BPOM
Government · 1 endpoint
Search the national food and drug register by product name, offers a consumer, across food, drugs, cosmetics, and traditional medicine.
Base URL
Endpoint
Snippet
Request — cURL
v1
curl https://api.diraz.ae/v1/bpom/products \
-H "Authorization: Bearer drz_live_…"Query parameters
- qstring · required
- Product name to search for. At least two characters.
- categorystring · optional
- Which register class to search: `food` (processed food), `drug`, `cosmetic`, or `traditional` (herbal and jamu).Default: food
- pageinteger · optional
- 1 to 500.Default: 1
- page_sizeinteger · optional
- Records per page, 1 to 50.Default: 20
- max_ageinteger (seconds) · optional
- Ask for data no older than this. Clamped to the product's own floor, so it can narrow the window but never force a refresh on every call.Default: 300
Example response
200 OK
v1
{
"data": {
"query": "indomie",
"category": "food",
"page": 1,
"page_size": 20,
"total_items": 1405,
"total_pages": 71,
"results": [
{
"registration_number": "MD 242811002100462",
"name": "Es Krim Rasa Mi Ayam Bawang (Indomie Ayam Bawang)",
"brand": "CHOC ROCKS",
"package": "Kertas Laminat (100 ml, 110 ml)",
"status": "Berlaku",
"registrar": "PT Cita Rasa Prima",
"registrar_npwp": null,
"manufacturer": "PT Cita Rasa Prima",
"importer": null,
"submitted_at": "2024-01-19",
"registered_at": "2024-02-27",
"expires_at": "2027-02-26",
"halal_certificate_id": null
}
]
},
"meta": {
"request_id": "req_7Q2fK4mZ",
"as_of": "2026-08-22T01:05:00.000Z",
"age_seconds": 12,
"next_update_at": "2026-08-22T01:20:00.000Z"
}
}- query / category
- The search term and register class, echoed back.
- page / page_size / total_items / total_pages
- Pagination over the register's own result count.
- results[].registration_number
- The registration number as printed, e.g. `MD 242811002100462`.
- results[].name / brand
- The registered product name and brand. `null` where the register states none.
- results[].package
- Packaging description, in the register's own wording.
- results[].status
- Register status — `Berlaku` means currently valid.
- results[].registrar / registrar_npwp
- The certificate holder and its tax ID, where stated.
- results[].manufacturer / importer
- Who makes it and, for imports, who brings it in.
- results[].submitted_at / registered_at / expires_at
- `YYYY-MM-DD` milestones from the register.
- results[].halal_certificate_id
- Cross-reference into the halal register, when the record carries one.
Errors
401 Unauthorized
v1
{
"error": {
"code": "UNAUTHORIZED",
"message": "The API key is invalid, expired, or revoked."
},
"meta": {
"request_id": "req_7Q2fK4mZ"
}
}Every failure carries a stable machine-readable code before the human message, and the same meta.request_id the successful responses carry. Quote it and we can find your exact request.
Errors are free
Nothing on this page is billed. You are charged for a 2xx and nothing else — a rejected key, a bad parameter, a rate limit, or an outage on our side all cost you zero. Retry without watching the meter.
- UNAUTHORIZEDHTTP 401
- Missing, malformed, expired, or revoked API key.
- FORBIDDENHTTP 403
- The key is valid but lacks the scope this product needs.
- VALIDATION_ERRORHTTP 422
- A query parameter is the wrong type or out of range.
- RATE_LIMITEDHTTP 429
- Rate limit exhausted. `Retry-After` says how long to wait.
- SERVICE_UNAVAILABLEHTTP 503
- No data recent enough to serve. Carries `Retry-After`, and is never billed.
- Status
- Operational
- Category
- Government
- Scope
- data:read
- Rate limit
- 60 requests / 60s per key
- Pricing
- 1 credit / request
- BPOM
1/1 passing
Every response is timestamped. as_of is when the data was published, age_seconds how old that is now, and next_update_at when newer data is expected.
Three shapes to handle:
- Up to date200
The data is inside its published window. The overwhelming majority of requests.
- Delayeddelayed: true
Newer data is late. You still get the most recent there is, flagged so you can decide whether to use it.
- Unavailable503
Nothing recent enough to serve. Carries Retry-After, and is never billed.