Node reference
HTTP request
Call an API with query, body, headers, and auth
HTTP request calls a web API and returns its response. Start with a GET request that reads data before adding authentication or a request that changes remote data.
Try it step by step#
- Choose GET and enter an API URL you can access. Select JSON for a JSON endpoint; use Text when you want the response as text.
- Run once and inspect status, ok, and body. These are separate fields: the API’s returned data is inside body.
- If the API returns {"items":[{"name":"Notebook"}]}, set Iterate’s Items to {{httpRequest.output.body.items}} using the actual HTTP scope from the picker.
What to expect#
A successful JSON response might include status: 200, ok: true, and body: {"items":[{"name":"Notebook"}]}. This is an illustrative response shape; your endpoint determines the body.
Things to check#
- Query parameters go in the URL; a JSON body is sent as request content. Match the API’s documented method and fields.
- For private APIs, select Authentication and a saved HTTP credential. Literal headers and workflow values are saved with the workflow.
- Browser CORS rules may prevent access even when the URL works elsewhere. Try the Desktop runtime for APIs that do not allow browser requests.
- A non-2xx response fails this node. On failure: Continue ends this path; it does not turn the error into a response on out.
Keep learning#
Parameters#
| Setting | Default | What it does |
|---|---|---|
| Method | GET | HTTP operation required by the API. Start with GET for a read request. |
| URL | (empty) | Runs in the browser when possible. APIs that block browser CORS may require Blokboard Desktop. |
| Query parameters | [] | Named values added to the request URL as query parameters. |
| Authentication | none | Credential scheme required by the API. Choose a saved credential for private requests. |
| HTTP credential | (empty) | Stored encrypted in the Web Vault and resolved only while this node runs. |
| Username | (empty) | Username sent with the password from the selected HTTP credential. |
| API key location | header | Send the saved API key in a header or URL query parameter as required by the API. |
| API key name | x-api-key | Name of the header or query parameter that carries the API key. |
| Headers | [] | Literal values are saved with the workflow. Use Authentication for encrypted credentials. |
| Body | none | Request body format. GET and HEAD cannot send a body. |
| JSON body | (empty) | Use an exact expression such as {{request_body}} to send an object or array directly. |
| Text body | (empty) | Text sent as the request body when Body is Text. |
| Form fields | [] | Named fields encoded as application/x-www-form-urlencoded request content. |
| Timeout (ms) | 30000 | Set to 0 to wait until the workflow is stopped. |
| Response body | auto | Parse the response as JSON or text, or select automatically from its content type. |
| Maximum response (bytes) | 10485760 | Stops reading when the response exceeds this limit. |
| On failure | stop | Choose whether a failed execution stops the workflow or only ends this path. |
| Retry attempts | 0 | How many additional attempts to make after the first failure. |
Method: Choices: GET (GET), POST (POST), PUT (PUT), PATCH (PATCH), DELETE (DELETE), HEAD (HEAD), OPTIONS (OPTIONS).
Authentication: Choices: None (none), Bearer token (bearer), Basic auth (basic), API key (apiKey).
HTTP credential: Shown when authentication is not none. Select your own http connection. See connection setup.
Username: Shown when authentication is basic.
API key location: Choices: Header (header), Query parameter (query). Shown when authentication is apiKey.
API key name: Shown when authentication is apiKey.
Body: Choices: None (none), JSON (json), Text (text), Form URL encoded (form).
JSON body: Shown when bodyType is json.
Text body: Shown when bodyType is text.
Form fields: Shown when bodyType is form.
Timeout (ms): Available under More options. Limits: minimum 0.
Response body: Choices: Auto detect (auto), JSON (json), Text (text). Available under More options.
Maximum response (bytes): Available under More options. Limits: minimum 1; maximum 104857600.
On failure: Choices: Stop workflow (stop), Continue (continue). Available under More options.
Retry attempts: Available under More options. Limits: minimum 0.
Inputs#
| Port | Value | Description |
|---|---|---|
in | any | Optional workflow data available to parameter expressions. |
Outputs#
| Port | Value | Description |
|---|---|---|
out | object | HTTP status, response headers, and parsed response body. |
out fields#
| Field | Type | Description |
|---|---|---|
status | number | HTTP response status code. |
statusText | string | HTTP response status text. |
ok | boolean | Whether the response status is between 200 and 299. |
headers | object | Response headers keyed by lowercase name. |
body | unknown | Parsed JSON or text response body. |
durationMs | number | Elapsed request time in milliseconds. |