Get API key by hash
Find out what key this is.
Required Permissions
Your credential must have one of the following permissions for basic key information:
api.*.read_key(to read keys from any API)api.<api_id>.read_key(to read keys from a specific API)unkey:v1:<workspace_id>:keyspaces/*/keys/*#read_key(to read keys in any keyspace)unkey:v1:<workspace_id>:keyspaces/<keyspace_id>/keys/*#read_key(to read keys in a specific keyspace)unkey:v1:<workspace_id>:keyspaces/<keyspace_id>/keys/<key_id>#read_key(to read a specific key)
If your credential lacks permissions but the key exists, we may return a 404 status here to prevent leaking the existence of a key to unauthorized clients. If you believe that a key should exist, but receive a 404, please double check your credential has the correct permissions.
Authorizations
Unkey uses bearer tokens for authentication. Public integrations use root keys, while the dashboard proxy uses short-lived JWTs. To authenticate, include the token in the Authorization header of each request:
Root keys have specific permissions attached to them, controlling what operations they can perform. Legacy permissions use tuple strings like api.*.create_key; resource permissions use Unkey Resource Names plus actions, like unkey:v1:ws_123:keyspaces/*#create_key.
Security best practices:
- Keep root keys secure and never expose them in client-side code
- Use different root keys for different environments
- Rotate keys periodically, especially after team member departures
- Create keys with minimal necessary permissions following least privilege principle
- Monitor key usage with audit logs.
Body
The complete API key string provided by you, including any prefix. Never log, cache, or store API keys in your system as they provide full access to user resources. Include the full key exactly as provided - even minor modifications will cause a not found error.
1 - 512"sk_1234abcdef5678"
Response
Successfully retrieved key information.