Download the PHP package retrochaos/trustpilot-authenticator without Composer
On this page you can find all versions of the php package retrochaos/trustpilot-authenticator. It is possible to download/install these versions without Composer. Possible dependencies are resolved automatically.
Download retrochaos/trustpilot-authenticator
More information about retrochaos/trustpilot-authenticator
Files in retrochaos/trustpilot-authenticator
Package trustpilot-authenticator
Short Description A PHP library for obtaining Trustpilot API access tokens
License MIT
Informations about the package trustpilot-authenticator
Trustpilot Authenticator
A PHP library for obtaining access tokens for the Trustpilot Business User OAuth API.
Originally developed and open-sourced by moneymaxim.
Fully modernised to:
- Use Symfony HTTP Client
- Support all current Trustpilot OAuth grant types
- Provide type-safe error handling
- Provide refresh & revoke support
Install
Install via Composer:
The package has no external dependencies other than Symfony’s HTTP client (automatically installed).
Supported OAuth Flows
This library supports all Trustpilot Business OAuth grant types:
| Flow | Method |
|---|---|
| Password (legacy, deprecated but still works for old apps) | requestPasswordAccessToken() |
| Client Credentials (server-to-server) | requestClientCredentialsAccessToken() |
| Authorization Code (interactive user login) | requestAuthorizationCodeAccessToken() |
| Refresh Token | refreshAccessToken() |
| Revoke Refresh Token | revokeRefreshToken() |
| Build Authorization URL | buildAuthorizationUrl() |
Usage
Create the authenticator
1. Password Grant (Deprecated by Trustpilot)
Useful only for older Trustpilot applications pre-February 2025.
The alias getAccessToken() still works for backwards compatibility.
2. Client Credentials Grant (Recommended)
Best for server-to-server integrations.
3. Authorization Code Grant (Interactive User Login)
Step 1 — Redirect the user to login
Step 2 — Exchange the returned code for a real access token
4. Refresh an Access Token
5. Revoke a Refresh Token
6. buildAuthorizationUrl()
buildAuthorizationUrl() constructs a Trustpilot-compatible login URL for the Authorization Code OAuth flow.
Signature
Parameters
| Parameter | Description |
|---|---|
clientId |
Your Trustpilot API key |
redirectUri |
URL that Trustpilot redirects the user back to |
state |
Optional anti-CSRF or session identifier |
scopes |
Optional list of OAuth scopes as an array of strings |
Example
Example output:
What you do with it
- Redirect the user to the URL
- Trustpilot handles login
- Trustpilot redirects them back to your app with
?code=... - Exchange that code using
requestAuthorizationCodeAccessToken()
Error Handling
All errors throw a single exception type:
AccessToken Object
Every method returns an AccessToken instance:
Tests
A full PHPUnit test harness is included and covers:
- Successful authentication flows
- Error codes (400/401/403/500)
- Network exceptions
- Refresh & revoke
- Authorization URL generation
Run tests with:
License
MIT License — feel free to use, modify, and contribute.