Call any API from the middle of a conversation
Free for 7 days, no credit card required
Someone asks where their order is, or how fast beans reach their ZIP code. The HTTP request step (ManyChat calls it an External Request) asks your system or any API mid-chat and puts the answer in the next message.
- Meta's official API, no password, nothing installed
- Unlimited contacts on every plan
- AI replies in your customer's language
- From $29 a month
From their answer to your API and back
Four moments inside one conversation, the Shipping check flow from start to reply.
- 01
They tell you what you need
A question earlier in the flow asks for it: a ZIP code, an order number, an email. The answer is saved as a variable.
Anything you know about them can go in: their answers, their email, a saved field
- 02
The request goes out
The step fills the variables in, safely encoded for where they land, and calls the address from our server.
GET, POST, PUT, PATCH or DELETE; a time limit of 3, 5, 8 or 10 seconds
- 03
The answer is ready to use
Name the response once and every field it sends back is a variable for later steps; Save to contact puts one on the person for future runs.
Up to 20 saved values; the answer is read up to 512 KB
- 04
The flow takes a way
A good answer takes Success and the next message can say Portland. An error or a timeout takes Failed, so nobody is left waiting.
Failed: a person, a retry, or another message
Every setting, in the panel’s words
The labels you will see in the step’s panel, what each one does, and the limit behind it.
The request
Everything an API’s docs ask for, in the fields its docs use.
- MethodFive methods
GET reads something (an order, a booking), POST creates it (a lead in your CRM), PUT replaces it, PATCH changes part of it and DELETE removes it.
A GET request has no body; send values as Query parameters.
- AddressAny https or http address
Paste the address from the API’s docs and drop a variable anywhere in it, like the order number in /orders/{{order_number}}.
Up to 2,000 characters.
- Query parametersValues in the address
Each row is added to the address as key=value, encoded for you; switch a row off with Send this row without deleting it.
Up to 20 parameters.
- HeadersHeaders
Extra lines the API asks for, like which store or language. Lock any row that holds a key and it is saved encrypted.
Up to 20 headers.
- BodyJSON, form or raw
JSON fields are sent as text, a number, true/false or JSON, and a dot in a key nests it: customer.email is sent as email inside customer. Form sends fields as a web form does; Raw is JSON, plain text or XML written by hand.
Up to 40 JSON fields; a raw body up to 20,000 characters.
- Paste a cURL commandBuild it from the docs
Copy the example from your API’s docs and paste it here. The method, address, headers, auth and body fill in by themselves.
Variables and keys
What changes per person goes in; what must stay secret stays sealed.
- Insert a variableFour groups of variables
Contact (first name, username, email, phone), This conversation (what they last wrote, their comment, the post), Answers and saved fields, and From API calls: the fields an earlier request sent back.
Each is escaped for where it lands: URL-encoded in the address, JSON-escaped in a JSON body.
- AuthenticationNo auth, Bearer, Basic or an API key
A Bearer token, a username and password, or an API key sent under the name the API chooses, in a header or the query string.
- Secret: saved encrypted, never shown againSecrets are sealed
Auth values and any row marked secret are sealed with AES-256-GCM when you save, bound to your account, and opened only on our server. Nobody sees them again, not even in the run history.
A key typed anywhere, even inside a pasted cURL, is made secret on its own.
- BlockedPrivate addresses refused
An address that points inside a private network, at loopback or at a cloud metadata range is refused where the connection is made, redirects included.
At most 3 redirects; your credentials are never sent on to another site.
Using the answer
Name it once, use it everywhere after.
- Response nameEvery field, by name
Name the response once and every field it sends back can go into later messages, requests and Conditions as {{name.path}}, like {{order.items[0].name}}, or {{name.$status}} for the status code.
Two HTTP steps in one flow cannot share a name.
- Save to contactOnto the person, for future runs
Beside each field it sent back: save it as their email, phone or name, or as a saved field on the contact (as Set field saves one). Later steps of this flow already have every field.
Up to 20 saved values per step.
- Status codeStatus, headers, the whole answer
A saved value can be the status code, the whole response, one header, or any field such as data.items[0].email.
The answer is read up to 512 KB.
- Fields it sent backFields from the last test
Press Send test request and every field of the answer is listed with its value, ready to insert with the variable button or copy, like {{ship.places[0].place name}}.
When it fails
Under More options. An API stumbles sometimes; the person in the chat never notices.
- SuccessTwo ways out
Success is a 2xx answer; Failed is an error, a timeout or no answer. Set Counts as success to Any answer and a Condition can check the status code instead.
A Failed way with nothing wired ends the run as failed, and the builder warns you first.
- Time limitYou choose how long it waits
If the API is slower than the limit, the step stops waiting and takes Failed. People are mid-chat, so shorter is kinder.
3, 5, 8 or 10 seconds, 8 by default.
- Try again on errorsRetries that cannot double-charge
On a network error or a 5xx it tries again a moment later, once or twice, honouring Retry-After. Only methods that are safe to send twice retry (GET, PUT, DELETE), or a request carrying an Idempotency-Key.
At most 2 retries.
- Paused after failuresA failing address rests
An address that failed 5 times in a row pauses for a minute, then is tried again, so a broken API never floods.
At most 5 calls at once per account.
See the real answer before it goes live
Send test request makes the real call from our server with sample values, then shows the answer, its headers and exactly what was sent.
- Send test request
- The real call with sample values for its variables, and which way the flow would take; then every field it sent back, listed.
- What was sent
- The request exactly as it left, with every secret masked.
- Save to contact
- Beside any field: their email, phone or name, or a saved field, for future runs.
97205Send test request
20023 msTakes the Success way
Fields it sent back
{{ship.$status}} 200{{ship.country}} United States Save to contact{{ship.post code}} 97205 Save to contact{{ship.places[0].place name}} Portland Save to contact{{ship.places[0].state}} Oregon Save to contact{{ship.places[0].latitude}} 45.5207 Save to contact
Insert any of these later with the variable button. Copy one to paste it yourself.
ResponseHeadersWhat was sent
Copy it from the docs, it builds itself
Every API documents itself with a cURL example. Paste it and the method, address, headers, auth and body fill in; the key in it is sealed on the spot.
- Build it
- Ctrl or ⌘ + Enter builds it; anything it could not read is named.
- Then add variables
- Swap a typed value for {{email}} or {{name}} so each person’s own goes out.
Paste a cURL command
curl -X POST https://crm.northwindcoffee.com/api/leads \
-H "Authorization: Bearer nw_live_8f2k…" \
-H "Content-Type: application/json" \
-d '{"name": "Lucía", "email": "lucia@example.com",
"source": "instagram"}'Build it
Built from your cURL. Check the fields below.
https://crm.northwindcoffee.com/api/leads- Auth
- Bearer tokenSaved and hidden
- Body
- JSON ·
name{{name}} ·email{{email}} ·sourceinstagram
One step in a whole conversation
An HTTP request sits anywhere in a flow: after a question that collects what it needs, before a Condition that reads its answer. Wire its Failed way too, to notify the team and hand the chat to a person.
The numbers behind it
Every cap the step has, in one place.
| What | The limit |
|---|---|
| Methods | GET, POST, PUT, PATCH, DELETE |
| Query parameters and headers | Up to 20 each |
| JSON body | Up to 40 fields; a raw body up to 20,000 characters |
| Address | Up to 2,000 characters, variables included |
| Time limit | 3, 5, 8 or 10 seconds, 8 by default |
| Retries | None, once or twice, on a network error or a 5xx |
| Values saved to the contact | Up to 20 per step |
| Answer read | Up to 512 KB |
| Redirects followed | Up to 3, each checked again |
| Calls at once | Up to 5 per account |
| After 5 failures in a row | That address pauses for a minute |
| Test requests | Up to 30 a minute per person |
| Steps in one flow | Up to 60 |
| Plan | Starter and up, with the flow builder; the 7-day DM pass on Mini and Lite |
All limits are CommentWatchDog’s own, from the step’s code; the plan line is from the pricing.
Say what you want, AI sets it up
Press Set it up with AI and describe the job. It searches for an official API, reads its docs, tests the request and fills the step in.
- Set it up with AI
- How the AI builder works, and what it costs in AI credits.
- Ready services
- Twelve free services it starts from, for rates, weather, holidays, postcodes and more: the ready services.
Using an API’s answer, without the catches
ManyChat’s External Request, against the HTTP request step, on what decides whether the answer is usable. More in the ManyChat alternative.
ManyChat’s help centre: “Make External Request” and “Dev Tools: Basics”, read October 2026. Logos belong to their owners.
Questions about the HTTP request step
What people ask before they connect an API.
It calls another system’s API in the middle of a conversation and uses the answer in the next steps. Look up an order’s status from the number someone types, check a ZIP code, send a new lead to your CRM, or ask a stock count, then say the result in the next message or branch on it with a Condition. It works on Instagram and Facebook, before or after the chat opens.
No. Paste a cURL example from the API’s docs and the method, address, headers, auth and body fill in by themselves, or press Set it up with AI and describe what you want in words: it finds the service, reads its docs and tests the request for you. See the AI builder.
Yes. Auth values and any row you mark secret are encrypted with AES-256-GCM when you save, bound to your account and opened only on our server. They are masked in the test’s echo, removed from stored answers, never shown again and never shown to the AI. A key typed anywhere, even inside a pasted cURL, is made secret on its own.
Give the response a name, such as order, and every field it sends back can go into later messages, requests and Conditions as {{order.status}} or {{order.items[0].name}}, or {{order.$status}} for the status code. Save to contact puts a field on the person for future runs: their email, phone or name, or a saved field, up to 20 per step.
The step waits up to your time limit (3, 5, 8 or 10 seconds, 8 by default), can try again once or twice on a network error or a 5xx, and otherwise takes its Failed way, so you can hand the chat to a person or send another message. An address that fails 5 times in a row pauses for a minute.
Yes, to any of them that gives you an API address and a key. There are no built-in integrations, so nothing connects in one click: the HTTP request step calls the service’s own API. For a CRM, use a POST, put the contact’s name, email or answers in the JSON body as variables, and add its key under Auth; see collecting leads in DMs. The step only calls out, so none of these can start a flow or send data into one.
It sends a request out, which many tools call a webhook or an External Request. Calls into a flow from another system are not supported; a flow starts from a comment, a message, a story, a DM link, a new conversation or a shared post.
It comes with the flow builder on Starter and up, and on Mini and Lite with the 7-day DM pass. There is no extra charge per request; only Set it up with AI uses AI credits.

