> ## Documentation Index
> Fetch the complete documentation index at: https://unkey.com/docs/llms.txt
> Use this file to discover all available pages before exploring further.

> ## Agent Instructions
> Unkey is two separate products. Compute builds, deploys, and runs apps behind a gateway. API Management issues API keys, enforces rate limits, manages identities and permissions, and reports usage. Say which product a page belongs to; a reader can use either without the other.
> Every Unkey API endpoint is an HTTP POST to https://api.unkey.com/v2/{service}.{procedure} with a root key in the Authorization: Bearer header. Root keys are workspace scoped.
> Error codes have the form err:{system}:{category}:{specific} and each has a page at /errors/{system}/{category}/{specific}.
> The word environment means production or preview in Compute. Rate limiting has four meanings on this site; the glossary lists them.

# API management

> Put API keys in front of an app you host anywhere.

API Management issues API keys to the users of your application and checks those keys on every request. Unkey stores only a hash of each key. It runs the checks you configure (expiry, credits, rate limits, permissions, IP allow lists) and returns one verdict your backend can act on. Your app can keep running wherever it already runs.

<Columns cols={2}>
  <Card title="Issue and verify your first key" icon="rocket" href="/docs/api-management/get-started/quickstart">
    Create a keyspace, create a key, and verify it with curl or an SDK in a few minutes.
  </Card>

  <Card title="Keyspaces, keys, identities, and root keys" icon="sitemap" href="/docs/api-management/get-started/concepts">
    The four objects you work with and how they fit together.
  </Card>

  <Card title="Keyspaces" icon="folder-tree" href="/docs/api-management/keyspaces/overview">
    The container for keys: settings, defaults, and listing keys.
  </Card>

  <Card title="Creating keys" icon="key" href="/docs/api-management/keys/creating-keys">
    Every field on `keys.createKey`, with bounds and defaults.
  </Card>

  <Card title="Verifying keys" icon="shield-check" href="/docs/api-management/keys/verifying-keys">
    What `keys.verifyKey` checks, in which order, and what it returns.
  </Card>

  <Card title="Credits and refill" icon="coins" href="/docs/api-management/keys/credits-and-refill">
    Meter total usage per key and refill it daily or monthly.
  </Card>

  <Card title="Rate limiting, identities, and authorization" icon="gauge-high" href="/docs/api-management/ratelimiting/overview">
    Per-key and shared rate limits, identities, roles, and permission queries.
  </Card>

  <Card title="Analytics and audit logs" icon="chart-line" href="/docs/api-management/analytics/overview">
    Query verification data with SQL and follow every change in the audit log.
  </Card>
</Columns>

## How this ties to Compute and Platform

Root keys authenticate your calls to the Unkey API, and both products share the CLI. You'll find both documented in [Platform](/docs/platform). If you also host your app on Unkey, the Compute gateway can verify keys for you with its key-auth policy. See [API key authentication](/docs/compute/gateway/api-key-auth).
