The Unkey CLI gives you direct access to the Unkey API from your terminal. Create and manage API keys, configure rate limits, set permissions, and query analytics, all without leaving the command line.
The CLI is early and provided on a best-effort basis. There are no breaking change guarantees for commands, flags, or output format. The underlying API is versioned and stable.
Installation#
Authentication#
Before using the CLI, authenticate with your root key:
This stores your key at ~/.unkey/config.toml. All subsequent commands use it automatically.
You can also pass a key per-command or via environment variable:
Usage#
All API operations live under the unkey api command, organized by resource:
Resources#
| Resource | Description |
|---|---|
apis | Create, get, delete API namespaces and list their keys |
keys | Create, verify, update, delete keys and manage their permissions and roles |
identities | Create, get, update, delete identities for grouping keys |
permissions | Create, get, delete permissions and roles |
ratelimit | Apply rate limits and manage overrides |
analytics | Query key verification data with SQL |
Examples#
Create an API and issue a key:
Verify a key:
Set up rate limiting:
Query analytics:
Manage permissions:
Output#
By default, the CLI prints the request ID, followed by the response data:
For scripting, use --output=json to get the raw API response envelope (meta + data) as JSON on stdout:
Send a typed JSON body#
Every unkey api action accepts --body for sending a JSON string directly to the API. This is useful for AI agents and scripts that already produce an API request body:
Explicitly passing --body selects typed body mode. The CLI decodes the value into the endpoint's generated SDK request type, then the SDK serializes that typed request. Malformed JSON is rejected locally. An explicitly empty value, including --body='', selects body mode and is rejected as malformed JSON. Request schema and business validation remain the API's responsibility.
You cannot combine --body with request-building flags. Selecting body mode waives required request-building flag checks because the typed JSON supplies the request instead.
Operational flags continue to work in body mode. Your configured root key or --root-key is still used, while --api-url and --output keep their normal behavior.
Quote the JSON so your shell passes it as one argument. Single quotes are usually the clearest choice for inline JSON in Bash:
Global Flags#
Every command accepts these flags:
| Flag | Description |
|---|---|
--root-key | Override the root key (also: UNKEY_ROOT_KEY env var) |
--api-url | Override the API base URL (default: https://api.unkey.com) |
--config | Path to config file (default: ~/.unkey/config.toml) |
--output | Output format. Use json for raw JSON |
--body | Send this JSON string as the typed request body. You cannot combine it with request-building flags. |
Help#
Every command has built-in help with descriptions, flag details, and examples: