meta.plan label, and upgrading a customer is one keys.updateKey call that takes effect within about ten seconds.
You need a root key with the permissions listed on this page. Create one in the dashboard under Settings > Root Keys. See Permission reference for every permission.
Define the tiers
Define each plan once and build every key from it. Rate limits cap how often, credits cap how much, permissions unlock features, andmeta returns the plan name on every verification so your handlers don’t need a database lookup.
src/plans.ts
keys.createKey creates any that don’t exist. keys.setPermissions does too, but only if the root key has rbac.*.create_permission; otherwise it returns 403. Don’t use * in slugs, because it isn’t a wildcard.
Create a key for a plan
src/keys.ts
Read the plan during verification
Gate features with apermissions query so Unkey makes the decision. Use meta.plan only for softer choices, such as page size.
src/handler.ts
Change a customer’s plan
keys.updateKey changes a key in place. Fields you leave out keep their value, ratelimits replaces the whole list, and credits: null removes the cap and any refill. Use keys.setPermissions for permissions. It replaces the key’s permissions, so a downgrade removes what the higher plan granted.
Related
- Creating keys for every field and its bounds.
- Usage-based billing with credits for metering inside a plan.
- Roles and permissions are documented under Roles and permissions.