io.usefulapi/unkey

Unkey MCP by usefulapi

Manage API keys, identities, permissions, rate-limit overrides and verification analytics.

1.11.1
Version
remote
Transport
19
Tools

Security review

Review passed

Reviewed 1d ago.

  • tools: 19 tools scanned
  • metadata: scanned

No findings.

Tools (19)

  • unkey_liveness

    Check that the Unkey API is reachable and the root key works. The only GET in the v2 surface. Unkey: GET /v2/liveness.

  • unkey_get_key

    Fetch a key's metadata by its key id — name, owner, permissions, credits, rate limits and whether it is enabled. Read-only despite being a POST. Unkey: POST /v2/keys.getKey.

  • unkey_whoami_key

    Given a plaintext API key, return which key it is and its metadata — without spending credits or recording a verification. This is the safe way to identify a key a customer sent you. Unkey: POST /v2/keys.whoami.

  • unkey_get_api

    Fetch an API namespace by id. Read-only despite being a POST. Unkey: POST /v2/apis.getApi.

  • unkey_list_api_keys

    List every key issued under one API, optionally narrowed to a single customer by externalId. Read-only despite being a POST. Unkey: POST /v2/apis.listKeys.

  • unkey_list_identities

    List identities — the end users or organisations your keys belong to. Read-only despite being a POST. Unkey: POST /v2/identities.listIdentities.

  • unkey_get_identity

    Fetch a single identity with its metadata and shared rate limits. Read-only despite being a POST. Unkey: POST /v2/identities.getIdentity.

  • unkey_list_permissions

    List the permissions defined in the workspace. Read-only despite being a POST. Unkey: POST /v2/permissions.listPermissions.

  • unkey_list_roles

    List the roles defined in the workspace. Read-only despite being a POST. Unkey: POST /v2/permissions.listRoles.

  • unkey_list_ratelimit_overrides

    List the per-identifier overrides in one rate-limit namespace. Read-only despite being a POST. Unkey: POST /v2/ratelimit.listOverrides.

  • unkey_get_ratelimit_override

    Fetch the override for one identifier in a namespace. Read-only despite being a POST. Unkey: POST /v2/ratelimit.getOverride.

  • unkey_query_verification_analytics

    Run a read-only SQL query over key-verification analytics. The query must use one of the public aliases: key_verifications_v1, key_verifications_per_minute_v1, key_verifications_per_hour_v1, key_verifications_per_day_v1 or key_verifications_per_month_v1. Physical default.* table names are rejected, and results are scoped to your workspace. Unkey: POST /v2/analytics.getVerifications.

  • unkey_create_api

    Create a new API namespace to issue keys under. Unkey: POST /v2/apis.createApi.

  • unkey_create_key

    Issue a new API key under an API. The plaintext key is returned ONCE in the response and cannot be retrieved later unless recoverable is set. Unkey: POST /v2/keys.createKey.

  • unkey_update_key

    Change a key's name, owner, metadata, expiry, roles, permissions or enabled state. Unkey: POST /v2/keys.updateKey.

  • unkey_update_key_credits

    Set, increment or decrement a key's remaining credits. Use set with no value for unlimited. Unkey: POST /v2/keys.updateCredits.

  • unkey_delete_key

    Revoke a key. By default this is a soft delete the key stops working but stays queryable; pass permanent to erase it. Unkey: POST /v2/keys.deleteKey.

  • unkey_create_identity

    Create an identity — an end user or organisation that keys and shared rate limits attach to. Unkey: POST /v2/identities.createIdentity.

  • unkey_set_ratelimit_override

    Set a custom rate limit for one identifier in a namespace — how you raise or lower a single customer's limit. Unkey: POST /v2/ratelimit.setOverride.