Skip to main content

What you’ll build

A Next.js API route that requires a valid API key on every request. Invalid or missing keys get rejected with a 401. Time to complete: ~5 minutes

Prerequisites

1

Create a Next.js app

Skip this if you have an existing project.
2

Install the Unkey SDK

3

Add your root key

Get a root key from Settings → Root Keys and add it to your environment:
.env.local
Never commit your root key. Add .env.local to .gitignore.
4

Create a protected route

Create a new API route that requires authentication:
app/api/protected/route.ts
The withUnkey wrapper handles key extraction, verification, and error responses automatically. Invalid keys never reach your handler.
5

Start your server

6

Test it

First, create a test key in your Unkey dashboard, then:
Test with valid key
You should see:
Now try without a key:
Test without key
You’ll get a 401 Unauthorized response.

What’s in req.unkey?

After verification, req.unkey.data contains:
data.meta is your custom key metadata (set via meta when creating the key). This is different from the response’s top-level meta which contains requestId.

Next steps

Add rate limiting

Limit requests per key

Set usage limits

Cap total requests per key

Add permissions

Fine-grained access control

Next.js SDK Reference

Full SDK documentation

Troubleshooting

  • Ensure the key hasn’t expired or been revoked - Verify the Authorization header format: Bearer YOUR_KEY (note the space) - Check that your root key has the verify_key permission
  • Restart your dev server after adding .env.local - Make sure the file is in your project root - Check for typos in the variable name
Last modified on June 2, 2026