Skip to main content

HTTP Request Step

The HTTP Request step makes one outbound call and stores the response.

The payload

string
required
The path, or the whole URL if base_url is not set. base_url and url are joined with a / between them.
string
An origin to prefix url with. Useful when several steps share a host.
string
default:"GET"
GET, POST, PUT, PATCH, DELETE, and so on. Case is not significant.
object
The request body. JSON-encoded, and Content-Type: application/json is set automatically when it is present. The field is data, not body.
object
Query-string parameters. params is accepted as a synonym; both are merged into the URL and every value is stringified.
object
Request headers, as a flat string-to-string map.
integer
default:"30000"
Request timeout in milliseconds.
Every value is JSONPath-resolved before the call, so any of them may be pulled from an earlier step.
There are two places to set a timeout and the payload’s own timeout wins. The Timeout field under Advanced Settings applies only when the payload does not carry one, so set whichever suits you — but not both, expecting the smaller to hold.

Authentication

The Authorization tab writes an auth object into the payload:
string
A bearer token. The scheme word is prefixed automatically if the value does not already start with it.
string
An API key, sent in header_name (default Authorization).
string
HTTP basic credentials.
string
A stored OAuth connection. The step fetches a live token for it at run time and uses it as the bearer.
string
default:"Authorization"
Which header the credential goes in.
string
When the payload also carries security_schemes (an OpenAPI-shaped map, which the Integration step supplies), this names the scheme to use and it decides the placement. Without security_schemes it is the scheme word, defaulting to Bearer.
If security_schemes is present and scheme_name does not match one of its keys, no credential is attached at all and the call goes out unauthenticated — usually surfacing as a 401 that looks like a bad token rather than a missing one.

Secrets

Never paste a credential into a payload. Store it as a secret and reference it as SECRET::<name>:: — the reference is substituted with the secret’s value when the run loads the flow, so the literal never sits in the flow configuration:
The header-value field offers your secrets in a picker for exactly this. There is no secrets object to read with JSONPath — $.secrets.… resolves to nothing.

The response

The body is at .data. There is no body, no rawBody and no duration on the response.

Failure and retries

Any 4xx or 5xx fails the step, and a failed step ends the run. There is no per-step error branch: the first failure cancels everything still in flight and nothing downstream runs. A Condition step placed after an HTTP call to inspect its status code is never reached when that call fails.
Three settings under Advanced Settings are the whole of the error-handling model:
integer
Total attempts, not extra ones. Capped at 5. 1 or less means no retry.
integer
A constant wait before each retry. There is no exponential backoff and no multiplier.
integer[]
Status codes that must not trigger a retry. The name is misleading: a code listed here is still an error.
ignore_response_codes does not let the run continue. It is read only when deciding whether to retry — a listed code skips the retry loop, and the step then fails exactly as it would have anyway, ending the run. There is no setting that tolerates a 4xx or 5xx from this step.To handle an expected 404, put the call in a nested flow whose own error path returns a value the parent can read, or use an Eval step to make the request yourself.
boolean
Flattens the response into dotted keys before storing it, turning $.STEP.data.id into the key data.id.

Testing a call

The Request tab has a Send button that issues the call immediately and shows the response, and a Lookup sub-tab holding sample run data so $. paths resolve while you are testing. Two conveniences sit above the method field: Copy as cURL and Import from cURL, which is the fastest way to get a working request in from an API’s own documentation.
Editing a flow changes its draft. Publish to make the change take effect.

HTTP Request compared with an Integration step

Use the Integration step when the service is already connected to your account — it picks the action from the integration’s own catalogue, fills in the URL and method, and handles the credential. Use HTTP Request for anything else, or when you need exact control over the request.

Next Steps

Integration Step

Call a connected service instead

Map Step

Reshape the response for the next step

Variable Mapping

JSONPath reference for the payload

Flow Steps Overview

How a failure ends a run