Skip to main content
Set an expiry to make a key stop working at a time you choose. After that time, every verification returns code: EXPIRED. Nothing else about the key changes, so you can extend an expired trial key and it keeps its metadata, credits, and permissions.

Set an expiry

integer | null
Unix timestamp in milliseconds. The maximum is 4102444800000 (1 January 2100). On keys.updateKey, omitting the field keeps the current expiry and null removes it. A timestamp in the past is accepted and makes the key expired at once.
In the dashboard’s Create key dialog, the expiry must be at least two minutes in the future.

What happens at expiry

Expiry is checked against Unkey’s clock, not your server’s. An expired key uses no rate limits or credits. The response looks like this:
The expires value is also returned on valid verifications, so your backend can warn a user that their key is about to lapse.

Expired keys are kept

Expired keys aren’t deleted. They stay in the keyspace, show up in apis.listKeys and the dashboard, and keep returning EXPIRED. You can extend one and keep its analytics history. To remove expired keys, delete them yourself. See Disabling and deleting keys.

Extend or remove an expiry

Extending an expired key takes about 10 seconds to apply, and a few verifications just after that can still return EXPIRED. Verifying keys explains the timing.

Expiry and rerolling

Rerolling a key copies its expiry to the new key and sets the old key to expire after the grace period you choose. In the dashboard you can’t reroll an expired key, and the grace period can’t go past the original expiry. The API applies the grace period as requested. See Rerolling keys.

Expiry compared with credits

An expiry ends access at a time. Credits end it after an amount of use. For a trial that ends after seven days or 1,000 requests, whichever comes first, set both. See Credits and refill.
Last modified on September 29, 2026