Skip to main content
Use the Go SDK, github.com/unkeyed/sdks/api/go/v3 (current release ), to call the Unkey API from Go. The older v1 and v2 module paths are no longer updated.
You need a root key with the permissions listed on this page. Create one in the dashboard under Settings > Root Keys, and pass it as Authorization: Bearer <root key>. See Permission reference for every permission.

Install

It needs a recent Go toolchain (currently Go 1.25).

Construct the client

WithSecurity sets your root key. To change retries for every call, add unkey.WithRetryConfig(retry.Config{...}). For one call, pass operations.WithRetries(...) as the last argument. Request and response types are in github.com/unkeyed/sdks/api/go/v3/models/components, and typed errors in .../models/apierrors.

Verify a key

The response field, here V2KeysVerifyKeyResponseBody, is a pointer, so check it for nil even when err is nil. Optional request fields are pointers or slices. Use helpers such as unkey.String and unkey.Bool for pointer values. An invalid key is a successful call with Valid false, not an error. The meaning of each field is covered in Verifying keys and the schema in keys.verifyKey.

Create a key

ByteLength, Meta, Roles, Expires, Credits, Ratelimits, and Recoverable are the remaining fields. Creating keys explains them and keys.createKey lists the schema.

Apply a rate limit

The endpoint is ratelimit.limit.

Create a deployment

The client covers Compute too. Name the project, app, and environment, and optionally set the source with one of Oci, Git, or Deployment. Leave all three out to use the app’s default:
The endpoint is deployments.createDeploymentV3. Don’t use the CreateDeployment method. It calls the deprecated v2 endpoint. For projects, apps, and environments, see Projects, apps, and environments.

Handle errors

Every method returns a response or an error, never both. API errors have a type per status that you can match with errors.As. Anything else is an *apierrors.APIError.
The typed errors are BadRequestErrorResponse (400, whose Error_ is a components.BadRequestErrorDetails with a per-field GetErrors() list), UnauthorizedErrorResponse (401), ForbiddenErrorResponse (403), NotFoundErrorResponse (404), ConflictErrorResponse (409), GoneErrorResponse (410), PreconditionFailedErrorResponse (412), UnprocessableEntityErrorResponse (422), TooManyRequestsErrorResponse (429), InternalServerErrorResponse (500), and ServiceUnavailableErrorResponse (503). Each endpoint page in the API reference, for example keys.getKey, lists which ones apply.

Next steps

The unkey CLI

The same calls from a shell, built on this module.

API reference

Request and response fields for every method.
Last modified on September 29, 2026