Skip to main content
You need a root key with the permissions listed on this page. Create one in the dashboard under Settings > Root Keys, and pass it as Authorization: Bearer <root key>. See Permission reference for every permission.
Check a for any identifier, such as a user ID or IP address. The response says whether the request passed and how much is left in the window. The namespace is created on first use. If an override matches the identifier, its limit and window are used instead of yours. A deleted namespace isn’t recreated. The call fails with 410 Gone and err:unkey:data:ratelimit_namespace_gone. Calls POST /v2/ratelimit.limit. See Limit and multi-limit.

Usage

Flags

integer
required
Window length in milliseconds, from 1000 (one second) to 2592000000 (30 days).
string
required
The thing being limited, for example a user id or IP address. Up to 512 characters.
integer
required
Maximum operations allowed in the window. At least 1.
string
required
Namespace id or name, up to 512 characters. A new name creates the namespace.
integer
How much of the limit this call uses. Defaults to 1. A cost of 0 checks the limit without using any, but --cost=0 is treated as leaving the flag off, so it charges 1. Use --body to send a cost of 0.

Shared flags

Every unkey api command takes these. See CLI output and shared flags.
string
Root key used for the request. Falls back to UNKEY_ROOT_KEY, then to the key stored by unkey auth login.
string
default:"https://api.unkey.com"
Base URL of the API. Falls back to UNKEY_API_BASE_URL. You don’t normally need to set it.
string
default:"~/.unkey/config.toml"
Path of the config file written by unkey auth login. Falls back to UNKEY_CONFIG.
string
Output format. Falls back to UNKEY_OUTPUT. json prints the full response. Any other value prints the request ID and data.
string
Send this JSON as the whole request body instead of using the command’s flags. You can’t combine it with them.

Required permissions

ratelimit.*.limit or ratelimit.<namespace_id>.limit. Creating a namespace on first use also needs ratelimit.*.create_namespace. See Root key permissions.

Examples

100 requests per minute
Expensive operation costing 5
Or send the whole request as JSON:
Raw body
Last modified on September 29, 2026