You need a root key with the permissions listed on this page. Create one in the dashboard under Settings > Root Keys, and pass it as
Authorization: Bearer <root key>. See Permission reference for every permission.--recoverable. Calls POST /v2/keys.createKey. See Creating keys.
Usage
Flags
string
required
Id of the API (keyspace) the key belongs to.
integer
Length of the random part of the key in bytes. The API accepts 16 to 255. If you leave the flag off, it uses the keyspace’s default byte length, or 16 if the keyspace doesn’t set one.
string
JSON object with
remaining and an optional refill of interval (daily or monthly), amount, and refillDay. refillDay is a day of the month from 1 to 31. It’s required for monthly, and a monthly refill without it fails with 400. It’s ignored for daily.boolean
default:"true"
Whether the key can be used. Create it disabled to turn it on later.
integer
Unix timestamp in milliseconds after which the key stops verifying.
string
Your identifier for the user or tenant, up to 255 characters. Links the key to the identity with this external id, and creates the identity if needed.
string
JSON object stored on the key and returned by every verification. At most 100 top-level properties.
string
Name shown in the dashboard, up to 255 characters.
string[]
Comma-separated permission slugs to grant directly, at most 1000 of them. A slug that doesn’t exist yet is created.
string
Prefix added to the start of the key so users can tell keys apart, for example
prod. Up to 16 characters of letters, digits, and underscores. If you leave it off, the keyspace’s default prefix is used, if it has one.string
JSON array of rate limits, each with
name, limit, duration in milliseconds, and autoApply.boolean
default:"false"
Store the plaintext encrypted so
get-key --decrypt can return it later. Needs encrypt_key. Fails with 412 unless the keyspace has key encryption turned on, which only we can do, through a support request.string[]
Comma-separated role names to assign, at most 100 of them. Unlike permissions, each role must already exist. An unknown name fails the whole call.
Shared flags
Everyunkey api command takes these. See CLI output and shared flags.
string
Root key used for the request. Falls back to
UNKEY_ROOT_KEY, then to the key stored by unkey auth login.string
default:"https://api.unkey.com"
Base URL of the API. Falls back to
UNKEY_API_BASE_URL. You don’t normally need to set it.string
default:"~/.unkey/config.toml"
Path of the config file written by
unkey auth login. Falls back to UNKEY_CONFIG.string
Output format. Falls back to
UNKEY_OUTPUT. json prints the full response. Any other value prints the request ID and data.string
Send this JSON as the whole request body instead of using the command’s flags. You can’t combine it with them.
Required permissions
api.*.create_key or api.<apiId>.create_key. --recoverable also needs api.*.encrypt_key or api.<apiId>.encrypt_key. Without the permission you get a 404, not a 403, so the response doesn’t reveal whether the API exists. See Root key permissions.
Examples
Plain key
Key for a user with roles
Key with credits and a rate limit
Raw body