Skip to main content
Create a keyspace, issue a key, and it from your backend. Every step is an HTTPS call to api.unkey.com, so it works from any host or language.
You need a root key with the permissions listed on this page. Create one in the dashboard under Settings > Root Keys, and pass it as Authorization: Bearer <root key>. See Permission reference for every permission.
The root key you create needs api.*.create_key and api.*.verify_key. Pick your language with the switcher. Only the steps that call the API change.
1

Create a keyspace

A keyspace holds the keys for one product, environment, or tier. In the dashboard, open Keyspaces (APIs) in the sidebar, click Create keyspace, and give it a name. Copy the API ID (api_...) from its settings page. You pass it when you create keys.
Create keyspace dialog with a name entered and the Create Keyspace button
1

Create a key

Call keys.createKey with the API ID. The name is only for you. Your users never see it.
This is the only time you see the key. Copy data.key now and give it to your user.
2

Verify the key

This is the call your backend makes on every incoming request. There’s no apiId field because the key alone identifies its keyspace.

How you read the verification response

Verification returns HTTP 200 even when the key is rejected. data.valid tells you whether the key passed. When it didn’t, data.code says why.
The response gets more fields as you set more on the key, such as credits, ratelimits, meta, and identity. Verifying keys lists every field and every code value.

Next steps

Creating keys

Prefixes, expiry, credits, rate limits, permissions, and metadata on one key.

Verifying keys

The order of checks, the code enum, and caching behavior.

Credits and refill

Sell a fixed number of requests and refill them on a schedule.

Keyspaces, keys, identities, and root keys

How the objects you just used fit together.
Last modified on September 29, 2026