CLI reference
Every command takes --json. whisk mcp serves the same commands over stdio for agents that speak MCP.
Account and context
whisk login [--profile p] [--agent name] [--no-wait|--wait] [--resume <device_code>] device-code login; the
result says all_orgs and orgs for a login for the whole account
whisk logout revoke this token
whisk whoami [--json] user, org(s), token scopes, expiry, whether the token is
bound to this device (bound_to_this_device, and the
device's name); an agent identity's name and categories
when the token is its credential
whisk account export [--out file] save everything Whisk keeps about you as JSON
(whisk-account-<date>.json here by default, mode 0600)
whisk account delete --yes delete your own account (NEEDS_HUMAN without --yes)
whisk orgs list orgs the token can see
whisk use <org>/<app> write .whisk/app.json for the current directory; when
the platform confirms the app and the remote whisk
exists, point it at the app's git_url (remote_updated)
whisk clone <org>/<app> [directory] copy an existing app's code into a new directory
whisk version · whisk update [--check] [--force] self-update from the platform with checksum
and signature verification
whisk completion <shell>Creating an app
whisk init [--template ts|py|go] [--name slug] [--no-template] whisk apps create <slug> · whisk apps list · whisk apps info · whisk apps delete <slug> --yes whisk apps deleted · whisk apps restore <id>
Doctor
whisk doctor [--json] [--fix]
Deploy
whisk deploy [--env production|preview] [--branch name] [--commit] [-m "what changed"] [--force] [--no-wait] [--json] whisk deploys list [--limit n] · whisk deploys info <id> · whisk deploys cancel <id> whisk deploys log <id> whisk rollback [<deploy-id>] [--env name] [--no-wait]
Observe
whisk status app state (running, sleeping, broken, blocked), the current
deploy (commit, when, by whom), URL, unset secrets as a
NEEDS_HUMAN block, and on a plan with package scanning one
packages line
whisk scan [--now] [--json] the live app's known vulnerable packages; --now checks again
and waits for the result
whisk logs [-f] [--since 1h] [--env] [--grep text] [--raw] SSE tail; --json for every line as data
whisk logs forwarding [test <id>] where the org's logs are also sent and how sending is going;
test sends one destination a test line
whisk traces [--since 1h] [--until t] [--env] [--slowest] [--min 500ms] [--q text] [--limit 50]
the app's traces, one line each
whisk traces show <trace-id|request-id> one trace as a waterfall of its spans
whisk errors [--since] [--query words] [--resolve id] [--ignore id] the app's error groups
whisk errors <CODE> what one platform error code means and how to fix it
whisk open [dashboard|app|deploys|logs|runs|secrets|domains|access|errors] [--no-browser]Secrets
whisk secrets list [--scope org|app] names, scope, set or unset, version, previews, consumers, last read whisk secrets declare NAME [--scope org|app] create the slot (agents use this) whisk secrets set NAME [NAME...] [--scope org|app] one link where a human pastes the values; exits 2, always whisk secrets set NAME [NAME...] --previews[=false] one link where a human shares them with previews (or stops); exits 2 whisk secrets link NAME print the dashboard URL for a human to set it (exit 0) whisk secrets versions NAME · whisk secrets rollback NAME --to N · whisk secrets delete NAME whisk secrets reads NAME [--since 30d] whisk secrets share NAME --from <app> the value that app holds becomes the business's
Domains, CDN, environments, GitHub
whisk domains add <hostname> · whisk domains verify <hostname> · whisk domains list · remove
whisk domains business add <domain> · verify · show · remove the business's own domain:
every app at <app>.<domain>
whisk cdn [status] the app's CDN: status, each hostname's route, this month's
traffic against the plan's allowance
whisk cdn on · whisk cdn off serve the app through the CDN, or directly again
whisk envs list · whisk envs start <branch> [--no-wait] · whisk envs delete preview:<branch>
whisk github [status] the app's GitHub copy: repo, status, each branch's state
whisk github repos GitHub accounts Whisk is installed on, their repositories and
which app each is linked to
whisk github link <owner/name> link the app to a repository (a person; an agent exits 2)
whisk github sync compare both sides now
whisk github unlink stop copying; nothing changes on GitHub or in Whisk
whisk github install [--no-browser] the page where a person installs Whisk on GitHub (a person;
an agent exits 2)Workflows, jobs, webhooks
whisk functions list · whisk functions graph <name> [--json] declared + observed + drift
a cron reads in its declared tz (UTC when none), next run too
whisk runs list [<function>] [--status failed|running|parked] [--since] [--event id]
newest first; <function> (or --function) for one function's
WHY: a failed run's code, "(Whisk's side)" when it was, and
the run Whisk started again in its place; "started by hand"
for a run whisk cron run started
whisk runs show <id> [--json] what started it, steps, timing, inputs/outputs (truncated),
error and whose side it was, and the re-run it links to
whisk runs replay <id> · whisk runs cancel <id> replay prints the new run
whisk events send <name> [--data '{...}' | --data @file | --data-file file|-] [--dedupe key]
test an event into the queue
whisk cron list from the manifest, with next run times and, on a plan that
spaces schedules out, the schedule each runs as
whisk cron run <function> start one run of a cron function now, as its schedule would;
prints the run id and whisk runs show <id> to follow it
(or its event id and whisk runs list --event <id>)
whisk approvals list
whisk webhooks list each source with the URL to paste into the provider
whisk webhooks add <name> --preset stripe --secret STRIPE_WEBHOOK_SECRET --handler /hooks/stripe
writes the entry into whisk.yaml; the URL exists after a push
whisk webhooks events <name> [--limit n] · whisk webhooks replay <name> <event-id>
events: newest first, with why the last delivery failed
(WHY: the handler's HTTP status and answer, or the
connection error; last_error under --json)
whisk webhooks presets list known presetsData
whisk db query "<sql>" [--env] [--database] [--limit 1000]
runs SQL on the platform and prints the last statement's rows
and what the SQL did; --file script.sql, or - for stdin
whisk db query --confirm <code> runs SQL a CONFIRM_REQUIRED preview held back
whisk db schema [--env] [--database]
tables, columns, keys and estimated row counts in one call
whisk db shell [--env] [--database] an SQL prompt over db query; asks before destructive SQL
whisk db url [--env] [--private] prints the environment's connection string, to be used within
15 minutes (expires_at); audited; developer role or above
whisk db snapshot [--env] restore point marker now; prints the whisk restore command
whisk restore --at "2026-09-07T14:13:00Z" [--swap] [--env] [--wait] self-service PITR (paid plans)
whisk restore show <id> [--wait] one restore: status, target database, error
whisk restore list the app's restores, newest first
whisk export [--wait] starts the org's export and prints its id; with --wait
follows it, or the one already running, and prints the
link when it is ready. Owners and admins
whisk export show <id> one export; once ready, a newly signed link that works for
5 minutes (url_expires_at) while the archive is kept (7 days)Local development
whisk dev [--as user@example.com] [--groups admin,finance] [--audience team|customer]
[--roles owner,developer] [--port 3000] [--status] [--down [--wipe]]
[-- <app command>]Team and org (mostly dashboard, minimal here)
whisk members list · whisk members invite <email> [--role developer] [--guest] [--name n]
whisk members remove <email>
whisk access show
whisk access grant --group <name> | --user <email> | --everyone [--audience team|customer]
whisk access revoke --group <name> | --user <email> | --everyone [--audience team|customer]
whisk deploy-keys create [--label text] a deploy token for CI; its value is shown once
whisk customers list · whisk customers invite <email> [--name n] apps with customer_identity
whisk customers block <email> · whisk customers unblock <email> · whisk customers remove <email>
whisk billing plan, usage this period, next invoice, the trial, and
for a client business, the agency that pays for it
whisk clients an agency's client businesses: standing, handed over,
live apps, problems, storage and runs
whisk clients add <name> [--contact email] [--slug s] [--yearly] [--no-free-month]
add a client business (a person; prints the payment
page when a card is needed)
whisk clients handover <client> [--contact email]
the link the client's contact accepts the business withAgent helpers
whisk skill print the skill document for the API version in use whisk errors <CODE> explain a code and its fix whisk schema print the whisk.yaml JSON schema whisk agent-token create --label "claude on laptop" [--scopes] (humans; for CI or a second agent) whisk tokens list · whisk tokens revoke <id> whisk feedback "<what happened>" [--kind bug|difficulty|idea|praise] [--code CODE] [--command c] whisk feedback send … same as whisk feedback, the name MCP clients call whisk feedback list [--status open|resolved|all] [--kind k] [--org o] [--limit n] [--cursor c] [--everyone] whisk feedback show <id> whisk feedback resolve <id> [--note "what changed"] · whisk feedback reopen <id> [--note n]
MCP server
whisk mcp [--list] serve the contract and the commands over stdio as MCP
3. Exit codes
| Code | Meaning | Agent action |
|---|---|---|
| 0 | Success | continue |
| 1 | Error from the platform or CLI | read code and fix |
| 2 | Needs a human | show the printed URL to the human, wait |
| 3 | Validation failed (doctor, manifest) | fix the listed problems, retry |
| 4 | Not authenticated or not permitted | run whisk login or ask an admin |
| 5 | Network or platform unavailable, or a deploy that failed on Whisk's side (PLATFORM_DEPLOY_FAILED) | retry with backoff; do not change the code |
| 6 | Deploy failed (build or health) | read the log excerpt, fix, redeploy |