This takes one member from your system to a public verification page. Every request here is safe to repeat.
Make a key
An admin makes the key in Commercial, under Your integration. The API is part of the Creator and Studio plans. See Make a key. The key looks like
wik_followed by 64 hexadecimal characters, and it is shown once.Keep it in a server-side secret:
export WARDEN_KEY="wik_..."Rehearse one record
Add
?dry_run=1and Warden checks the key, reads the record the way a write would, and stores nothing.curl -sS "https://3dwarden.com/api/v1/integration/entitlements?dry_run=1" \ -H "Authorization: Bearer $WARDEN_KEY" \ -H "Content-Type: application/json" \ -d '{ "records": [{ "external_id": "member-1001", "status": "active", "normalized_state": "active", "capabilities": ["physical_sales"], "credential": { "holder_name": "Example Print Shop" }, "identities": [{ "source": "website", "url": "https://shop.example.com", "public": true }] }] }'{ "dry_run": true, "records": [{ "external_id": "member-1001", "would": "create", "normalized_state": "active", "capabilities": ["physical_sales"], "credential": true, "identities": [{ "position": 0, "source": "website", "handle": null, "assurance": "registered", "public": true, "identity": { "kind": "domain", "key": "shop.example.com" } }] }], "rejected": [] }wouldiscreatebecause this key's provider does not holdmember-1001yet.identityis what Warden read out of the shop address, and what it will compare that storefront on.Write it
Save the same body as
record.jsonand send it withoutdry_run.curl -sS "https://3dwarden.com/api/v1/integration/entitlements" \ -H "Authorization: Bearer $WARDEN_KEY" \ -H "Content-Type: application/json" \ -d @record.json{ "records": [{ "external_id": "member-1001", "public_id": "q3Zr8mW1x0aB4cD5eF6gHi", "normalized_state": "active", "capabilities": ["physical_sales"], "last_synced_at": "2026-09-21T18:04:11.123456+00:00", "retired": false, "verify_url": "https://3dwarden.com/verify/q3Zr8mW1x0aB4cD5eF6gHi" }], "rejected": [] }Store
public_idagainst your member. It is minted once and never changes while Warden holds the record, through lapses, reactivations and withdrawals.Open the public page
Open
verify_urlin a browser. It says two separate things: whether the certificate is genuine, and whether the membership is active now. See The verification page.
Next
Send records explains every field.
Keep it current explains how often to send, and what happens if you stop.
Errors lists the codes to branch on.