Skip to main content
Every call to https://api.unkey.com needs a root key as a bearer token. The only exception is the customer portal’s end-user endpoints, which take a portal session instead.

Send a root key

Put the key in the Authorization header after Bearer :
A root key belongs to one workspace, and every request stays inside it. You don’t pass a workspace ID, and a key can’t reach another workspace. See Root keys to create one.

Errors a bad key returns

All of these use the standard error envelope, so one error handler covers them.

Keep root keys safe

Treat a root key like a database password:
  • Create one per service with only the permissions that service needs. A leaked key then does less damage and is easy to replace.
  • Never put a root key in client-side code, a mobile app, or a public repository.
  • If one leaks, rotate or delete it under Settings > Root Keys. See Root keys.
Root keys are for managing Unkey. They aren’t the API keys you issue to your own users, which you check with keys.verifyKey. See Verifying keys.
Last modified on September 29, 2026