Skip to main content
Store a root key locally so the unkey api commands can authenticate without --root-key on every call.

Usage

The command takes no flags or arguments. It prompts Enter your root key: and doesn’t show what you type. An empty answer fails with root key cannot be empty. On success it saves the key to ~/.unkey/config.toml and prints Authentication successful. Key stored in <path>.

What gets written

~/.unkey/config.toml
Only your user can read the file (mode 0600, in a 0700 directory). Running the command again replaces the file, which is how you change the stored key. The command doesn’t check the key with the API, so it saves whatever you type. A wrong key only shows up on your next unkey api call. Only unkey api commands read this file, and only when neither --root-key nor UNKEY_ROOT_KEY is set. unkey deploy ignores it. See CLI authentication for which key wins.

Examples

Log in, then run commands without a key flag:
Replace the stored key with a new one:
Bypass the stored key for a single command:
Last modified on September 29, 2026