---
name: hs-crypto-troubleshooting-error-CLI-API
title: Why am I receiving a `CKR_IBM_WK_NOT_INITIALIZED` error when I use CLI or API?
description: When you use CLI or API, you receive a `CKR_IBM_WK_NOT_INITIALIZED` error message.
last-updated: 2026-07-01
---

> ## Documentation Index
> The table of contents for this documentation set is at https://cloud.ibm.com/docs/hs-crypto?format=markdown
> The index for all IBM Cloud docs is at: https://cloud.ibm.com/docs/llms.txt
> Use these files to discover more information as needed.

# Why am I receiving a `CKR_IBM_WK_NOT_INITIALIZED` error when I use CLI or API?
{: #troubleshoot-error-CLI-API}

IBM Cloud&reg; Hyper Protect Crypto Services is deprecated. As of 28 March 2026, you can't create new instances, and access to free instances will be removed. Existing premium plan instances are supported until 28 March 2027. Any instances that still exist on that date will be deleted.
{: deprecated}
{: troubleshoot}
{: support}

When you use CLI or API, you receive a `CKR_IBM_WK_NOT_INITIALIZED` error message.
{: shortdesc}

You might got an error message similar to the following message:
{: tsSymptoms}

> ibmcloud kp -i <service_instance_id> wrap <key_id>
> Wrapping key...
> FAILED
> Bad Request: rpc error: code = Unknown desc = GRPC Return Code: [0X434B525F484F53545F4D454D4F5259] GRPC Message: [Got error CKR_IBM_WK_NOT_INITIALIZED, from libep11.so in m_UnwrapKey]

When you ran the `ibmcloud tke cryptounit-compare` command, you didn't get a `Valid` confirmation on the CURRENT MASTER KEY REGISTER.
{: tsCauses}

Make sure that the HSM [master key](#x2908413){: term} is properly set.
{: tsResolve}