Skip to main content

@unkey/nextjs

Use the @unkey/nextjs SDK to protect Next.js API routes and server actions with Unkey API key authentication. Includes withUnkey wrapper.
2 min read

The official Next.js SDK for Unkey. Use this within your route handlers as a simple, type-safe way to verify API keys.

github.com/unkeyed/sdks/tree/main/nextjs

Install#

Protecting API routes is as simple as wrapping them with the withUnkey handler:

What's in req.unkey?#

The req.unkey.data object contains the verification result:

FieldTypeDescription
validbooleanWhether the key passed all checks
codestringStatus code (VALID, NOT_FOUND, RATE_LIMITED, etc.)
keyIdstringThe key's unique identifier
namestring?Human-readable name of the key
metaobject?Custom metadata associated with the key
expiresnumber?Unix timestamp (in milliseconds) when the key will expire (if set)
creditsnumber?Remaining uses (if usage limits set)
enabledbooleanWhether the key is enabled
rolesstring[]?Roles attached to the key
permissionsstring[]?Permissions attached to the key
identityobject?Identity info if externalId was set when creating the key
ratelimitsobject[]?Rate limit states (if rate limiting configured)
Note

Access these via req.unkey.data.valid, req.unkey.data.keyId, etc.

If you want to customize how withUnkey processes incoming requests, you can do so as follows:

getKey#

By default, withUnkey will look for a bearer token located in the authorization header. If you want to customize this, you can do so by passing a getter in the configuration object:

onError#

You can specify custom error handling. By default errors will be logged to the console, and withUnkey will return a NextResponse with status 500.

handleInvalidKey#

Specify what to do if Unkey reports that your key is invalid.