Skip to main content
You need a root key with the permissions listed on this page. Create one in the dashboard under Settings > Root Keys, and pass it as Authorization: Bearer <root key>. See Permission reference for every permission.
Create a portal for one keyspace or one app in your workspace. Each keyspace or app can have only one portal. A second portal for the same one, or a slug that’s already taken, returns 409 err:unkey:data:portal_already_exists. Calls POST /v2/portal.createPortal. The portal management commands are unreleased and may change without notice.

Usage

Flags

string
required
Portal handle, unique in your workspace. 3 to 64 lowercase letters, digits, and hyphens, not starting or ending with a hyphen. You pass it as --portal to the other portal commands. End users never see it.
string
required
Name shown to end users in the portal header, up to 64 characters. You can change it later.
string
Keyspace this portal serves. Pass exactly one of --keyspace-id or --app-id.
string
App this portal serves. Pass exactly one of --keyspace-id or --app-id.
boolean
default:"true"
Whether you can create sessions for the portal. Pass --enabled=false to create it turned off.
string
Absolute HTTPS URL of the logo shown in the portal header, up to 500 characters.
string
Six-digit hex color used for primary actions, for example #6366f1.

Shared flags

Every unkey api command takes these. See CLI output and shared flags.
string
Root key used for the request. Falls back to UNKEY_ROOT_KEY, then to the key stored by unkey auth login.
string
default:"https://api.unkey.com"
Base URL of the API. Falls back to UNKEY_API_BASE_URL. You don’t normally need to set it.
string
default:"~/.unkey/config.toml"
Path of the config file written by unkey auth login. Falls back to UNKEY_CONFIG.
string
Output format. Falls back to UNKEY_OUTPUT. json prints the full response. Any other value prints the request ID and data.
string
Send this JSON as the whole request body instead of using the command’s flags. You can’t combine it with them.

Required permissions

portal.*.create_portal, plus read on the resource the portal will serve: api.*.read_api or api.<apiId>.read_api for a keyspace, app.*.read_app or app.<appId>.read_app for an app. Without the read permission, the call fails with 403 and “You do not have permission to point a portal at that resource.” Unlike the other portal commands, a missing portal.*.create_portal returns 403, not 404. See Root key permissions.

Examples

Keyspace portal
Branded app portal
Or send the whole request as JSON:
Raw body

Developer portal

What a portal is and how your users reach it.

create-session

Mint the session that lets one end user in.
Last modified on September 29, 2026