Download the PHP package flagdash/sdk without Composer
On this page you can find all versions of the php package flagdash/sdk. It is possible to download/install these versions without Composer. Possible dependencies are resolved automatically.
Informations about the package sdk
FlagDash PHP SDK
Feature flags, remote config, AI configs, translations and experiments for PHP 8.1+.
Dependency-free: the default transport uses PHP streams, so there is nothing to install beyond the package itself.
Installation
To install straight from GitHub, add https://github.com/flagdash/flagdash-php
as a Composer VCS repository and require the immutable tag v0.1.0.
Quick start
API key tiers
The key decides which project and environment you read, and what you may reach.
There is no environment parameter anywhere in this SDK — the key carries it.
| Key | Prefix | Reaches |
|---|---|---|
| Client | pk_ |
Flag values and configs. Safe in a browser or mobile app. |
| Server | sk_ |
Everything the client key reaches, plus targeting rules, translations and experiments. Keep it on your server. |
Anything below marked server key returns nothing useful with a client key.
Configuration
region is detected from FLY_REGION, AWS_REGION and friends when you leave
it out, so region-scoped targeting rules work with no wiring. transport takes
any FlagDash\Transport, which is where a PSR-18 client or a test double goes.
Feature flags
Pass a user_id (or key) in the context whenever you want a stable
answer. Percentage rollouts and A/B variations hash that identifier, so an
anonymous context re-rolls on every call by design.
Context is a plain array. Any attribute you send can be targeted on:
Remote config
AI configs
Prompts, agents, skills and rules, versioned per environment and editable without a deploy.
Translations (server key)
The key is namespace.message. {placeholders} are filled from the variables
array, and the default is returned whenever the catalogue, the namespace or the
message is missing — a translation lookup never throws.
Experiments (server key)
experiment() returns null for a context with no identifier — an assignment
that cannot be stable is worse than no assignment.
Metrics are buffered in memory (up to 1000) and sent by flush(), which
close() calls for you:
In a long-running worker, call flush() periodically. In a request/response
process, close() at the end of the request is enough.
Caching
Responses are cached in memory for cacheTtl seconds (60 by default), so a
burst of flag() calls costs one request. clearCache() empties it.
Failure behaviour
Every read returns the default you passed rather than throwing, so an outage
degrades to your fallback values instead of an exception in a request path.
FlagDash\FlagDashException surfaces only for programming errors such as an
empty SDK key.
Security
Keep the server key on the server. A key granted only the scopes it needs limits the blast radius if it leaks, and a client key never returns targeting rules — the browser cannot see who else you are targeting.
License
MIT
Backend session replay
The recorder captures only events you add. It redacts sensitive attribute keys, buffers bounded batches, and exposes contextHeaders() for cross-service correlation. Use a replays:write key.
AI releases
Create a release in Manage → AI Releases, select the environment, then set
a baseline, candidate and rollout. With your initialized client, evaluate it using
an environment-bound key with ai_configs:read:
The result includes key, version, config, reason, variation_key, and
rollout_percentage (idiomatic field names for typed SDKs). Pass a stable user
identity. Decisions are fetched afresh; verify baseline, rollout and paused
behavior in development before ramping production. Your backend calls the AI
provider. Ordinary evaluation leaves secret references unresolved; never put
provider credentials in a configuration delivered to browsers or mobile apps.
See the release guide for lifecycle and cleanup.