Skip to main content
API Management issues API keys to the users of your application and checks those keys on every request. Unkey stores only a hash of each key. It runs the checks you configure (expiry, credits, rate limits, permissions, IP allow lists) and returns one verdict your backend can act on. Your app can keep running wherever it already runs.

Issue and verify your first key

Create a keyspace, create a key, and verify it with curl or an SDK in a few minutes.

Keyspaces, keys, identities, and root keys

The four objects you work with and how they fit together.

Keyspaces

The container for keys: settings, defaults, and listing keys.

Creating keys

Every field on keys.createKey, with bounds and defaults.

Verifying keys

What keys.verifyKey checks, in which order, and what it returns.

Credits and refill

Meter total usage per key and refill it daily or monthly.

Rate limiting, identities, and authorization

Per-key and shared rate limits, identities, roles, and permission queries.

Analytics

Query verification and rate-limit data with SQL.

Audit logs

See who changed what in the workspace, and stream it out with a log drain.

How this ties to Compute and Platform

Root keys authenticate your calls to the Unkey API, and both products share the CLI. You’ll find both documented in Platform. If you also host your app on Unkey, the Compute gateway can verify keys for you with its key-auth policy. See API key authentication.
Last modified on October 6, 2026