https://api.unkey.com needs a root key as a bearer token. The only exception is the customer portal’s end-user endpoints, which take a portal session instead.
Send a root key
Put the key in theAuthorization header after Bearer :
Errors a bad key returns
All of these use the standard error envelope, so one error handler covers them.
Keep root keys safe
Treat a root key like a database password:- Create one per service with only the permissions that service needs. A leaked key then does less damage and is easy to replace.
- Never put a root key in client-side code, a mobile app, or a public repository.
- If one leaks, rotate or delete it under Settings > Root Keys. See Root keys.
keys.verifyKey. See Verifying keys.