Skip to main content
The official Next.js SDK for Unkey. Use this within your route handlers as a simple, type-safe way to verify API keys.

github.com/unkeyed/sdks/tree/main/nextjs

Install

Protecting API routes is as simple as wrapping them with the withUnkey handler:

What’s in req.unkey?

The req.unkey.data object contains the verification result:
Access these via req.unkey.data.valid, req.unkey.data.keyId, etc.
If you want to customize how withUnkey processes incoming requests, you can do so as follows:

getKey

By default, withUnkey will look for a bearer token located in the authorization header. If you want to customize this, you can do so by passing a getter in the configuration object:

onError

You can specify custom error handling. By default errors will be logged to the console, and withUnkey will return a NextResponse with status 500.

handleInvalidKey

Specify what to do if Unkey reports that your key is invalid.
Last modified on April 7, 2026