Authentication

Keys, and what works without one.

Send your key in the Authorization header:

Authorization: Bearer dyme_live_YOUR_KEY

The same key works for the MCP server.

Without a key

You can call the API without a key, at 30 requests an hour per IP address. That works from a browser too, since responses carry Access-Control-Allow-Origin: *. Links in keyless responses don't carry an affiliate code, so nobody is credited for bookings from them. It's for trying things out.

Getting a key

Apply at dyme.earth/affiliates; approved affiliates can ask for an API key. Keys come at the standard tier (2,000 requests a day). If you need more, say so and we'll set you up on the partner tier (20,000 a day).

A key looks like dyme_live_ followed by 32 characters.

Keeping it safe

  • Keep the key on your server, in a secret or an environment variable.
  • Don't put it in client-side code, in a widget address, or in a public repository. Widgets don't take a key at all, only your affiliate code.
  • If a key leaks, email us and we'll issue a new one and revoke the old one.

If a key we don't recognise, or one that's been revoked, is sent, the request isn't refused. It's served as if there were no key: the keyless limit applies and links carry no affiliate code. The response header X-Dyme-Key-Status says why.

Errors

Errors are JSON with a code and a message:

{ "error": { "code": "rate_limited", "message": "…" } }
Status Code Meaning
400 invalid_params A required parameter is missing or wrong.
404 not_found No hotel or place matched.
429 rate_limited You're over the limit. See rate limits.