Every Unkey API endpoint is a POST to a path that names a service and a procedure, like /v2/keys.verifyKey or /v2/deployments.promoteDeployment. It isn’t REST: the path doesn’t name a resource, and the HTTP method doesn’t say what the call does. All parameters go in the JSON body.
The shape
The service is a camelCase noun for a group of resources, and the procedure is a camelCase verb phrase that usually ends in the resource name. IDs go in the body, not the path. For example, to fetch a key you send {"keyId": "key_..."} to keys.getKey. There are no query strings.
There are three GET exceptions: /v2/liveness, a health check that needs no root key, and /openapi.yaml and /reference, which serve the OpenAPI document and a browsable reference.
Services
Almost every procedure is under /v2. A procedure gets a new version prefix when its request or response changes in a breaking way. So far that’s happened once, for /v3/deployments.createDeployment. Each service belongs to one product, and its endpoints are documented there.
Verbs
Procedures use a small set of verbs, so you can often guess a name:
create, get, list, update, and delete for the basics.
- Action verbs where a resource does something, such as
verifyKey, rerollKey, migrateKeys, limit, multiLimit, setOverride, promoteDeployment, rollbackDeployment, setPolicies, and installApp.
set procedures (setPermissions, setRoles, setPolicies, setEnvironmentVariables) replace the whole list. add and remove procedures change one part of it.
Deprecated procedures
When a procedure is replaced, the old path keeps working for a while and shows a deprecation badge in the reference. Use the newest path in new code. Three paths are deprecated today:
/v2/deploy.createDeployment and /v2/deploy.getDeployment are replaced by the deployments service.
/v2/deployments.createDeployment is replaced by /v3/deployments.createDeployment, which takes an oci source instead of image and lets you leave out the source to use the app’s default.
Last modified on September 29, 2026