You need a root key with the permissions listed on this page. Create one in the dashboard under Settings > Root Keys. See Permission reference for every permission.
--body and set the field to null. The flags can’t do this. Calls POST /v2/keys.updateKey. See Enabling, disabling, and deleting keys.
Usage
Flags
string
required
Id of the key to update.
string
JSON object with an optional
remaining and an optional refill of interval (daily or monthly), amount, and refillDay. refillDay is a day of the month from 1 to 31. It’s required for monthly and not allowed for daily. Either mistake fails with 400. Setting remaining to null makes the key unlimited and drops its refill schedule.boolean
Enable (
--enabled) or disable (--enabled=false) the key. Leave it off to keep the current state.integer
New expiry as a Unix timestamp in milliseconds.
string
Link the key to the identity with this external id. The identity is created if it doesn’t exist.
string
JSON object that replaces the key’s metadata.
string
New name.
string[]
Comma-separated permission slugs that replace the key’s direct permissions. A slug that doesn’t exist yet is created.
string
JSON array of rate limits, each with
name, limit, duration in milliseconds, and autoApply. Replaces the key’s rate limits.string[]
Comma-separated role names that replace the key’s roles. Each role must already exist. An unknown name fails the call.
Shared flags
Everyunkey api command takes these. See CLI output and shared flags.
string
Root key used for the request. Falls back to
UNKEY_ROOT_KEY, then to the key stored by unkey auth login.string
default:"https://api.unkey.com"
Base URL of the API. Falls back to
UNKEY_API_BASE_URL. You don’t normally need to set it.string
default:"~/.unkey/config.toml"
Path of the config file written by
unkey auth login. Falls back to UNKEY_CONFIG.string
Output format. Falls back to
UNKEY_OUTPUT. json prints the full response. Any other value prints the request ID and data.string
Send this JSON as the whole request body instead of using the command’s flags. You can’t combine it with them.
Required permissions
api.*.update_key or api.<apiId>.update_key for the API the key belongs to. See Root key permissions.
Examples
Rename
Disable
Raw body