X-Unkey-Principal header. You can send one yourself to test the code that reads it.
Test your app locally
The principal header is JSON. Put it in the header value of your request:jq -c. It also catches invalid JSON before the request goes out.
- No
identity. The key isn’t linked to an identity. - No
credits. The key has unlimited usage. - No
rolesorpermissions. The key has none attached. - No header at all. This is what a request to an unauthenticated route looks like.
Test your policies
To test your policies, deploy to a preview and call its preview domain. Preview and production have separate policy lists. A policy change only applies on a new deployment.Next steps
The principal header
Every field and when it’s omitted.
Gateway policies
Add authentication, rate limits, and other rules to your app.