Your first API call, in a few minutes
Get a key, send one POST from your server, and read the response. No SDK needed.
Get a key
Keys are issued by the Dium team. There is no self-serve portal or sandbox yet. Ask for a key and tell us the actions you need. For this guide you only need the auth.issue_token scope.
Store the key as an environment variable on your server:
export DIUM_API_KEY="paste-your-key-here"Make your first call
This call asks Dium for a one-time sign-in token for one member. It is a good first call because it proves your key and scope work, and it changes nothing: the token simply expires after five minutes if you do not use it.
curl -sS https://dium.io/api/auth.php \
-H "Content-Type: application/json" \
-H "X-Api-Key: $DIUM_API_KEY" \
-d '{"action":"issue_token","email":"[email protected]","name":"Your Name"}'// Node 18+ (fetch is built in). Run on your server only.
const res = await fetch("https://dium.io/api/auth.php", {
method: "POST",
headers: {
"Content-Type": "application/json",
"X-Api-Key": process.env.DIUM_API_KEY,
},
body: JSON.stringify({ action: "issue_token", email: "[email protected]", name: "Your Name" }),
});
const data = await res.json();
console.log(res.status, data.success, data.expires_in); // 200 true 300# pip install requests
import os, requests
r = requests.post(
"https://dium.io/api/auth.php",
headers={"X-Api-Key": os.environ["DIUM_API_KEY"]},
json={"action": "issue_token", "email": "[email protected]", "name": "Your Name"},
timeout=10,
)
data = r.json()
print(r.status_code, data.get("success"), data.get("expires_in")) # 200 True 300<?php
$ch = curl_init('https://dium.io/api/auth.php');
curl_setopt_array($ch, [
CURLOPT_POST => true,
CURLOPT_RETURNTRANSFER => true,
CURLOPT_TIMEOUT => 10,
CURLOPT_HTTPHEADER => ['Content-Type: application/json', 'X-Api-Key: ' . getenv('DIUM_API_KEY')],
CURLOPT_POSTFIELDS => json_encode(['action' => 'issue_token', 'email' => '[email protected]', 'name' => 'Your Name']),
]);
$data = json_decode(curl_exec($ch), true);
echo curl_getinfo($ch, CURLINFO_HTTP_CODE), ' ', $data['expires_in'] ?? 'error', PHP_EOL; // 200 300Every Dium API call has the same shape: a POST to one PHP file, a JSON body, and an action field that picks what to do.
Check the response
A working call returns HTTP 200 with success, the token and its lifetime in seconds. Your token will differ.
HTTP/1.1 200 OK
Content-Type: application/json
{
"success": true,
"token": "9f2c4e1ab07d53e8c6f1a2b4d9e07c35a8b61f4e2d0c9a7b",
"expires_in": 300
}If something is wrong, you get an HTTP error status and an error message:
HTTP/1.1 401 Unauthorized
{ "error": "..." }| Status | Most likely cause | Fix |
|---|---|---|
400 | A required field is missing, such as email | Send every required field |
401 | No key, or the key is wrong | Check the X-Api-Key header and the value of DIUM_API_KEY |
403 | The key works but lacks the auth.issue_token scope | Ask us to add the scope |
Next steps
- Sign the member in. Redirect the browser to
https://dium.io/home/autologin.php?token=...&redirect=/asq/d/your-flow/waves. The SSO guide has full server code. - Create a Flow for an event. Call
ladder.phpcreatewith your ownexternal_idso retries do not make duplicates. See the API reference. - Add sessions and sponsor pages. Use
wave.phpcreateandexhibit.phpcreate. - Mount Dium on your site. Follow widgets and embeds.