Skip to main content
API Management issues API keys to the users of your application and checks those keys on every request. Unkey stores only a hash of each key. It runs the checks you configure (expiry, credits, rate limits, permissions, IP allow lists) and returns one verdict your backend can act on. Your app can keep running wherever it already runs.

Issue and verify your first key

Create a keyspace, create a key, and verify it with curl or an SDK in a few minutes.

Keyspaces, keys, identities, and root keys

The four objects you work with and how they fit together.

Keyspaces

The container for keys: settings, defaults, and listing keys.

Creating keys

Every field on keys.createKey, with bounds and defaults.

Verifying keys

What keys.verifyKey checks, in which order, and what it returns.

Credits and refill

Meter total usage per key and refill it daily or monthly.

Rate limiting, identities, and authorization

Per-key and shared rate limits, identities, roles, and permission queries.

Analytics and audit logs

Query verification data with SQL and follow every change in the audit log.

How this ties to Compute and Platform

Root keys authenticate your calls to the Unkey API, and both products share the CLI. You’ll find both documented in Platform. If you also host your app on Unkey, the Compute gateway can verify keys for you with its key-auth policy. See API key authentication.
Last modified on September 29, 2026