API connections
One of your systems as flows and the assistant reach it, its base URL, authentication, default headers and timeout.
A connection holds where your system is and how to prove the call is from you. HTTP steps and AI actions choose a connection by name and add their own path, so a URL or a credential is changed in one place. An account can have up to 10 connections.
Set them up under Integrations → API connections → Add connection.
Fields
| Field | Rules |
|---|---|
| Name | Up to 80 characters; how steps and actions pick it |
| Base URL | https:// only; no username or password, query string or #fragment; no . or .. path segments; up to 500 characters. Every call starts here, such as https://api.example.com/v1 |
| Authentication | One of the kinds below |
| Default headers | Up to 10, sent with every call, such as a store id or an API version |
| Timeout | 1–15 seconds per call, 10 by default |
The base URL must resolve to public IP addresses only; this is checked when you save it and again at every connection.
Authentication
| Kind | Sent as |
|---|---|
| None | No credential. Only for an address anyone may call. |
| Bearer token | Authorization: Bearer <token> |
| Basic | Authorization: Basic <base64 of username:password> |
| API key in a header | The key in a header you name, such as X-Api-Key |
| API key in the query | The key as a query parameter you name. Prefer a header: URLs end up in logs. |
The credential is stored encrypted and is never shown again; the dashboard shows at most its last four characters. It is added to each request last, after every template is filled in, so nothing a customer writes can replace it, and it is removed from any answer before a flow or the assistant reads it. Credentials up to 4,096 characters are accepted.
Give each connection a credential of its own, with only the permissions its steps and actions need. Revoke it in your system if it may have leaked, then replace it here.
Test, switch off, delete
- Test sends a request through the connection now and shows the answer. Tests are real calls and are limited to 10 a minute per account.
- Switch off stops every call through it: HTTP steps take their failure path and the assistant is not offered its actions. You can still test it.
- A connection used by steps or actions cannot be deleted until they stop using it.