Skip to main content
You need a root key with the permissions listed on this page. Create one in the dashboard under Settings > Root Keys. See Permission reference for every permission.
Verify a key the way your API would. An invalid key still returns 200, with valid: false, and the command exits successfully. Check data.valid and data.code, not the exit status. Calls POST /v2/keys.verifyKey. See Verifying keys.

Usage

Flags

string
required
The key to verify, including its prefix.
string
JSON object with cost, the number of credits this verification uses. Defaults to 1.
string
Migration id, to verify a key that hasn’t been imported yet. The key is imported on first use.
string
Permission query the key must satisfy, for example documents.read AND (billing.read OR billing.write).
string
JSON array of rate limits to check, each with name and optional cost, limit, and duration overrides.
string[]
Comma-separated key=value tags recorded on the verification for analytics. At most 20 tags, each up to 512 characters.

Shared flags

Every unkey api command takes these. See CLI output and shared flags.
string
Root key used for the request. Falls back to UNKEY_ROOT_KEY, then to the key stored by unkey auth login.
string
default:"https://api.unkey.com"
Base URL of the API. Falls back to UNKEY_API_BASE_URL. You don’t normally need to set it.
string
default:"~/.unkey/config.toml"
Path of the config file written by unkey auth login. Falls back to UNKEY_CONFIG.
string
Output format. Falls back to UNKEY_OUTPUT. json prints the full response. Any other value prints the request ID and data.
string
Send this JSON as the whole request body instead of using the command’s flags. You can’t combine it with them. The endpoint also accepts keyspaces, a list of up to five keyspace ids that the key has to be in. It has no flag of its own, and a key outside them comes back as NOT_FOUND without spending credits or rate limits.

Required permissions

api.*.verify_key or api.<apiId>.verify_key for the API the key belongs to. A missing permission never returns 403. Whether the root key has no verify permission or has one for a different API, you get 200 with valid: false and code NOT_FOUND. See Root key permissions.

Examples

Verify
Verify with a permission query and tags
Or send the whole request as JSON:
Raw body
Last modified on September 29, 2026