App-to-app calls

Apps call each other securely, with no tokens to set up.

Built on Caddy

Plans: Every plan, including the free app

What you get

  • Calls between your own apps over the platform's internal network
  • No API keys to create, share or rotate
  • The calling app named on every request
  • Calls only to the apps each app lists
  • Traffic that never leaves the platform
  • Sleeping apps woken for the call

How it works

An app lists the apps it calls under calls in its whisk.yaml. It then sends ordinary HTTP to the other app's internal address with its service token, which Whisk issues and rotates every day. A call to an app that is not on the list is refused.

Caddy, the open-source web server in front of every app, checks the token before the request arrives. The receiving app sees which app sent the request, so it can refuse callers it does not expect.

Calls suit questions that need an answer now. To read another app's tables, use a shared database. For work that can wait, the receiving app accepts the request and puts it on its own queue as a durable workflow.

Example

A building supplier runs a stock app and a separate trade quoting app. When a rep builds a quote, the quoting app asks the stock app for current levels at each branch. No key was ever created, so none can leak or expire.

For your coding agent

calls: [stock]
env: { STOCK_APP_ID: "<stock app id>" }

whisk apps info stock --json prints the ID. The app calls http://<app id>.internal.whisk:8443/<path> with Authorization: Bearer $WHISK_SERVICE_TOKEN, as the whisk.yaml reference explains.

All features