Skip to main content
You need a root key with the permissions listed on this page. Create one in the dashboard under Settings > Root Keys, and pass it as Authorization: Bearer <root key>. See Permission reference for every permission.
Change a key’s credits and nothing else. The new balance applies to the next verification. Switching between limited and unlimited credits can take up to about 10 seconds. Calls POST /v2/keys.updateCredits. See Credits and refill.

Usage

Flags

string
required
Id of the key.
string
required
One of set, increment, or decrement. increment and decrement fail with 400 on a key with unlimited credits. Use set to give it a balance first.
integer
Credits to set, add, or subtract. Required for increment and decrement. Leave it off with set to make the key unlimited and keep any refill schedule. Sending "value": null through --body makes it unlimited and also clears the refill schedule. --value=0 is treated as leaving the flag off, so use --body to set a key to zero credits.

Shared flags

Every unkey api command takes these. See CLI output and shared flags.
string
Root key used for the request. Falls back to UNKEY_ROOT_KEY, then to the key stored by unkey auth login.
string
default:"https://api.unkey.com"
Base URL of the API. Falls back to UNKEY_API_BASE_URL. You don’t normally need to set it.
string
default:"~/.unkey/config.toml"
Path of the config file written by unkey auth login. Falls back to UNKEY_CONFIG.
string
Output format. Falls back to UNKEY_OUTPUT. json prints the full response. Any other value prints the request ID and data.
string
Send this JSON as the whole request body instead of using the command’s flags. You can’t combine it with them.

Required permissions

api.*.update_key or api.<apiId>.update_key for the API the key belongs to. See Root key permissions.

Examples

Set to 1000
Top up by 500
Or send the whole request as JSON:
Raw body
Last modified on September 29, 2026