You need a root key with the permissions listed on this page. Create one in the dashboard under Settings > Root Keys. See Permission reference for every permission.
identity.*.create_identity (or identity.*.update_identity for an existing identity), api.*.create_key, and api.*.verify_key.
Create the identity with a limit
autoApply: true makes the limit count on every verification without the caller naming it.externalId earlier, the call returns HTTP 409 err:unkey:data:identity_already_exists. Use identities.updateIdentity with the same ratelimits array instead.Several limits on one identity
Add more than one limit when different operations need different budgets. A limit withautoApply: false is only checked when a verification names it, so an expensive endpoint can have its own budget.
requests (auto-applied) and tokens are checked together. If either is exceeded, the verification returns RATE_LIMITED and neither is consumed.
Exceptions for one key
If a key has a limit with the samename as one on its identity, the key’s limit wins for that key. Use this to give one integration a higher limit than the user’s other keys. Details are in Key and identity rate limits.