On this page
Overview
Unkey is a developer platform for API operations. It combines API-key issuance, verification and revocation with global rate limiting, permissions and RBAC, gateway routing, analytics, and audit logs, with hosted and self-hosted deployment options.
Features and best fit
Based on official documentation; not hands-on tested · Content checked:
Key features
Manage API-key lifecycle and fine-grained access control
The platform handles issuing, verifying, and revoking API keys together with per-key permissions, roles, and RBAC so access policy can move into shared API infrastructure.
Sources: [1]
Unify traffic policy with a global gateway and rate limiting
Its distributed gateway handles routing, authentication, and traffic shaping, while durable rate limits and request-level usage and latency analytics use the same platform.
Sources: [1]
Best fit
Fits Next.js APIs and public APIs that want shared key management, rate limits, and auditability
It is useful when teams want to avoid rebuilding API-key tables, rate limiting, and audit logs separately in every application.
Sources: [1]
Before adoption
Review AGPLv3 and per-package license boundaries for self-hosting
The repository license assigns packages and some directories their own licenses and applies AGPLv3 to content outside those exceptions. The README also describes the repository as source-available for forking and self-hosting under AGPL terms, so network-hosted modifications require license review.
Treat keys, root keys, and gateway policies as security boundaries
Recent component changes include root-key APIs, remote-IP policy matching, key rotation behavior, and portal-session revocation. Credential storage, rotation, auditing, and policy changes should be reviewed as security-sensitive deployment changes.
Sources: [3]
Official sources
- [1]Unkey README(2026-10-06)
- [2]Unkey repository license(2026-10-06)
- [3]Unkey control-worker 1.1.38 release(2026-10-06)
Supplemental curator note
It fits Next.js and public APIs that want shared access policy. Review root-key and credential handling, gateway policies, and AGPLv3 plus per-package license boundaries when self-hosting.
Try it in 3 steps
- 1
Get the source
git clone --depth 1 https://github.com/unkeyed/unkey.git - 2
Enter the repository
cd unkey - 3
Check the official steps
Continue with the commands in the README Installation, Quick Start, or Getting Started section.
find . -maxdepth 1 -iname 'README*' -exec sed -n '1,220p' {} \; -quit
Growth
Growth trends · Last 30 days
5,456 Stars
Trend data is still being collected.
Development activity
Last 90 days · weekly
- Commits (last 30 days)
- 237
- Open PRs
- 139
Development activity is still being collected.
Built with
Categories and tags
GitHub data
GitHub dataView detailed GitHub data
GitHub Topics
- open-source
- authentication
- authorization
- gateway
- api
- api-keys
- rate-limiter
- deployment
- Stars
- 5,456
- Forks
- 638
- Watchers
- 12
- Open issues
- 34
- Contributors
- 124
- Owner type
- Organization
- Primary language
- Go
- License
- AGPL-3.0-only
- Repository last updated
- Oct 5, 2026
Related information
Write a related articleShare a guide or use case for this OSS in Markdown. Articles are published after administrator approval.
Explore next
- Passbolt6,149 Stars
3 shared tag(s) · 1 shared category(s)
share and audit team credentials with user-owned keys and end-to-end encryption
PHP - Fusio2,119 Stars
3 shared tag(s) · 1 shared category(s)
self-host API gateway, developer portal, and SDK generation in one platform
PHP - Cosmos Server6,176 Stars
2 shared tag(s) · 2 shared category(s) · Same language
manage home-server apps, access, protection, and backups together
Go - SPIRE2,571 Stars
2 shared tag(s) · 2 shared category(s) · Same language
attest running workloads and issue short-lived SVID credentials bound to SPIFFE identities
Go - Apache APISIX17,192 Stars
2 shared tag(s) · 2 shared category(s)
centralize API routing, security, and observability in a dynamic gateway
Lua - Consul30,091 Stars
2 shared tag(s) · 1 shared category(s) · Same language
combine service discovery, health checks, service mesh, and API gateway capabilities for distributed infrastructure
Go
Report incorrect information
Tell us if any listing information is incorrect or outdated.