analytics.getVerifications from five tables. key_verifications_v1 has one row per verification. The four rollups have one row per time bucket with counts already summed. Use a rollup for charts and totals, and the raw table when you need individual requests, latency, or a column the rollups don’t have.
key_verifications_v1
One row per call tokeys.verifyKey.
String
The
meta.requestId of the verification request. Join it with your own logs.Int64
When the verification happened, in milliseconds since the Unix epoch. Convert with
fromUnixTimestamp64Milli(time) to bucket or format it.Int64
When the row was recorded, in milliseconds since the Unix epoch. Filter on
time instead.String
Your workspace. Always the same value.
String
The keyspace the key belongs to. This is the keyspace’s
ks_ ID, not the api_ ID you pass to endpoints.String
The verified key. Empty when the key wasn’t found.
String
The identity attached to the key, or empty.
String
The identity’s
externalId, your own user or tenant ID. Group by it for per-customer usage.LowCardinality(String)
The verification result:
VALID, NOT_FOUND, DISABLED, EXPIRED, FORBIDDEN, INSUFFICIENT_PERMISSIONS, RATE_LIMITED, or USAGE_EXCEEDED, which are the values keys.verifyKey returns in data.code, plus WORKSPACE_DISABLED and WORKSPACE_NOT_FOUND, which the Compute gateway records when the workspace itself can’t be used.Array(String)
The
tags sent with the verification. Use has(tags, 'x') or arrayJoin(tags).Int64
Credits deducted by this verification. Zero for keys without credits.
Float64
How long Unkey took to process the verification, in milliseconds.
LowCardinality(String)
The region that served the request.
LowCardinality(String)
default:"api"
What performed the verification:
api for calls to keys.verifyKey, or gateway when a Compute key-auth policy verified the key.LowCardinality(String)
default:""
The Compute app whose gateway verified the key, or empty for API calls.
Rollup tables
key_verifications_per_minute_v1, key_verifications_per_hour_v1, key_verifications_per_day_v1, and key_verifications_per_month_v1 have the same columns. Each row sums one time bucket, so sum(count) equals the raw table’s row count for the same filter. The rollups don’t have request_id, region, or latency.
DateTime | Date
Start of the bucket.
DateTime on per-minute and per-hour, Date on per-day and per-month. Compare directly with now() or today().String
Your workspace.
String
The keyspace
ks_ ID.String
The identity, or empty.
String
The identity’s
externalId, or empty.String
The key, or empty when not found.
LowCardinality(String)
Same values as the raw table.
LowCardinality(String)
api or gateway, as on the raw table.LowCardinality(String)
The Compute app, or empty.
Array(String)
The request tags.
SimpleAggregateFunction(sum, Int64)
Verifications in the bucket. Read with
sum(count).SimpleAggregateFunction(sum, Int64)
Credits deducted in the bucket. Read with
sum(spent_credits).AggregateFunction(avg, Float64)
Can’t be read, because
avgMerge isn’t allowed. Compute latency from the raw table instead.AggregateFunction(quantilesTDigest(0.75), Float64)
Can’t be read. Same as
latency_avg.AggregateFunction(quantilesTDigest(0.99), Float64)
Can’t be read. Same as
latency_avg.Which table to use
- Raw table: individual requests and latency.
- Per-minute: the last few hours in fine detail.
- Per-hour: charts over a day to a week.
- Per-day and per-month: billing totals.