mesej

Getting access to the Business Profile API, and the 60-day rule

The Business Profile APIs are not public. Google requires a profile verified and active for 60+ days plus a website on it, says requests are reviewed within 14 days, and grants all seven APIs at once.

The Business Profile APIs are not public and there is no switch to turn them on. You apply, Google reviews the application, and the requirement that sets your timeline is the one you cannot start today: the prerequisites ask you to “Manage a Google Business Profile that is verified and active for 60+ days”, and the FAQ says “Requests are reviewed within 14 days.”

The FAQ is blunt about the gate, “GBP APIs aren’t open to the public.”, and broad about who clears it: “Any individual or company who can demonstrate legal business reason to access GBP APIs are approved for access.”

The requirements, verbatim

In order to get access to GBP APIs, we require all applicants: Manage a Google Business Profile that is verified and active for 60+ days. This GBP can be the applicant’s own office or headquarters or it could belong to one of the clients they manage. Have a website representing the business listed on the GBP.

Two items. The sentence after them is advice, not a rule: “For a smooth and timely review of your application, we recommend that the Google Business Profile is fully complete and kept up-to-date with the current business information, including the business’s official website.” Note what is absent: no revenue floor, no company size, no incorporation paperwork, no fee.

Five steps on one page, four on another

The prerequisites list the work as “Get a Google Account. Try out Business Profile. Create a project in the Google Cloud Console. Create an Organization account. Request access to the API.” The FAQ answers the same question with one step missing: “Get a Google Account. Try out Business Profile. Create a project in the Google Cloud console. Request access to the API: Requests are reviewed within 14 days.”

The dropped step is the Organization account, which the prerequisites explain in one line: “To create an Organization account, go to the GBP help center.” So two of Google’s pages disagree about whether an owner applying for one business needs one. We have not applied without one and we are not going to assert an answer.

Submission is a form, and two details decide whether it lands:

Find your Project Number in the Project info card on your project’s Dashboard. You will need to provide this number in your application. When you are ready, submit your request using our GBP API contact form. Select ‘Application for Basic API Access’ from the drop-down menu and provide all requested information.

Plus one detail easy to get wrong: “Make sure that you are using an email address that is listed as an owner/manager on your business’s GBP.”

Approval arrives as a number on the quota page

Google promises a follow-up email after review, and documents a way not to wait for it: “You can also check if your project has been approved by viewing the quotas for the Business Profile APIs in the Google Cloud Console.”

If your quota is 0 QPM (Queries Per Minute), your project has not yet been approved. If your quota is set to 300 QPM, your project is approved.

Rejection gets one sentence: “If your application is rejected, make sure you have met the requirements stated earlier before re-applying.” No reason code, no appeal, no stated wait before trying again. Thinner than what a rejected review reply gets, which at least has a published list of rejection reasons.

What you get is all of it

“There are seven APIs associated with Business Profile that must be enabled in the Google Cloud console:” appears on both the FAQ and the basic setup page. Under that identical sentence the lists differ: basic setup names seven, the FAQ names eight by adding the Business Profile Performance API. The count is ours; Google prints seven in both places.

You cannot be approved for just the one you want: “If a user’s application to request access is approved, they are granted with a standard default quota for all seven APIs.”

Reviews is not one of the seven. The FAQ nests it inside the Google My Business API entry, next to FoodMenus, Media and LocalPosts, and describes it in the capability table:

API What Google says it does
Reviews API “Allows merchants to get reviews and reply to reviews on a business profile.”
Business Profile Performance API “Allows merchants to fetch performance insights about their business listing on Google.”

What that second one no longer returns is part of what a Business Profile stopped being in 2024. Access attaches to the project, not to you, “GBP API access is granted on a Google Cloud project level.”, and it buys calls, not data: “Even if you get access to GBP APIs, you can’t query a Google Business Profile data unless you have access to that particular Google Business Profile.”

Quota

The only non-zero quota figure the prerequisites publish is the 300 QPM that signals approval. For real limits the FAQ points elsewhere: “The standard quota limits are listed in the Usage limits.” We did not read that page, so we are not repeating a number from it.

Increases are conditional: “If your average quota usage is less than 70% of your current quota limits, you might be denied any further increase in your quota limits.”

The client-listing question, and where our own note was wrong

Our own research file recorded applying through a client’s listing as a documented rejection path. Rereading the page, that is not what Google publishes: the prerequisites allow the profile to “belong to one of the clients they manage” in as many words, and we are not going to assert our note over Google’s sentence.

What the pages support is narrower, and worth planning around. The application email must be an owner or manager on the profile you name, the FAQ recommends an address tied to your own business domain, and the profile needs a website representing that business. On somebody else’s listing those three point at different entities, and neither page says which wins.

There is nowhere to rehearse either: “There’s no Sandbox environment for the Business Profile APIs.”

Unfortunately, there’s no direct way to create a fake GBP listing in prod either through GBP UI or API and test against it. Most of the fake listings that are created get flagged by our moderation and suspended.

The Reviews API is not on the deprecation schedule

Google does retire these APIs, and publishes the terms: “Discontinuation indicates that the version of the API will always return errors and will soon be shut down.” The most recent row is the My Business Q&A API, support ended 2025-09-15 and discontinued 2025-11-03. On the whole page the string Reviews API occurs once, in the banner about policy violations now being readable, and in none of the rows. That is not a promise, but as of the day we read it nothing in the reply path has a shutdown date.

Who this shuts out

Stack the two clocks: 60+ days of verified activity, then up to 14 days of review, so up to 74 days before a business starting today can read anything through this API.

That is why a business without an approved project cannot see why its own review reply was refused. The moderation state and the rejection reason are both published and machine-readable, and both sit behind this gate. Among the reasons it withholds are a suspension on the profile itself and an editing restriction that produces no error message. A tool with its own approved project is one way past it, part of what you are comparing in review management software; the other is the dashboard, where you write replies to negative reviews without ever learning which of them Google declined.

The short version

Two requirements, five steps, one form, up to 14 days. The 60 days of verified activity is the part you cannot compress, so start that clock early, on a profile you own and have verified, with a website on it, from an email listed as an owner or manager of it.

Sources