HTTP Steps
The HTTP steps connect FlowMint to any system with a web API: a CRM, a
ticketing system, a chat webhook, a vendor’s data feed. They need no
FlowMint credential; you send whatever authentication the API expects in
headers.
Settings
Section titled “Settings”| Setting | Steps | What it does | Default |
|---|---|---|---|
url | All | The address. Required. | — |
method | http_request | GET, POST, PUT, PATCH, DELETE or HEAD. Required. | — |
headers | All | An object of header names and values. | none |
body | http_post, http_request | The request body: an object, a list or text. Sent only with POST, PUT, PATCH and DELETE. | — |
body_format | http_post, http_request | json, form (URL-encoded) or raw. | json |
timeout_seconds | All | How long to wait. | 30 |
accept_non_2xx | All | Treat any status as success instead of failing on 3xx, 4xx or 5xx. | false |
follow_redirects | All | Follow up to five redirects. | true |
verify_ssl | All | Check the server’s certificate. Turn off only for a server you control. | true |
With body_format json, an object or list body is encoded as JSON and
Content-Type: application/json is added unless you set one. With form,
an object body is URL-encoded with the matching content type. With raw,
text is sent as it is.
Output
Section titled “Output”| Field | What it holds |
|---|---|
status | The HTTP status code. |
headers | The response headers. |
body | The response body. When the response’s content type is JSON, the parsed data, so later steps can read {{ steps.<name>.body.items }}; otherwise the text. |
duration_ms | How long the request took. |
Example
Section titled “Example”{ "name": "create_ticket", "type": "http_post", "config": { "url": "https://tickets.example.com/api/tickets", "auth": { "credential": "tickets", "scheme": "bearer" }, "body": { "subject": "{{ labels.issue_type }} at {{ data.address }}", "reporter_email": "{{ data.email }}", "category": "{{ data.issue_type }}" } } }Placeholders in body keep their type when a value is exactly one
placeholder, so a list stays a list in the JSON.
Sending an API key
Section titled “Sending an API key”Store the key once as a credential named http_<name>, then name it in the
step’s auth — never type it into headers:
auth | Sends |
|---|---|
{ "credential": "tickets", "scheme": "bearer" } | Authorization: Bearer <key> (bearer is the default) |
{ "credential": "tickets", "scheme": "header", "header": "X-API-Key" } | X-API-Key: <key> |
{ "credential": "tickets", "scheme": "basic" } | Basic sign-in; store the credential as user:password |
FlowMint adds the key when the request is sent, so it is not in the workflow,
its run history or the step’s output, and changing it is one PUT with no
workflow edit. See Managing credentials.
Errors
Section titled “Errors”A response outside 200–299 fails the step unless accept_non_2xx is on:
| Status | Code | Retryable |
|---|---|---|
| 401, 403 | auth_failed | No |
| 429 | rate_limited | Yes |
| Other 4xx | external_4xx | No |
| 5xx | external_5xx | Yes |
| 3xx, when redirects are not followed | unexpected | Yes |
| No response, timed out | timeout | Yes |
| No response, other network error | network_error | Yes |
The error message includes the method, URL, status and the first 200 characters of the response.
Limits and common problems
Section titled “Limits and common problems”http_getandhttp_postcannot change the method. Usehttp_requestfor PUT, PATCH, DELETE and HEAD.- A request with side effects repeats on replay. A replayed run sends every POST again.
- A JSON response without a JSON content type comes back as text, and paths into it are empty. Check the output in the run history.