Skip to main content

Quick Checklist

1

No extra spaces

Ensure there are no leading or trailing spaces when you paste your API key. Copy it fresh — from the install command on Configure, or from unbound tools connect <TOOL_TYPE>. See Finding your API key.
2

Correct tool selected

Roo Code, Cline, Kilo Code and Custom Access each have their own key. Copy the one unbound tools connect <TOOL_TYPE> prints for that tool — another tool’s key will be rejected.
3

Not a spending block

“You’ve reached the monthly usage budget set by your organization” and “You’ve reached the spend limit set by your organization” are not key errors. Your key is fine — see Credits, Usage and Budgets.
4

Key not regenerated

If someone (including you) regenerated the key, your old key is now permanently invalid. Copy the new key from the dashboard.

”Invalid API key” in Roo Code

Invalid API key from Unbound (invalid_api_key)

Unbound rejected the key the tool presented. Work through it in this order.

1. Check the stored key

Doctor validates the key stored in ~/.unbound/config.json against the backend, so a revoked or rotated key is caught here rather than at your next tool call. If it reports the key was rejected, sign in again:

2. Check the environment variable actually loaded

Setup writes a per-tool variable — UNBOUND_CLAUDE_API_KEY for Claude Code — to one shell profile, and an already-open terminal never sees it:
Unset means you need a new terminal. The profile file is ~/.zprofile on macOS with zsh, ~/.bash_profile on macOS otherwise, ~/.zshrc on Linux with zsh, and ~/.bashrc on Linux otherwise.

3. Re-run setup for the tool

This rewrites the key, the hooks and the tool’s own configuration together:
unbound doctor --fix does the same for every tool it finds broken. On an MDM-managed device, ask your administrator to re-run the deployment instead.

”API Key Is Incorrect, But It’s Correct”

Almost always one of these:
  • Key from the wrong tool — Roo Code, Cline, Kilo Code and Custom Access each have their own key. Copy the one on that tool’s page
  • Key was recently regenerated or rotated — a teammate regenerating it, or an admin running Configure → Actions → Rotate API Keys, invalidates the old one immediately. Copy the current key from the dashboard
  • Invisible characters — some terminals and password managers add them. Type the key manually, or paste from a plain text editor
  • Left-over gateway settings — if this machine was ever set up with Unbound as the AI provider, an old ANTHROPIC_BASE_URL export or an apiKeyHelper entry in ~/.claude/settings.json can still be in play. unbound doctor flags a machine carrying both setups as Tampered; re-running unbound setup claude-code --subscription clears what Unbound wrote

How to Verify Your API Key

It checks each connected tool’s configuration, hook script and environment wiring, and validates your stored key against the backend. unbound status is the shorter version — your email, organization, role and the tools wired through Unbound on this device.

Still Not Working?

Send us:
  1. The exact error message you’re seeing (screenshot preferred)
  2. The output of unbound doctor
  3. Which tool you’re using (Claude Code, Roo Code, Cursor, etc.)
  4. Your email address associated with your Unbound account
Email support@unboundsecurity.ai.