry Trustpilot API rate limit errors?
- No. Truto passes HTTP 429 errors directly to the caller. It normalizes the upstream rate limit information into standard IETF headers (ratelimit-limit, ratelimit-remaining, ratelimit-reset), leaving the backoff logic up to your AI agent or client application.
- How do I prevent ChatGPT from accidentally deleting Trustpilot reviews?
- When creating your Truto MCP server, you can pass a configuration object with specific method filters (e.g., methods: ["read", "update"]). This ensures the MCP server drops any delete or create requests before they reach the upstream API.