> ## Documentation Index
> Fetch the complete documentation index at: https://unkey.com/docs/llms.txt
> Use this file to discover all available pages before exploring further.

> ## Agent Instructions
> Unkey is two separate products. Compute builds, deploys, and runs apps behind a gateway. API Management issues API keys, enforces rate limits, manages identities and permissions, and reports usage. Say which product a page belongs to; a reader can use either without the other.
> Every Unkey API endpoint is an HTTP POST to https://api.unkey.com/v2/{service}.{procedure} with a root key in the Authorization: Bearer header. Root keys are workspace scoped.
> Error codes have the form err:{system}:{category}:{specific} and each has a page at /errors/{system}/{category}/{specific}.
> The word environment means production or preview in Compute. Rate limiting has four meanings on this site; the glossary lists them.

# unkey auth login

> Store a root key locally so unkey api commands stop asking for it.

Store a root key locally so the `unkey api` commands can authenticate without `--root-key` on every call.

## Usage

```bash theme={"system"}
unkey auth login
```

The command takes no flags or arguments. It prompts `Enter your root key:` and doesn't show what you type. An empty answer fails with `root key cannot be empty`. On success it saves the key to `~/.unkey/config.toml` and prints `Authentication successful. Key stored in <path>`.

## What gets written

```toml ~/.unkey/config.toml theme={"system"}
root_key = "unkey_xxx"
```

Only your user can read the file (mode `0600`, in a `0700` directory). Running the command again replaces the file, which is how you change the stored key.

The command doesn't check the key with the API, so it saves whatever you type. A wrong key only shows up on your next `unkey api` call.

Only `unkey api` commands read this file, and only when neither `--root-key` nor `UNKEY_ROOT_KEY` is set. `unkey deploy` ignores it. See [CLI authentication](/docs/platform/cli/authentication) for which key wins.

## Examples

Log in, then run commands without a key flag:

```bash theme={"system"}
unkey auth login
unkey api apis list-keys --api-id=api_1234abcd
```

Replace the stored key with a new one:

```bash theme={"system"}
unkey auth login
```

Bypass the stored key for a single command:

```bash theme={"system"}
unkey api apis list-keys --api-id=api_1234abcd --root-key=unkey_other
```
