You need a root key with the permissions listed on this page. Create one in the dashboard under Settings > Root Keys. See Permission reference for every permission.
--policy. Fields you leave out keep their values.
"match": nullor an empty array removes all match expressions, so the policy applies to every request.- Passing one of
keyauth,ratelimit,firewall,openapi, orloggingreplaces the rule, and can change its type. Pass at most one.
set-policies replaces the list, so get them from list-policies first.
Usage
Flags
string
required
App ID or slug.
string
required
Environment ID or slug.
string
required
Policy fields to update as a JSON object. Accepted keys are
name, enabled, match, keyauth, ratelimit, firewall, openapi, and logging.string
required
ID of the policy to update, from
list-policies.string
required
Project ID or slug. Both forms resolve to the same project.
Shared flags
Everyunkey api command accepts these; CLI output and shared flags describes them in full.
string
A JSON document sent as the request body instead of building it from the flags above. It is mutually exclusive with the request-building flags, and unknown fields are rejected locally. See Send a raw body.
string
Root key for the request. Falls back to
UNKEY_ROOT_KEY, then to the config file written by unkey auth login. See CLI authentication.string
default:"https://api.unkey.com"
Base URL of the API. Falls back to
UNKEY_API_BASE_URL. You don’t normally need to set it.string
default:"~/.unkey/config.toml"
Path of the TOML file that
unkey auth login writes. Falls back to UNKEY_CONFIG.string
Output format. Falls back to
UNKEY_OUTPUT. Set json to print the full response envelope (meta and data) for piping; any other value prints the request ID followed by data.Required permissions
Your root key needs one of:environment.*.update_policy(any environment)environment.<environment_id>.update_policy(a specific environment)
Permission denied: followed by the detail. See Root key permissions for the full catalog.
Examples
Disable a policy:API endpoint
The command callsPOST /v2/gateway.updatePolicy and prints its response. The request fields carry the same names as the flags in camelCase, which is the shape --body expects.
Related
Gateway policies
How policies are ordered, matched, and evaluated at the edge.