Skip to content

HTTP Steps

The HTTP steps connect FlowMint to any system with a web API: a CRM, a ticketing system, a chat webhook, a vendor’s data feed. They need no FlowMint credential; you send whatever authentication the API expects in headers.

SettingStepsWhat it doesDefault
urlAllThe address. Required.—
methodhttp_requestGET, POST, PUT, PATCH, DELETE or HEAD. Required.—
headersAllAn object of header names and values.none
bodyhttp_post, http_requestThe request body: an object, a list or text. Sent only with POST, PUT, PATCH and DELETE.—
body_formathttp_post, http_requestjson, form (URL-encoded) or raw.json
timeout_secondsAllHow long to wait.30
accept_non_2xxAllTreat any status as success instead of failing on 3xx, 4xx or 5xx.false
follow_redirectsAllFollow up to five redirects.true
verify_sslAllCheck the server’s certificate. Turn off only for a server you control.true

With body_format json, an object or list body is encoded as JSON and Content-Type: application/json is added unless you set one. With form, an object body is URL-encoded with the matching content type. With raw, text is sent as it is.

FieldWhat it holds
statusThe HTTP status code.
headersThe response headers.
bodyThe response body. When the response’s content type is JSON, the parsed data, so later steps can read {{ steps.<name>.body.items }}; otherwise the text.
duration_msHow long the request took.
{ "name": "create_ticket", "type": "http_post",
"config": {
"url": "https://tickets.example.com/api/tickets",
"auth": { "credential": "tickets", "scheme": "bearer" },
"body": {
"subject": "{{ labels.issue_type }} at {{ data.address }}",
"reporter_email": "{{ data.email }}",
"category": "{{ data.issue_type }}"
}
} }

Placeholders in body keep their type when a value is exactly one placeholder, so a list stays a list in the JSON.

Store the key once as a credential named http_<name>, then name it in the step’s auth — never type it into headers:

authSends
{ "credential": "tickets", "scheme": "bearer" }Authorization: Bearer <key> (bearer is the default)
{ "credential": "tickets", "scheme": "header", "header": "X-API-Key" }X-API-Key: <key>
{ "credential": "tickets", "scheme": "basic" }Basic sign-in; store the credential as user:password

FlowMint adds the key when the request is sent, so it is not in the workflow, its run history or the step’s output, and changing it is one PUT with no workflow edit. See Managing credentials.

A response outside 200–299 fails the step unless accept_non_2xx is on:

StatusCodeRetryable
401, 403auth_failedNo
429rate_limitedYes
Other 4xxexternal_4xxNo
5xxexternal_5xxYes
3xx, when redirects are not followedunexpectedYes
No response, timed outtimeoutYes
No response, other network errornetwork_errorYes

The error message includes the method, URL, status and the first 200 characters of the response.

  • http_get and http_post cannot change the method. Use http_request for PUT, PATCH, DELETE and HEAD.
  • A request with side effects repeats on replay. A replayed run sends every POST again.
  • A JSON response without a JSON content type comes back as text, and paths into it are empty. Check the output in the run history.