unkey api commands can authenticate without --root-key on every call.
Usage
Enter your root key: and doesn’t show what you type. An empty answer fails with root key cannot be empty. On success it saves the key to ~/.unkey/config.toml and prints Authentication successful. Key stored in <path>.
What gets written
~/.unkey/config.toml
0600, in a 0700 directory). Running the command again replaces the file, which is how you change the stored key.
The command doesn’t check the key with the API, so it saves whatever you type. A wrong key only shows up on your next unkey api call.
Only unkey api commands read this file, and only when neither --root-key nor UNKEY_ROOT_KEY is set. unkey deploy ignores it. See CLI authentication for which key wins.