You need a root key with the permissions listed on this page. Create one in the dashboard under Settings > Root Keys. See Permission reference for every permission.
200 even when some fail. data.migrated lists each imported hash with its new keyId. data.failed lists the hashes that didn’t import, usually because the hash already exists in Unkey. Hashes must be unique across all of Unkey, not just your workspace. Calls POST /v2/keys.migrateKeys. See Migrating keys.
Usage
Flags
string
required
Id of the API to import the keys into.
string
required
JSON array of key objects. Only
hash is required. Each object also takes name, externalId, meta, roles, permissions, expires, enabled, credits, and ratelimits, with the same meaning as on create-key.string
required
Id of the migration provider configured for your workspace. Unkey support issues it.
Shared flags
Everyunkey api command takes these. See CLI output and shared flags.
string
Root key used for the request. Falls back to
UNKEY_ROOT_KEY, then to the key stored by unkey auth login.string
default:"https://api.unkey.com"
Base URL of the API. Falls back to
UNKEY_API_BASE_URL. You don’t normally need to set it.string
default:"~/.unkey/config.toml"
Path of the config file written by
unkey auth login. Falls back to UNKEY_CONFIG.string
Output format. Falls back to
UNKEY_OUTPUT. json prints the full response. Any other value prints the request ID and data.string
Send this JSON as the whole request body instead of using the command’s flags. You can’t combine it with them.
Required permissions
api.*.create_key or api.<apiId>.create_key. See Root key permissions.
Examples
Import two hashes
Raw body