The API Report CardAPI Index
Grubhub

Grubhub API

Delivery marketplace with restaurant portal and partner Marketplace API · get.grubhub.com

Grubhub's developer portal documents a full Marketplace API with webhooks, but credentials arrive only after a partner form, kickoff call and pilot. Auth is a bespoke HMAC MAC header rather than OAuth, and there is no self-serve sandbox or SDK.

Last verified: September 2026Restaurants & Food ServiceNO MCP
API GRADE
D
VERIFIED SEP 2026

SCORECARD

ExistenceGOODdeveloper.grubhub.com hosts Marketplace, Connect and Reporting API references plus a public Postman collection.
AccessPOORPartners submit a Google form, wait for Grubhub review and a kickoff call; production keys follow a 15 to 20 store pilot.
CoverageGOODMenus, merchant data, schedules, orders, deliveries, onboarding and reporting, with order, menu and delivery webhooks.
AuthPOORCustom MAC header: HMAC-SHA256 over nonce, method, path, host, port and body hash with a Grubhub-issued secret and partner key.
Docs & DXPOORNo self-serve sandbox or SDK; preprod credentials come by Privnote after kickoff and signing help is a sample Python script.
StabilityMIXEDEndpoints sit under /pos/v1 with a release notes page; the merchant_status field is flagged as legacy for future removal.
MCPNONENo official or community MCP server found for this platform.
What you can do
Ingest menus and 86 items via /pos/v1 endpointsPartner credentials required
Receive order, delivery and menu status webhooksURL registered with Grubhub
Set stores online or offline in bulk100 merchants per request
Pull statements through the Reporting APIPartner access
What you can't
Sign up and get API keys from the portalGoogle form and review
Authenticate with OAuth or a plain bearer tokenMAC HMAC header only
Test in a sandbox without Grubhub involvementPreprod issued by Grubhub
Apply refunds or cancellations without CareChange requests routed to Care
MORE FROM THE REPORT CARD
Supergood turns hard-to-integrate enterprise software into clean REST APIs and MCP tools: stable endpoints, normalized JSON, managed auth.

Frequently asked questions

Grubhub scores D on Supergood's API Report Card. Grubhub's developer portal documents a full Marketplace API with webhooks, but credentials arrive only after a partner form, kickoff call and pilot. Auth is a bespoke HMAC MAC header rather than OAuth, and there is no self-serve sandbox or SDK.

Tried to integrate with Grubhub?
SOURCES
A small restaurant owner who chose the 15 percent commission tier found they were effectively paying about 35 percent of sales once delivery and service fees were added. apps.apple.com
An owner could not see how much the restaurant had earned in the merchant app and had to call Grubhub to find out. apps.apple.com
A G2 reviewer describes a loop of back-and-forth support tickets with staff unable to fix their issues. g2.com
Smaller operators report Grubhub's refund dispute flow is harder to find in the portal, slower to respond and with the least consistent account manager access of the three marketplaces. gotjelly.com
Reconciliation guides flag marketing premium charges appearing on orders outside enrolled campaigns and refund chargebacks for delivery issues outside the restaurant's control. deliverguard.io