What you’ll build
An Express server with a protected/secret route that requires a valid API key. Requests without a valid key get rejected with a 401.
Time to complete: ~5 minutes
Prerequisites
- Unkey account (free)
- Keyspace created in your Unkey dashboard
- Node.js 18+
Want to skip ahead?
Clone the complete example and run it locally.
1
Create your Express app
2
Add your root key
Get a root key from Settings → Root Keys and create a
.env file:.env
3
Create your server
Create
index.js with a protected route:index.js
4
Start your server
5
Test it
First, create a test key in your Unkey dashboard, then:You should see:Now try without a key:You’ll get:
Test with valid key
Test without key
What’s in data?
After successful verification, data contains:
Using as middleware
For cleaner code, extract verification into middleware:middleware/auth.js
Next steps
Add rate limiting
Limit requests per key
Set usage limits
Cap total requests per key
Add permissions
Fine-grained access control
SDK Reference
Full TypeScript SDK docs
Troubleshooting
Getting 401 even with a valid key?
Getting 401 even with a valid key?
- Ensure the key hasn’t expired or been revoked - Verify the
Authorizationheader format:Bearer YOUR_KEY(note the space) - Check that your root key has theverify_keypermission
Getting 500 errors?
Getting 500 errors?
- Check that
UNKEY_ROOT_KEYis set correctly in your.env- Make sure you’re callingrequire("dotenv").config()before using env vars - Check the Unkey dashboard for any service issues
TypeScript version?
TypeScript version?
The code above uses CommonJS. For TypeScript, install types and use imports: