You need a root key with the permissions listed on this page. Create one in the dashboard under Settings > Root Keys. See Permission reference for every permission.
production and a preview .
The slug is what you pass to later --app flags. It must be unique within the project, or you get a 409 conflict.
Pass exactly one source:
--gitfor a GitHub repository. Pass arepositoryto connect it now (the Unkey GitHub App must be installed first), or pass--git='{}'and connect one later with update-app.--ocifor a prebuilt image, if you already build images elsewhere.
Usage
Flags
string
GitHub repository connection as a JSON object, for example
{"repository":"unkeyed/api","defaultBranch":"main"}. Both fields are optional, so {} creates a Git app with no repository yet; defaultBranch requires repository. Mutually exclusive with --oci.string
OCI image source as a JSON object with a required
image field, for example {"image":"ghcr.io/acme/payments:v1.2.3"}. The reference needs an explicit tag or digest and is at most 256 characters. Mutually exclusive with --git.string
required
Human-readable name for the app, 1 to 256 characters.
string
required
Project ID or slug. Both forms resolve to the same project.
string
required
Stable app slug, unique within the project. 3 to 255 characters matching
^[a-zA-Z0-9_-]+$. Used in --app flags and in generated deployment hostnames.Shared flags
Everyunkey api command accepts these; CLI output and shared flags describes them in full.
string
A JSON document sent as the request body instead of building it from the flags above. It is mutually exclusive with the request-building flags, and unknown fields are rejected locally. See Send a raw body.
string
Root key for the request. Falls back to
UNKEY_ROOT_KEY, then to the config file written by unkey auth login. See CLI authentication.string
default:"https://api.unkey.com"
Base URL of the API. Falls back to
UNKEY_API_BASE_URL. You don’t normally need to set it.string
default:"~/.unkey/config.toml"
Path of the TOML file that
unkey auth login writes. Falls back to UNKEY_CONFIG.string
Output format. Falls back to
UNKEY_OUTPUT. Set json to print the full response envelope (meta and data) for piping; any other value prints the request ID followed by data.Required permissions
Your root key needs one of:project.*.create_app(apps in any project)project.<project_id>.create_app(apps in a specific project)
--git includes a repository, your key also needs app.*.connect_repository. --git='{}' doesn’t.
Without a matching permission the API answers 403 and the CLI prints Permission denied: followed by the detail. See Root key permissions for the full catalog.
Examples
Create an app connected to a repository:API endpoint
The command callsPOST /v2/apps.createApp and prints its response. The request fields carry the same names as the flags in camelCase, which is the shape --body expects.
Related
Projects, apps, and environments
How the three objects nest and how slugs and IDs are resolved.
Deploy from GitHub
Connect a repository and ship the first deployment.