Skip to main content
You need a root key with the permissions listed on this page. Create one in the dashboard under Settings > Root Keys. See Permission reference for every permission.
Replace the gateway policies of an in one atomic request. Policies run at the edge before a request reaches your : they API keys, , block requests outright, or validate them against your OpenAPI spec. Each policy sets exactly one of keyauth, ratelimit, firewall, openapi, or logging, plus up to ten optional match expressions that restrict which requests it applies to. Every call replaces the whole list. The environment’s policies become exactly the array you send, in that order, and each one gets a new ID. An empty array removes all policies. An environment can have up to 50 policies. If any policy is invalid, nothing is saved.

Usage

Flags

string
required
App ID or slug.
string
required
Environment ID or slug.
string
required
JSON array containing the complete ordered policy list.
string
required
Project ID or slug. Both forms resolve to the same project.

Shared flags

Every unkey api command accepts these; CLI output and shared flags describes them in full.
string
A JSON document sent as the request body instead of building it from the flags above. It is mutually exclusive with the request-building flags, and unknown fields are rejected locally. See Send a raw body.
string
Root key for the request. Falls back to UNKEY_ROOT_KEY, then to the config file written by unkey auth login. See CLI authentication.
string
default:"https://api.unkey.com"
Base URL of the API. Falls back to UNKEY_API_BASE_URL. You don’t normally need to set it.
string
default:"~/.unkey/config.toml"
Path of the TOML file that unkey auth login writes. Falls back to UNKEY_CONFIG.
string
Output format. Falls back to UNKEY_OUTPUT. Set json to print the full response envelope (meta and data) for piping; any other value prints the request ID followed by data.

Required permissions

Your root key needs one of:
  • environment.*.set_policies (any environment)
  • environment.<environment_id>.set_policies (a specific environment)
Without a matching permission the API answers 403 and the CLI prints Permission denied: followed by the detail. See Root key permissions for the full catalog.

Examples

Require an API key from one keyspace. A keyauth rule names one to five keyspaces, and each one must exist in your workspace. Otherwise the call fails with Keyspace "<id>" does not exist. and nothing is saved.
Remove every policy:
Send the request body as JSON:

API endpoint

The command calls POST /v2/gateway.setPolicies and prints its response. The request fields carry the same names as the flags in camelCase, which is the shape --body expects.

Gateway policies

How policies are ordered, matched, and evaluated at the edge.
Last modified on September 29, 2026