> ## Documentation Index
> Fetch the complete documentation index at: https://unkey.com/docs/llms.txt
> Use this file to discover all available pages before exploring further.

> ## Agent Instructions
> Unkey is two separate products. Compute builds, deploys, and runs apps behind a gateway. API Management issues API keys, enforces rate limits, manages identities and permissions, and reports usage. Say which product a page belongs to; a reader can use either without the other.
> Every Unkey API endpoint is an HTTP POST to https://api.unkey.com/v2/{service}.{procedure} with a root key in the Authorization: Bearer header. Root keys are workspace scoped.
> Error codes have the form err:{system}:{category}:{specific} and each has a page at /errors/{system}/{category}/{specific}.
> The word environment means production or preview in Compute. Rate limiting has four meanings on this site; the glossary lists them.

# unkey api portal get-portal

> Read one portal by its handle or by the resource it serves.

<Note>
  You need a root key with the permissions listed on this page. Create one in the dashboard under **Settings > Root Keys**. See [Permission reference](/docs/platform/root-keys/permissions-legacy) for every permission.
</Note>

Read a [portal](/docs/api-management/portal/overview): its branding, whether it's enabled, and the keyspace or app behind it. Look it up by ID or slug, or by the keyspace or app it serves to check whether one has a portal. Pass exactly one of the three. More than one fails with 400. Calls `POST /v2/portal.getPortal`. The portal management commands are unreleased and may change without notice.

## Usage

```bash theme={"system"}
unkey api portal get-portal (--portal=<portal> | --keyspace-id=<id> | --app-id=<id>) [flags]
```

## Flags

<ParamField body="--portal" type="string">
  Portal id or slug.
</ParamField>

<ParamField body="--keyspace-id" type="string">
  Find the portal for this keyspace.
</ParamField>

<ParamField body="--app-id" type="string">
  Find the portal for this app.
</ParamField>

### Shared flags

Every `unkey api` command takes these. See [CLI output and shared flags](/docs/platform/cli/output-and-flags).

<ParamField body="--root-key" type="string">
  Root key used for the request. Falls back to `UNKEY_ROOT_KEY`, then to the key stored by `unkey auth login`.
</ParamField>

<ParamField body="--api-url" type="string" default="https://api.unkey.com">
  Base URL of the API. Falls back to `UNKEY_API_BASE_URL`. You don't normally need to set it.
</ParamField>

<ParamField body="--config" type="string" default="~/.unkey/config.toml">
  Path of the config file written by `unkey auth login`. Falls back to `UNKEY_CONFIG`.
</ParamField>

<ParamField body="--output" type="string">
  Output format. Falls back to `UNKEY_OUTPUT`. `json` prints the full response. Any other value prints the request ID and `data`.
</ParamField>

<ParamField body="--body" type="string">
  Send this JSON as the whole request body instead of using the command's flags. You can't combine it with them.
</ParamField>

## Required permissions

`portal.*.read_portal` or `portal.<portalId>.read_portal`. Without it you get a 404, so a 404 means either there's no such portal or you don't have permission. See [Root key permissions](/docs/platform/root-keys/permissions).

## Examples

```bash By handle theme={"system"}
unkey api portal get-portal --portal=acme-portal
```

```bash By the keyspace it serves theme={"system"}
unkey api portal get-portal --keyspace-id=ks_1234abcd
```

Or send the whole request as JSON:

```bash Raw body theme={"system"}
unkey api portal get-portal --body='{"portal":"acme-portal"}'
```
