ProductUnkey
Websiteunkey.com
CategoryDeveloper Infrastructure / API Management
Key FeatureAPI key creation, verification, and rate limiting
PricingFree tier (1,000 keys, 2,500 verifications/month), Pro from $25/month
Open SourceYes

What Is Unkey?

Unkey is an API key management platform. You create API keys through the Unkey API, your users include those keys in their requests, and Unkey verifies them at the edge with sub-millisecond latency. It also handles rate limiting, usage tracking, key expiration, and temporary key disabling.

Most API products build key management in-house: a keys table, a middleware that hashes and compares, manual rate limiting logic, and a dashboard to manage it all. Unkey replaces that entire layer. Your API calls Unkey to verify a key, gets back the key’s metadata and rate limit status, and serves the response. The verification happens at edge locations globally, so the latency overhead is negligible.

Key Features

API Key Lifecycle

Create keys with metadata (owner ID, permissions, expiration date). Keys can be temporary, limited-use, or permanent. Revoke or disable keys instantly. The dashboard shows all active keys, their usage, and when they were last used.

Edge Verification

Key verification runs at edge locations close to the user. A verification call returns in under a millisecond from the nearest edge, which means your API doesn’t take a latency hit for checking keys. The response includes the key’s metadata, remaining rate limit, and validity status.

Rate Limiting

Attach rate limits to individual keys or key groups. Unkey tracks usage and enforces limits at the edge. When a key exceeds its limit, the verification response says so, and your API can return a 429. No Redis setup, no sliding window implementation, no distributed counter coordination.

Usage Analytics

Track how each key is being used: request volume, endpoints hit, rate limit events. This data feeds into billing (charge per verification), customer support (see exactly what a user’s key did), and abuse detection (find keys with unusual patterns).

Who Is This For?

Pros

  • Sub-millisecond edge verification
  • Rate limiting without Redis or custom infrastructure
  • Open source and self-hostable
  • Rich key metadata (permissions, expiration, owner)
  • Usage analytics per key
  • SDKs for TypeScript, Go, Python

Cons

  • External dependency on critical path (key verification)
  • Free tier limited to 2,500 verifications/month
  • Newer platform (less battle-tested than AWS API Gateway)
  • No built-in billing integration
  • Self-hosting requires Cloudflare Workers

Verdict

API key management is infrastructure that every API product needs and nobody wants to build. Hashing keys, tracking usage, enforcing rate limits, building a management dashboard — it’s weeks of work that doesn’t differentiate your product. Unkey eliminates that work and does it faster than most homegrown solutions (edge verification is hard to replicate in-house).

The main concern is adding an external service to the critical path of every API request. If Unkey’s edge goes down, your API can’t verify keys. The self-hosting option mitigates this if you need that level of control. For most API startups, the trade-off of outsourcing key management for faster shipping and better performance is straightforward.

Build an API or infrastructure tool?

Get reviewed and linked from our 27-site network. Placements live in 48 hours.

See Packages