# HTTP steps

Source: https://docs.revoplyai.com/connect-your-systems/http-steps/

> A flow step that calls your API through a connection, keeps values from the answer and branches on success or failure.

The **Call your system** step in the flow builder makes one request through an
[API connection](/connect-your-systems/api-connections/), keeps values from the answer as
flow variables, and continues on its **success** path after a `2xx` answer or its
**Failed** path after anything else.

## The request [#the-request]

| Part             | Rules                                                                                                                                                                                                                                 |
| ---------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| Method           | `GET`, `POST`, `PUT`, `PATCH` or `DELETE`                                                                                                                                                                                             |
| Path             | Added to the connection's base URL, such as `/orders/{{vars.order_id}}`. Starts with `/`; no `.` or `..` segments, query or fragment                                                                                                  |
| Query parameters | Up to 10; names and values are percent-encoded for you                                                                                                                                                                                |
| Headers          | Up to 10, in addition to the connection's. Credentials and transport headers cannot be set: `Authorization`, `Cookie`, `Host`, `Content-Type`, `Content-Length` and similar, and anything starting `Proxy-`, `Sec-` or `X-Forwarded-` |
| Body             | `POST`, `PUT` and `PATCH` only: a JSON object or array, sent as `application/json`                                                                                                                                                    |

Values from the conversation are inserted with placeholders such as `{{vars.order_id}}`;
the builder's **Insert** menu lists what is available. Each value is escaped for where it
lands:

* in the path, it is percent-encoded. The call is not made when a value in the path comes
  out empty (`/orders/` is not the question `/orders/{{vars.order_id}}` asked) or contains
  `/`, `\` or `..`, which could walk out of the base path at a proxy that decodes it;
* in a query parameter, it is percent-encoded, and a parameter whose value comes out empty
  is left out;
* in the body, write each placeholder inside quotes (`"{{vars.order_id}}"`); the value is
  written as a JSON string, escaped.

## The answer [#the-answer]

* Up to 10 values can be kept from a JSON answer, each by a [path](/flow-triggers/sending-requests/#paths)
  such as `data.order.status`, as a variable for later steps.
* Every call also sets `vars.http_status` to the answer's status code, such as `200` or
  `404`, or leaves it empty when no answer came.
* An answer larger than 256 KB counts as a failure, and nothing is kept from it.

## Failures and retries [#failures-and-retries]

The Failed path is taken when the answer is not `2xx`, no answer comes within the
connection's timeout, the connection cannot be made, or the call is not made at all (the
connection is switched off, the account's daily allowance is used up, a path value is
empty). Add a step there so the customer is not left waiting.

A `GET` that times out, cannot connect or gets a `5xx` answer is tried once more. Other
methods are never repeated: the first attempt may have worked and only its answer been
lost.

A flow makes at most 3 calls in a row between two customer messages, within 30 seconds in
all, retries included.

## Test the request [#test-the-request]

**Test the request** in the step sends it once with sample values you type and shows the
answer, so you can tap the values to keep. Tests are real calls to your system.
