Flow builderStep

Call any API from the middle of a conversation

Start your free trial

Free for 7 days, no credit card required

Someone asks where their order is, or how fast beans reach their ZIP code. The HTTP request step (ManyChat calls it an External Request) asks your system or any API mid-chat and puts the answer in the next message.

  • Meta's official API, no password, nothing installed
  • Unlimited contacts on every plan
  • AI replies in your customer's language
  • From $29 a month
How it runs

From their answer to your API and back

Four moments inside one conversation, the Shipping check flow from start to reply.

  1. 01

    They tell you what you need

    A question earlier in the flow asks for it: a ZIP code, an order number, an email. The answer is saved as a variable.

    Anything you know about them can go in: their answers, their email, a saved field

  2. 02

    The request goes out

    The step fills the variables in, safely encoded for where they land, and calls the address from our server.

    GET, POST, PUT, PATCH or DELETE; a time limit of 3, 5, 8 or 10 seconds

  3. 03

    The answer is ready to use

    Name the response once and every field it sends back is a variable for later steps; Save to contact puts one on the person for future runs.

    Up to 20 saved values; the answer is read up to 512 KB

  4. 04

    The flow takes a way

    A good answer takes Success and the next message can say Portland. An error or a timeout takes Failed, so nobody is left waiting.

    Failed: a person, a retry, or another message

What you set

Every setting, in the panel’s words

The labels you will see in the step’s panel, what each one does, and the limit behind it.

The request

Everything an API’s docs ask for, in the fields its docs use.

MethodFive methods

GET reads something (an order, a booking), POST creates it (a lead in your CRM), PUT replaces it, PATCH changes part of it and DELETE removes it.

A GET request has no body; send values as Query parameters.

AddressAny https or http address

Paste the address from the API’s docs and drop a variable anywhere in it, like the order number in /orders/{{order_number}}.

Up to 2,000 characters.

Query parametersValues in the address

Each row is added to the address as key=value, encoded for you; switch a row off with Send this row without deleting it.

Up to 20 parameters.

HeadersHeaders

Extra lines the API asks for, like which store or language. Lock any row that holds a key and it is saved encrypted.

Up to 20 headers.

BodyJSON, form or raw

JSON fields are sent as text, a number, true/false or JSON, and a dot in a key nests it: customer.email is sent as email inside customer. Form sends fields as a web form does; Raw is JSON, plain text or XML written by hand.

Up to 40 JSON fields; a raw body up to 20,000 characters.

Paste a cURL commandBuild it from the docs

Copy the example from your API’s docs and paste it here. The method, address, headers, auth and body fill in by themselves.

Variables and keys

What changes per person goes in; what must stay secret stays sealed.

Insert a variableFour groups of variables

Contact (first name, username, email, phone), This conversation (what they last wrote, their comment, the post), Answers and saved fields, and From API calls: the fields an earlier request sent back.

Each is escaped for where it lands: URL-encoded in the address, JSON-escaped in a JSON body.

AuthenticationNo auth, Bearer, Basic or an API key

A Bearer token, a username and password, or an API key sent under the name the API chooses, in a header or the query string.

Secret: saved encrypted, never shown againSecrets are sealed

Auth values and any row marked secret are sealed with AES-256-GCM when you save, bound to your account, and opened only on our server. Nobody sees them again, not even in the run history.

A key typed anywhere, even inside a pasted cURL, is made secret on its own.

BlockedPrivate addresses refused

An address that points inside a private network, at loopback or at a cloud metadata range is refused where the connection is made, redirects included.

At most 3 redirects; your credentials are never sent on to another site.

Using the answer

Name it once, use it everywhere after.

Response nameEvery field, by name

Name the response once and every field it sends back can go into later messages, requests and Conditions as {{name.path}}, like {{order.items[0].name}}, or {{name.$status}} for the status code.

Two HTTP steps in one flow cannot share a name.

Save to contactOnto the person, for future runs

Beside each field it sent back: save it as their email, phone or name, or as a saved field on the contact (as Set field saves one). Later steps of this flow already have every field.

Up to 20 saved values per step.

Status codeStatus, headers, the whole answer

A saved value can be the status code, the whole response, one header, or any field such as data.items[0].email.

The answer is read up to 512 KB.

Fields it sent backFields from the last test

Press Send test request and every field of the answer is listed with its value, ready to insert with the variable button or copy, like {{ship.places[0].place name}}.

When it fails

Under More options. An API stumbles sometimes; the person in the chat never notices.

SuccessTwo ways out

Success is a 2xx answer; Failed is an error, a timeout or no answer. Set Counts as success to Any answer and a Condition can check the status code instead.

A Failed way with nothing wired ends the run as failed, and the builder warns you first.

Time limitYou choose how long it waits

If the API is slower than the limit, the step stops waiting and takes Failed. People are mid-chat, so shorter is kinder.

3, 5, 8 or 10 seconds, 8 by default.

Try again on errorsRetries that cannot double-charge

On a network error or a 5xx it tries again a moment later, once or twice, honouring Retry-After. Only methods that are safe to send twice retry (GET, PUT, DELETE), or a request carrying an Idempotency-Key.

At most 2 retries.

Paused after failuresA failing address rests

An address that failed 5 times in a row pauses for a minute, then is tried again, so a broken API never floods.

At most 5 calls at once per account.

Test it for real

See the real answer before it goes live

Send test request makes the real call from our server with sample values, then shows the answer, its headers and exactly what was sent.

Send test request
The real call with sample values for its variables, and which way the flow would take; then every field it sent back, listed.
What was sent
The request exactly as it left, with every secret masked.
Save to contact
Beside any field: their email, phone or name, or a saved field, for future runs.
In the app: the Shipping check’s test, 200 and its fields
Paste a cURL command

Copy it from the docs, it builds itself

Every API documents itself with a cURL example. Paste it and the method, address, headers, auth and body fill in; the key in it is sealed on the spot.

Build it
Ctrl or ⌘ + Enter builds it; anything it could not read is named.
Then add variables
Swap a typed value for {{email}} or {{name}} so each person’s own goes out.
In the app: Paste a cURL command, before Build it
In the flow

One step in a whole conversation

An HTTP request sits anywhere in a flow: after a question that collects what it needs, before a Condition that reads its answer. Wire its Failed way too, to notify the team and hand the chat to a person.

The Shipping check flow: the ZIP code goes into the request, the town comes back into the message.
The limits

The numbers behind it

Every cap the step has, in one place.

WhatThe limit
MethodsGET, POST, PUT, PATCH, DELETE
Query parameters and headersUp to 20 each
JSON bodyUp to 40 fields; a raw body up to 20,000 characters
AddressUp to 2,000 characters, variables included
Time limit3, 5, 8 or 10 seconds, 8 by default
RetriesNone, once or twice, on a network error or a 5xx
Values saved to the contactUp to 20 per step
Answer readUp to 512 KB
Redirects followedUp to 3, each checked again
Calls at onceUp to 5 per account
After 5 failures in a rowThat address pauses for a minute
Test requestsUp to 30 a minute per person
Steps in one flowUp to 60
PlanStarter and up, with the flow builder; the 7-day DM pass on Mini and Lite

All limits are CommentWatchDog’s own, from the step’s code; the plan line is from the pricing.

Not sure which API?

Say what you want, AI sets it up

Press Set it up with AI and describe the job. It searches for an official API, reads its docs, tests the request and fills the step in.

Set it up with AI
How the AI builder works, and what it costs in AI credits.
Ready services
Twelve free services it starts from, for rates, weather, holidays, postcodes and more: the ready services.
Why people switch

Using an API’s answer, without the catches

ManyChat’s External Request, against the HTTP request step, on what decides whether the answer is usable. More in the ManyChat alternative.

What decides it
ManyChat
CommentWatchDog
Using the answer
Map JSON fieldsJSON only, and nothing when the answer is not 200 OK
No mapping stepEvery field and the status code, ready after a test
Values from a test
Not while testingValues are mapped only in a live run
Every field, ready to useTest once and every field it sends back is ready to use: listed with its value, insert it anywhere, or save it to the contact from the test itself.
Signing in to an API
Typed into headersNo auth picker in its help centre
Bearer, Basic or API keySealed, never shown again

ManyChat’s help centre: “Make External Request” and “Dev Tools: Basics”, read October 2026. Logos belong to their owners.

Questions

Questions about the HTTP request step

What people ask before they connect an API.

It calls another system’s API in the middle of a conversation and uses the answer in the next steps. Look up an order’s status from the number someone types, check a ZIP code, send a new lead to your CRM, or ask a stock count, then say the result in the next message or branch on it with a Condition. It works on Instagram and Facebook, before or after the chat opens.

No. Paste a cURL example from the API’s docs and the method, address, headers, auth and body fill in by themselves, or press Set it up with AI and describe what you want in words: it finds the service, reads its docs and tests the request for you. See the AI builder.

Yes. Auth values and any row you mark secret are encrypted with AES-256-GCM when you save, bound to your account and opened only on our server. They are masked in the test’s echo, removed from stored answers, never shown again and never shown to the AI. A key typed anywhere, even inside a pasted cURL, is made secret on its own.

Give the response a name, such as order, and every field it sends back can go into later messages, requests and Conditions as {{order.status}} or {{order.items[0].name}}, or {{order.$status}} for the status code. Save to contact puts a field on the person for future runs: their email, phone or name, or a saved field, up to 20 per step.

The step waits up to your time limit (3, 5, 8 or 10 seconds, 8 by default), can try again once or twice on a network error or a 5xx, and otherwise takes its Failed way, so you can hand the chat to a person or send another message. An address that fails 5 times in a row pauses for a minute.

Yes, to any of them that gives you an API address and a key. There are no built-in integrations, so nothing connects in one click: the HTTP request step calls the service’s own API. For a CRM, use a POST, put the contact’s name, email or answers in the JSON body as variables, and add its key under Auth; see collecting leads in DMs. The step only calls out, so none of these can start a flow or send data into one.

It sends a request out, which many tools call a webhook or an External Request. Calls into a flow from another system are not supported; a flow starts from a comment, a message, a story, a DM link, a new conversation or a shared post.

It comes with the flow builder on Starter and up, and on Mini and Lite with the 7-day DM pass. There is no extra charge per request; only Set it up with AI uses AI credits.

Turn tonight's comments into conversations

Meta API approved Start your free trial

Free for 7 days, no credit card required

Call any API from a DM

Try free