Skip to main content
You need a root key with the permissions listed on this page. Create one in the dashboard under Settings > Root Keys, and pass it as Authorization: Bearer <root key>. See Permission reference for every permission.
Create a portal session so one of your end users can sign in to the portal. Redirect them to data.url. It works once and expires after 15 minutes. After they sign in, their session lasts 24 hours. The scopes you pass decide what they can do. data.id identifies the session. It isn’t a credential, so it’s safe to log. A disabled portal returns 403 “Portal is disabled”. A portal that doesn’t exist, or that your root key can’t reach, returns 404. Calls POST /v2/portal.createSession. See Portal sessions.

Usage

Flags

string
required
The end user’s ID in your system. The session only sees that identity’s keys.
string
required
Portal id or slug.
string[]
required
Comma-separated capabilities from keys:read, keys:reroll, and analytics:read. keys:reroll and analytics:read each need keys:read too, because both are reached from the keys page. The command rejects them without it.
boolean
default:"false"
Create a preview session for testing the portal without a real end user.
string
Full https:// URL the portal sends the user back to when they’re done, up to 500 characters. An http:// URL, a //host/path, or a bare path fails with 400.

Shared flags

Every unkey api command takes these. See CLI output and shared flags.
string
Root key used for the request. Falls back to UNKEY_ROOT_KEY, then to the key stored by unkey auth login.
string
default:"https://api.unkey.com"
Base URL of the API. Falls back to UNKEY_API_BASE_URL. You don’t normally need to set it.
string
default:"~/.unkey/config.toml"
Path of the config file written by unkey auth login. Falls back to UNKEY_CONFIG.
string
Output format. Falls back to UNKEY_OUTPUT. json prints the full response. Any other value prints the request ID and data.
string
Send this JSON as the whole request body instead of using the command’s flags. You can’t combine it with them.

Required permissions

portal.*.create_portal_session or portal.<portalId>.create_portal_session. Permissions to manage a portal don’t include this one. You also need the matching permission on the APIs behind the portal for each scope:
  • keys:read needs read_key and read_api.
  • keys:reroll needs create_key, plus encrypt_key when the keyspace stores recoverable keys.
  • analytics:read needs read_analytics.
Without the session permission, you get a 404 as if the portal didn’t exist. With it but missing a scope’s permission, the whole request fails with 403. We never create a session with fewer scopes than you asked for. See Root key permissions.

Examples

Read and reroll keys
Analytics with a return URL
Or send the whole request as JSON:
Raw body
Last modified on September 29, 2026