> ## Documentation Index
> Fetch the complete documentation index at: https://unkey.com/docs/llms.txt
> Use this file to discover all available pages before exploring further.

> ## Agent Instructions
> Unkey is two separate products. Compute builds, deploys, and runs apps behind a gateway. API Management issues API keys, enforces rate limits, manages identities and permissions, and reports usage. Say which product a page belongs to; a reader can use either without the other.
> Every Unkey API endpoint is an HTTP POST to https://api.unkey.com/v2/{service}.{procedure} with a root key in the Authorization: Bearer header. Root keys are workspace scoped.
> Error codes have the form err:{system}:{category}:{specific} and each has a page at /errors/{system}/{category}/{specific}.
> The word environment means production or preview in Compute. Rate limiting has four meanings on this site; the glossary lists them.

# Security

> See how Unkey protects your keys and workspace and what you can turn on.

You hand Unkey keys that open your production systems. Here's how we protect them, and what you can turn on.

## How we protect you

**Keys are never stored in plaintext.** We keep only a SHA-256 hash of every API key and root key. A copy of our database doesn't yield working keys, and we can't show you a key again after you create it. If you need to read a key back later, you opt in per keyspace. See [Key storage](/docs/platform/security/key-storage).

**Access is scoped.** A root key only works in the workspace that issued it, and every endpoint needs a specific permission. Dashboard users are either an admin or a developer. A developer who tries an admin-only action gets `This action requires admin privileges.` See [Team](/docs/platform/workspace/team).

**Changes are audited.** Changes made in the dashboard appear in the audit log with who made them, the event, and a description. For example, renaming a workspace logs `workspace.update`. How long entries are kept depends on your plan. See [Limits](/docs/platform/billing/limits).

## Security features you can use

<Columns cols={2}>
  <Card title="Key storage" icon="lock" href="/docs/platform/security/key-storage">
    Hashing, verification, and the opt-in encrypted storage for recoverable keys.
  </Card>

  <Card title="GitHub secret scanning" icon="github" href="/docs/platform/security/github-secret-scanning">
    What happens when a key is pushed to a public repository.
  </Card>

  <Card title="Delete protection" icon="shield-halved" href="/docs/platform/security/delete-protection">
    A flag that blocks deleting a keyspace, project, or app until you turn it off.
  </Card>

  <Card title="Two-factor authentication" icon="mobile-screen" href="/docs/platform/workspace/two-factor-auth">
    Enroll a second factor on your own account.
  </Card>
</Columns>

## Reporting a vulnerability

If you find a security issue, email [security@unkey.com](mailto:security@unkey.com) with steps to reproduce. Don't open a public issue or pull request. Reports about `api.unkey.com` and `app.unkey.com` are in scope. The docs site, the marketing site, and misconfigured self-hosted setups aren't. The full policy is in [SECURITY.md](https://github.com/unkeyed/unkey/blob/main/SECURITY.md).
