DayzHUBDiscord

FeaturesPremium 1

Bot API

Show your server data on your own website

Create a secret token in your dashboard and your website or tools can read live facts about your server: the level leaderboard, running giveaways, ticket counts, your game server status and your shop products. It only reads. Nothing it does can change your server, and members who opted out always stay anonymous.

bot-api

🚫

No Discord message

The Bot API runs from your dashboard and your own website. Nothing is posted to Discord.

How it works

Up and running in minutes

  1. 01

    Create a token

    Dashboard, Management, Bot API: name it, tick what it may read, copy it. It is shown once.

  2. 02

    Keep it secret

    Store it on your own server like a password. Use one token per website or tool.

  3. 03

    Ask for your data

    Your website sends the token in an Authorization header and gets your data back as JSON.

  4. 04

    Revoke any time

    Press Revoke on the Bot API page and the token stops working at once.

What you can build

The Bot API lets your own website or tools read live facts about your Discord server. It only reads. Nothing you build with it can change your server or touch your members. Here are some ideas that people set up in an afternoon.

  • A leaderboard widgetShow your top 10 survivors by level on your community website.
  • A giveaway countdownPut the running giveaway, its prize and its end time on your homepage.
  • Ticket countsShow how many tickets are open and how fast your team answers, for a staff dashboard or a "we reply in about 10 minutes" banner.
  • A status badgeDisplay whether your game server is online and how many players are on it.
  • A shop product listList your Donation Shop products with prices on your own site and link straight to checkout.

No coding yourself? Send this page to the person who runs your website. They will know what to do with it.

Step by step: create your token

A token is a long secret password that lets one website or tool read your server. You make it in your dashboard.

  1. 01

    Open the Bot API page

    Log in at dayzhub.net, open your dashboard, pick your server, and choose Bot API in the Management section of the side menu. Only people with the Manage Server permission can see it. Team Access members cannot.

  2. 02

    Name it

    Type a short name that tells you what it is for, for example "Website leaderboard". Use one token per website or tool.

  3. 03

    Choose what it may read

    Tick the boxes for the data you need, such as giveaways or the level leaderboard. Fewer boxes is safer. You can always make another token later.

  4. 04

    Allowed website (only sometimes)

    Leave this empty unless a web page in your visitors' browsers will call the API directly. In that case type your site address exactly, like https://yoursite.com, with no path at the end.

  5. 05

    Press Create token and copy it

    A box appears with your token, which starts with dhba_. Press Copy and paste it somewhere safe right away. It is shown only once. If you lose it, you make a new one.

  6. 06

    Keep it secret

    Treat the token like a password. Do not post it in Discord, do not put it in a public GitHub project, and do not paste it into a web page that visitors can read. Keep it on your own server or in a password manager.

Your first request

Let us check that your token works. You need two things: the token you just copied, and your server ID (in Discord, turn on Developer Mode in your settings, then right-click your server and choose Copy Server ID). The first call below needs only the token.

Replace dhba_YOUR_TOKEN with your real token in every example. Each one sends the token in a header called Authorization. Putting it in the web address does not work.

Windows PowerShell (use curl.exe with the .exe, plain curl means something else in PowerShell)

curl.exe -H "Authorization: Bearer dhba_YOUR_TOKEN" https://dayzhub.net/api/v1/bot/me

curl (macOS, Linux and most hosting)

curl -H "Authorization: Bearer dhba_YOUR_TOKEN" https://dayzhub.net/api/v1/bot/me

JavaScript on your own server (Node 18 or newer). Keep the token in an environment variable.

const res = await fetch("https://dayzhub.net/api/v1/bot/guilds/YOUR_SERVER_ID/giveaways?status=active", {
  headers: { Authorization: "Bearer " + process.env.DAYZHUB_BOT_API_TOKEN }
});
const { ok, data } = await res.json();
console.log(data);

JavaScript in a visitor's browser (needs the Allowed website setting on the token, and shows the token to everyone, so use a token with the fewest boxes ticked)

fetch("https://dayzhub.net/api/v1/bot/guilds/YOUR_SERVER_ID/leaderboard/levels?limit=10", {
  headers: { Authorization: "Bearer dhba_YOUR_TOKEN" }
}).then(r => r.json()).then(j => console.log(j.data));

A page that runs in a visitor's browser can be read by that visitor, token included. Calling the API from your own server is the safe way. Browser calls are only for tokens that can read harmless public facts.

What comes back

Every answer is JSON. Successful answers have "ok": true and your data. Lists come with a "page" part: when "hasMore" is true, pass the "nextCursor" value back as ?cursor= to get the next page. Dates are in UTC.

GET /me: who the token belongs to

{
  "ok": true,
  "data": {
    "guildId": "123456789012345678",
    "name": "Website leaderboard",
    "prefix": "dhba_aB3dE",
    "scopes": ["leveling:read", "giveaways:read"],
    "allowedOrigin": null,
    "rateLimitPerMin": 60,
    "createdAt": "2026-10-01T12:00:00.000Z",
    "plan": "premium1",
    "limits": { "tokens": 2, "perMinute": 60 },
    "tokensUsed": 1
  }
}

GET /guilds/ID/leaderboard/levels?limit=2

{
  "ok": true,
  "data": [
    { "rank": 1, "member": { "id": "111111111111111111", "anonymous": false }, "xp": 18450, "level": 27 },
    { "rank": 2, "member": { "id": null, "anonymous": true }, "xp": 17020, "level": 26 }
  ],
  "page": { "limit": 2, "hasMore": true, "nextCursor": "eyJpZCI6IjY..." }
}

GET /guilds/ID/giveaways?status=active

{
  "ok": true,
  "data": [{
    "id": "6650f0c2a1b2c3d4e5f60718",
    "prize": "Premium VIP for 30 days",
    "status": "active",
    "type": "reaction",
    "winnerCount": 1,
    "entryCount": 86,
    "endsAt": "2026-10-08T18:00:00.000Z",
    "requirements": { "role": false, "verified": true, "minInvites": 0 },
    "host": { "id": "111111111111111111", "anonymous": false },
    "winners": []
  }],
  "page": { "limit": 25, "hasMore": false, "nextCursor": null }
}

GET /guilds/ID/tickets/summary

{
  "ok": true,
  "data": {
    "open": 4,
    "closed": 212,
    "total": 216,
    "last30Days": { "created": 38, "closed": 41, "averageRating": 4.7, "ratingCount": 29, "averageFirstResponseMinutes": 9.5 },
    "byCategory": [ { "category": "Support", "open": 3, "closed": 150 } ]
  }
}

GET /guilds/ID/shop/products

{
  "ok": true,
  "shop": { "name": "Survivor HQ Shop", "description": "Support the server", "slug": "survivor-hq", "url": "https://dayzhub.net/shop/survivor-hq" },
  "data": [{
    "id": "6650f0c2a1b2c3d4e5f60999", "name": "VIP Role", "slug": "vip-role", "description": "Priority queue and a gold name",
    "price": 9.99, "compareAtPrice": null, "currency": "EUR", "type": "subscription", "interval": "monthly",
    "thumbnailUrl": null, "featured": true, "inStock": true, "url": "https://dayzhub.net/shop/survivor-hq/vip-role"
  }],
  "page": { "limit": 25, "hasMore": false, "nextCursor": null }
}

GET /guilds/ID/server-status

{
  "ok": true,
  "data": {
    "listed": true,
    "servers": [{ "name": "Survivor HQ", "slug": "survivor-hq", "url": "https://dayzhub.net/s/survivor-hq", "online": true, "players": 42, "maxPlayers": 60, "address": "game.yourserver.gg:2302", "lastChangeAt": "2026-10-01T09:30:00.000Z" }]
  }
}

When something is wrong, for example a mixed-up server ID (HTTP 403)

{ "ok": false, "error": "guild_mismatch", "code": "guild_mismatch", "message": "This token belongs to another server", "requestId": "3f2b8c1e-5a7d-4e0b-9c64-1d2e3f4a5b6c" }

The full list of endpoints and every field is in the machine-readable description at /api/v1/bot/openapi.json. Every answer carries an X-Request-Id header, and errors repeat it as requestId. Quote it when you contact support.

Limits, plans and privacy

  • Read onlyThere are no buttons that change anything. Only GET requests are answered.
  • PlansYour server needs a paid plan or an active free trial. Giveaway data needs Premium 2. The shop list needs real paid access, because the free trial does not include the Donation Shop.
  • How many tokens you can havePremium 1 includes 2 active tokens, Premium 2 includes 5 and Premium 3 includes 10. A free trial or a sponsored server counts as Premium 1. Revoke the ones you no longer use to free a place. If your plan goes down, the tokens you already have keep working. You just cannot create new ones until you are under the limit.
  • Speed limitsEach token may make 60 requests per minute on Premium 1, 120 on Premium 2 and 300 on Premium 3, and one internet address 300 per minute. Past that you get a 429 answer with a Retry-After header telling you how many seconds to wait.
  • Polling kindlyAnswers include an ETag. Send it back in an If-None-Match header and, when nothing changed, you get a tiny 304 answer instead of the full data. Asking every 30 to 60 seconds is plenty, and most widgets can ask less often.
  • What is never sharedTicket transcripts and messages, applications and their answers, payments and orders, e-mail addresses, names and avatars, and the people who entered a giveaway. You only ever get counts, plus numeric Discord IDs where the feature already shows people publicly in Discord, such as a giveaway host or the level leaderboard.
  • Members who opted outAnyone who used /privacy optout always appears as anonymous (an id of null). Their rank and numbers still count, so totals add up.

Troubleshooting

What you seeWhy it happensHow to fix it
401 unauthorized or invalid_tokenThe token is missing, mistyped, cut short or has been revoked.Copy it again in full, including the dhba_ start, and send it as Authorization: Bearer TOKEN. If it was revoked, create a new one.
403 guild_mismatchThe server ID in the address is not the server the token belongs to.Call /me to see the right guildId and use that one.
403 missing_scopeThe token was not allowed to read this kind of data.Create a new token with the box ticked for it.
403 feature_not_in_planThat feature is not part of your server's plan, for example giveaways without Premium 2.Upgrade the plan, or leave that data out.
403 plan_requiredThe server has no paid plan and no active free trial.Start a plan in Billing. The API works again straight away.
403 origin_not_allowedA web page on another website tried to use the token.Set the exact website on the token as Allowed website (https://yoursite.com), or call from your own server instead.
The browser says CORS errorThe token has no Allowed website, so browsers are not allowed to call it.Create a token with your site in Allowed website, or move the call to your server.
404 shop_not_enabledYour Donation Shop is not switched on.Turn the shop on in your dashboard.
429 rate_limitedToo many requests in one minute.Wait the number of seconds in the Retry-After header, then ask less often. Use ETag and 304 answers.
PowerShell shows a strange error with curlIn PowerShell, curl is a different command.Type curl.exe instead of curl.
503 unavailableA short hiccup on our side. The API never sends half answers.Try again in a minute.

Revoke and rotate a token

Do this at once if a token was shared by mistake, posted publicly, or a person who knew it has left your team.

  1. 01

    Create the new token first

    On the Bot API page create a replacement with the same settings, and copy it.

  2. 02

    Switch your website or tool

    Put the new token wherever the old one was used and check that everything still works.

  3. 03

    Revoke the old one

    In the list of your tokens, press Revoke on the old one and confirm. It stops working immediately, and anything still using it gets a 401. Creating and revoking are written to your server audit log, never the token itself.

Questions people ask

Can the API change anything on my server?

No. It is read only, and there is no way to give a token more power than that.

I lost my token. Can you show it again?

No. We keep only a fingerprint of it, so it cannot be shown again. Revoke it and create a new one.

Can I use one token for several servers?

No. A token belongs to one server and can only read that one. Create tokens in each server's dashboard.

Do I need to know how to code?

To build a widget, yes, or ask the person who makes your website. The dashboard part takes two minutes.

Can I see who entered my giveaway through the API?

No. You get the number of entries and the winners as Discord IDs, never the list of entrants.

Why is a member shown as anonymous?

They opted out of data processing with /privacy optout. We respect that everywhere, including here.

Does the free trial work?

Yes, during an active trial you can create tokens and read the features the trial includes. The Donation Shop is not part of the trial.

Why can I not create another token?

Every plan has a limit: 2 active tokens on Premium 1, 5 on Premium 2 and 10 on Premium 3. Revoke a token you no longer use, or upgrade your plan. The Bot API page shows how many you have used.

What happens to my token if my plan ends?

It keeps existing but answers 403 plan_required until you have a plan or trial again. Nothing is deleted.

Live preview

See it in Discord

Exactly what Premium 3 unlocks — as it appears in your server.

Premium 3€6.99 / mo

bot-api

🚫

No Discord message

The Bot API runs from your dashboard and your own website. Nothing is posted to Discord.

  • Everything in Premium 2
  • Up to 10 active tokens per server
  • 300 requests per minute per token

Plans

What you get

Every tier includes what's listed. Upgrade anytime — your settings carry over.

Premium 1

€2.99/ mo

🎁 Premium 1 includes a 7-day free trial (the Donation Shop and Free Mods unlock when you subscribe)

  • Read-only access to your own server data
  • Up to 2 active tokens per server
  • Level leaderboard, tickets summary, suggestions summary, game server status
  • 60 requests per minute per token
  • Works during the free trial
Premium 2

€4.99/ mo

  • Everything in Premium 1
  • Up to 5 active tokens per server
  • 120 requests per minute per token
  • Giveaway data (running and ended giveaways)
Premium 3

€6.99/ mo

  • Everything in Premium 2
  • Up to 10 active tokens per server
  • 300 requests per minute per token

🔌 Bot API

Show your server data on your own website

Add DayZ Hub to your server on Premium 1, and upgrade when you're ready for more.

DayZ Hub

Cookie settings

Choose whether DayZ Hub may count your visits with our cookieless analytics. You can change this at any time.

Necessary cookiesNeeded for sign-in, security, your language and this choice.
Always active
Analytics — PlausibleCounts page visits without cookies or personal data, so we can improve DayZ Hub.