OSS TanbouSign in with GitHub

manage API keys, rate limits, RBAC, and gateway policy on one API platform

About these scores

OSS scale score is an unbounded metric that log-compresses and weights Stars, Watchers, Forks, and Contributors. Discovery score is the current OSS scale score minus the score at discovery. Update pace is commits in the last 30 days, growth momentum is the OSS scale score difference within the recent observation window, and OSS health is a 0–100 rating based on available recency, Community Health, and release data.

Stars
5,456
Primary language
Go
License
AGPL-3.0-only
Repository last updated
Oct 5, 2026
On this page

Overview

Unkey is a developer platform for API operations. It combines API-key issuance, verification and revocation with global rate limiting, permissions and RBAC, gateway routing, analytics, and audit logs, with hosted and self-hosted deployment options.

Features and best fit

Based on official documentation; not hands-on tested · Content checked:

Key features

Manage API-key lifecycle and fine-grained access control

The platform handles issuing, verifying, and revoking API keys together with per-key permissions, roles, and RBAC so access policy can move into shared API infrastructure.

Sources: [1]

Unify traffic policy with a global gateway and rate limiting

Its distributed gateway handles routing, authentication, and traffic shaping, while durable rate limits and request-level usage and latency analytics use the same platform.

Sources: [1]

Best fit

Fits Next.js APIs and public APIs that want shared key management, rate limits, and auditability

It is useful when teams want to avoid rebuilding API-key tables, rate limiting, and audit logs separately in every application.

Sources: [1]

Before adoption

Review AGPLv3 and per-package license boundaries for self-hosting

The repository license assigns packages and some directories their own licenses and applies AGPLv3 to content outside those exceptions. The README also describes the repository as source-available for forking and self-hosting under AGPL terms, so network-hosted modifications require license review.

Sources: [2][1]

Treat keys, root keys, and gateway policies as security boundaries

Recent component changes include root-key APIs, remote-IP policy matching, key rotation behavior, and portal-session revocation. Credential storage, rotation, auditing, and policy changes should be reviewed as security-sensitive deployment changes.

Sources: [3]

Official sources

  1. [1]Unkey README(2026-10-06)
  2. [2]Unkey repository license(2026-10-06)
  3. [3]Unkey control-worker 1.1.38 release(2026-10-06)
Supplemental curator note

It fits Next.js and public APIs that want shared access policy. Review root-key and credential handling, gateway policies, and AGPLv3 plus per-package license boundaries when self-hosting.

Try it in 3 steps

  1. 1

    Get the source

    git clone --depth 1 https://github.com/unkeyed/unkey.git
  2. 2

    Enter the repository

    cd unkey
  3. 3

    Check the official steps

    Continue with the commands in the README Installation, Quick Start, or Getting Started section.

    find . -maxdepth 1 -iname 'README*' -exec sed -n '1,220p' {} \; -quit
Check the official README

Growth

Growth trends · Last 30 days

5,456 Stars

Trend data is still being collected.

Development activity

Last 90 days · weekly

Commits (last 30 days)
237
Open PRs
139

Development activity is still being collected.

Built with

Categories and tags

GitHub data

GitHub dataView detailed GitHub data

GitHub Topics

  • open-source
  • authentication
  • authorization
  • gateway
  • api
  • api-keys
  • rate-limiter
  • deployment
Stars
5,456
Forks
638
Watchers
12
Open issues
34
Contributors
124
Owner type
Organization
Primary language
Go
Repository last updated
Oct 5, 2026
Write a related article

Share a guide or use case for this OSS in Markdown. Articles are published after administrator approval.

Report incorrect information

Tell us if any listing information is incorrect or outdated.

After reading this page, do you know what to do next?