A key is shown once
When you create an API key or a root key, you see it once, in the create response or the dashboard dialog. We keep only a SHA-256 hash of it. A leaked copy of our database doesn’t yield working keys, and we can’t show you a key again unless it’s a recoverable key. Moving keys from another system? Migrating keys lists the hash formats we accept.Recoverable keys
A recoverable key is one you can show again later. To create one:- Ask support@unkey.com to turn on encrypted storage for the keyspace. It’s off by default and set per keyspace.
- Create the key with
recoverable: true, using a root key with the encrypt permission for that keyspace.
err:unkey:application:precondition_failed and “This API does not support key encryption.”
This weakens the guarantee above: anyone with a root key that has decrypt can read the key, so grant decrypt narrowly.