How to add an API key to a Serverless function

Oscar de la Hera Gomez
A set of flowers that represent AWS Lambda, AWS API Gateway, Typescript and Serverless. Below them sits the text "API key"

A step by step tutorial on adding an API key to a Serverless function.

The following tutorial builds off our Open Source starter project and walks you through how to create an API using an AWS Lambda function and an API Gateway through Serverless and Typescript.

Please note that this tutorial assumes that you have setup Serverless for deploying to AWS. For a comprehensive breakdown on how to do this, please follow the tutorial below.


We recommend downloading our Open Source project, checking out the tutorial/lambda-hello-world branch and carrying out the steps outlined below. All relevant changes can be found on the tutorial/api-key branch.

git clone

Step One: Update your Serverless.yml

A screenshot of the serverless.yml file showing how to add an API key, and how to apply it to a Serverless function.

First, include an API gateway key by adding it under the provider section. Please note that you must name your key - we have called it typescript-serverless-starter-key-dev as each stage should have its own key.

Subsequently, make the function private. This will let Serverless know that you want it to use an API key.

Finally, under cors, set the relevant headers in the function and set the allowCredentials to false.

Step Two: Deploy

A screenshot of terminal showing the data that API url and API key after it has successfully been deployed.

In your terminal, set the current directory to that of the serverless project and run sls deploy.

At the end of the deploy, the console will inform you of the path of your API.

Please note that this requires you to have setup AWS credentials for your Serverless client.

Step Three: Verify

A screenshot of Postman showing the successful  API call.

Verify that your API call works using the information gathered in Step 2, applying the x-api-key header for the api key that was produced.

If you would like to learn how to make an API call in Postman, use the tutorial linked below.

Any Questions

We are actively looking for feedback on how to improve this resource. Please send us a note to with any thoughts or feedback you may have.

delasign logo

Book a Free Consultation.

An icon of an email.

Click here to email us.

Fill in the details below to book a free consultation or to let us know about something else. Whatever it is, we are here to help.

How can we help you ?

Contact Details