Skip to main content
The unkey CLI lets you do from your terminal what you’d do with the API. It covers both products. Nearly every API endpoint has a matching unkey api <group> <command>. The exception is the customer portal’s end-user endpoints, which use a portal session instead of a root key. There are also three top-level commands: unkey deploy deploys a prebuilt container image to Compute, unkey auth login stores a root key so you don’t pass it on every call, and unkey healthcheck checks a URL from a script.
The CLI is early and best effort. Commands, flags, and output can change without notice. The HTTP API is versioned and stable, so use the API for scripts that must not break.

Command shape

Commands look like unkey <command> [subcommand] [flags] [arguments]. unkey --help, unkey <command> --help, and unkey help <command> print usage, and unkey --version prints the installed version. Every unkey api command shares five flags for auth, output, and a raw request body. They’re on CLI output and shared flags, along with flag syntax, so each command page only lists its own flags.

Command groups

unkey api has 14 groups, one per API service. Each command has its own page in the CLI section of the product it belongs to.

Compute

, deployments, domains, , gateway policies, and the GitHub App installation are Compute resources.

API Management

Keyspaces, keys, identities, permissions and roles, , and the customer portal are API Management resources. analytics appears in both tables because two of its commands read Compute data and two read API Management data.

Top-level commands

Next steps

Install the CLI

npm package or GitHub release.

CLI authentication

Where the root key comes from and in which order.

Output and shared flags

--output json, --body, --api-url, --config.
Last modified on September 29, 2026