OpenWhisk - Credentials

The Serverless Framework needs access to account credentials for your OpenWhisk provider so that it can create and manage resources on your behalf.

OpenWhisk is an open-source serverless platform. This means you can either choose to run the platform yourself or choose to use a hosted provider's instance.

Here we'll provide setup instructions for both options, just pick the one that you're using.

Register with IBM Cloud Functions

IBM's Cloud platform provides a hosted serverless solution (IBM Cloud Functions) based upon Apache OpenWhisk.

Here's how to get started…

IBM Cloud comes with a lite account that does not need credit card details to register. Lite accounts provide free access to certain platform services and do not expire after a limited time period.

All IBM Cloud users get access to the Free Tier for IBM Cloud Functions. This includes 400,000 GB-seconds of serverless function compute time per month.

Additional execution time is charged at $0.000017 per GB-second of execution, rounded to the nearest 100ms.

Install the IBM Cloud CLI

Following the instructions on this page to download and install the IBM Cloud CLI.

On Linux, you can run this command:

curl -fsSL | sh

On OS X, you can run this command:

curl -fsSL | sh

Install the IBM Cloud Functions Plugin

ibmcloud plugin install Cloud-Functions -r Bluemix

Authenticate with the CLI

Log into the CLI to create local authentication credentials. The framework plugin automatically uses these credentials when interacting with IBM Cloud Functions.


Replace <..> values with your platform region endpoint, account organisation and space.

For example....

ibmcloud login -a -o -s dev

After logging into the CLI, run the following command to populate the ~/.wskprops file with credentials needed to run serverless commands:

ibmcloud wsk property get --auth


Cloud Functions is available with the following regions US-South (, London (, Frankfurt ( Use the appropriate API endpoint to target Cloud Functions in that region.

Organisations and Spaces

Organisations and spaces for your account can be viewed on this page:

Accounts normally have a default organisation using the account email address. Default space name is usually dev.

After running the login command, authentication credentials will be stored in the .wskprops file under your home directory.

Register with OpenWhisk platform (Self-Hosted)

Following the Quick Start guide will let you run the platform locally using a Virtual Machine.

  • Download and install Vagrant for your platform.
  • Run the following commands to retrieve, build and start an instance of the platform.
# Clone openwhisk
git clone --depth=1

# Change directory to tools/vagrant
cd openwhisk/tools/vagrant

# Run script to create vm and run hello action

This platform will now be running inside a virtual machine at the following IP address:

Please note: If you are using a self-hosted platform, the ignore_certs property in serverless.yaml needs to be true. This allows the client to be used against local deployments of OpenWhisk with a self-signed certificate.

service: testing
  name: openwhisk
  ignore_certs: true
functions: ...

Access Account Credentials

The default environment has a guest account configured with the authentication key available here:

Use the address as the apihost value needed below.

(optional) Install command-line utility

Building OpenWhisk from a cloned repository will result in the generation of the command line interface in openwhisk/bin/go-cli/. The default executable in this location will run on the operating system and CPU architecture on which it was built.

Executables for other operating system, and CPU architectures are located in the following directories: openwhisk/bin/go-cli/macopenwhisk/bin/go-cli/linuxopenwhisk/bin/go-cli/windows.

Download and install the correct binary into a location in your shell path.

Using Account Credentials

You can configure the Serverless Framework to use your OpenWhisk credentials in a few ways:

IBM Cloud Functions

After logging into the CLI, run the following command to populate the ~/.wskprops file with credentials needed to run serverless commands:

ibmcloud wsk property get --auth

With this file available, the provider plugin will automatically read those credentials and you don't need to do anything else!

Environment Variables Setup

Access credentials can be provided as environment variables.

# mandatory parameters
export OW_AUTH=<your-key-here>
export OW_APIHOST=<your-api-host>
# optional parameters
export OW_APIGW_ACCESS_TOKEN=<your-access-token>
# OW_AUTH, OW_APIHOST and OW_APIGW_ACCESS_TOKEN are now available for serverless to use
serverless deploy

Using Configuration File

Credentials can be stored in a local configuration file, using either the CLI or manually creating the file.

Setup with the wsk cli

If you are using a self-hosted platform and have followed the instructions above to install the wsk command-line utility, run the following command to create the configuration file.

$ wsk property set --apihost PLATFORM_API_HOST --auth USER_AUTH_KEY

Credentials are stored in ~/.wskprops, which you can edit directly if needed.

Edit file manually

The following configuration values should be stored in a new file (.wskprops) in your home directory. Replace the PLATFORM_API_HOST, USER_AUTH_KEY and (optionally) ACCESS_TOKEN values will the credentials from above.

Go to Github