You need a root key with the permissions listed on this page. Create one in the dashboard under Settings > Root Keys, and pass it as
Authorization: Bearer <root key>. See Permission reference for every permission.ratelimit limit. Setting it again replaces the old one. An exact identifier beats a pattern. If an identifier matches two patterns, such as premium_* and *_eu, there’s no guarantee which applies, so keep patterns from overlapping. Calls POST /v2/ratelimit.setOverride. See Rate limit overrides.
Usage
Flags
integer
required
Window length in milliseconds, at least 1000. It doesn’t have to match the window the caller sends.
string
required
Identifier to override, or a pattern with
* such as premium_*.integer
required
Maximum operations allowed in the window. The API accepts 0, but checks against it then fail with a server error instead of being denied. To nearly block an identifier, use 1 with a long
--duration.string
required
Namespace id or name. The namespace must already exist.
Shared flags
Everyunkey api command takes these. See CLI output and shared flags.
string
Root key used for the request. Falls back to
UNKEY_ROOT_KEY, then to the key stored by unkey auth login.string
default:"https://api.unkey.com"
Base URL of the API. Falls back to
UNKEY_API_BASE_URL. You don’t normally need to set it.string
default:"~/.unkey/config.toml"
Path of the config file written by
unkey auth login. Falls back to UNKEY_CONFIG.string
Output format. Falls back to
UNKEY_OUTPUT. json prints the full response. Any other value prints the request ID and data.string
Send this JSON as the whole request body instead of using the command’s flags. You can’t combine it with them.
Required permissions
ratelimit.*.set_override or ratelimit.<namespace_id>.set_override. See Root key permissions.
Examples
Raise one user's limit
Pattern override
Raw body