Guide: Send an HTTP request from a flow
This page: https://commentwatchdog.com/help/http-requests/send-an-http-request-from-a-flow
Topic: HTTP requests
Time: about 5 minutes
Who can do it: Owner, Administrator or Manager
Author: https://anantgupta.xyz (Anant Gupta, founder of CommentWatchDog)
Start in the app: https://app.commentwatchdog.com/en/inbox
Result when done: Your flow sends data to another system, or reads from it, and takes the Success or Failed way.
Context: The HTTP request step calls another system's API from the middle of a conversation: look up an order, check a postcode, send a new lead to your CRM. It runs anywhere in a flow, on Instagram and Facebook. One form holds it all: the method and the address, authentication, a body, query parameters and headers, with anything you know about the person filled in through variables. A good answer takes Success; an error, a timeout or no answer takes Failed, so the person is never left waiting.

Before you start:
1. The HTTP request step comes with the flow builder, on Starter and above (and on the 7-day DM pass on Mini and Lite).
2. The step only calls out: other systems cannot call into a flow.
3. Authentication is a Bearer token, Basic auth or an API key; keys are saved encrypted and never shown again.

Steps:
Step 1 of 5: Add an HTTP request step.
Where: Open the flow on the canvas. In the Steps panel on the left, type HTTP in Search steps and drag HTTP request onto the canvas, or click it to add it after the selected step. On a phone, Add step, then HTTP request.
Link: https://app.commentwatchdog.com/en/inbox (Open the app)
Screenshot: https://commentwatchdog.com/media/shots/dm-node-http.en.webp (The HTTP request step on the canvas, its settings open on the right.)
Screenshot: https://commentwatchdog.com/media/shots/dm-node-http-phone.en.webp (The step's settings on a phone.)
You should see: The step on the canvas with two ways out, Success and Failed, and its settings open beside it.

Step 2 of 5: Choose the method and type the address.
Where: Under Address, near the top of the settings: the method on the left (GET, which opens to POST, PUT, PATCH and DELETE), then the address field, then the {x} variable button, which inserts values that change per person, for example https://api.zippopotam.us/us/{{zip}}. A variable in the address is encoded for you.
Screenshot: https://commentwatchdog.com/media/shots/dm-node-http.en.webp (The address, with the variable {{zip}} in it; the method on its left, the variable button on its right.)
Screenshot: https://commentwatchdog.com/media/shots/dm-node-http-phone.en.webp (The same on a phone.)
You should see: The step on the canvas shows the method and the address.

Step 3 of 5: Fill in what the API asks for: authentication, body, parameters, headers.
Where: The form goes on under the address, one section after another. Authentication: No auth, Bearer token, Basic auth or API key (sent in a header or the query string). Body (not for GET; a GET sends its values as query parameters): JSON with up to 40 fields, each sent as Text, Number, True/false or JSON (a dot in a key nests it), Form, Raw (JSON, plain text or XML) or None. Query parameters: up to 20 rows, added to the address as key=value. Headers: up to 20 rows; lock a row to keep its value secret. Send this row switches a row off without deleting it.
Screenshot: https://commentwatchdog.com/media/shots/dm-node-http.en.webp (Authentication, the first section under the address.)
Screenshot: https://commentwatchdog.com/media/shots/dm-node-http-phone.en.webp (The same on a phone.)
You should see: Each section fills as you go: Add a parameter and Add a header count their rows (0/20, 1/20). A key you type is saved encrypted and then reads Saved and hidden, with Replace.

Step 4 of 5: Open More options for success, the time limit and retries.
Where: More options, folded at the bottom of the form; its line shows the current choices (for example Only a 2xx answer · 8 s · Once). Counts as success: Only a 2xx answer, or Any answer (then check the status code in a Condition). Time limit: 3, 5, 8 or 10 s (8 by default). Try again on errors: Don't retry, Once or Twice, on no answer or a 5xx, only for requests safe to send twice.
Screenshot: https://commentwatchdog.com/media/shots/dm-node-http-more.en.webp (More options, at the bottom of the form, with the current choices on its line.)
Screenshot: https://commentwatchdog.com/media/shots/dm-node-http-more-phone.en.webp (The same on a phone.)
You should see: The More options line shows what you chose.

Step 5 of 5: Connect Success and Failed.
Where: Drag from the Success dot to the next step (a message that uses the answer), and from Failed to what should happen instead (tell your team, hand to a person, or a gentle message). On a phone, pick each step under Next steps, at the bottom of the settings. A Failed way with nothing connected ends the run as failed, and the bar warns you.
Screenshot: https://commentwatchdog.com/media/shots/dm-node-http.en.webp (The two ways on the step, Success and Failed, each wired to its next step.)
Screenshot: https://commentwatchdog.com/media/shots/dm-node-http-more-phone.en.webp (On a phone: Success and Failed under Next steps, each with the step it leads to.)
You should see: Both ways wired; the bar reads Ready to go live once nothing is left to fix.

If something is off:
Problem: Blocked
Fix: The address points inside a private network (or to loopback or a cloud metadata address), so it is refused for safety. Use the API's public address.
Problem: Timed out
Fix: The API took longer than the time limit under More options (10 seconds at most). The run took the Failed way.
Problem: Paused after failures
Fix: The address failed 5 times in a row, so calls to it pause for a minute, then it is tried again.
Problem: Bad address
Fix: The address is not a valid http or https link once its variables are filled in. Check the variable has a value at this point of the flow.

Common questions:
Question: Can a flow call any API?
Answer: Yes, any API reachable on the public internet with GET, POST, PUT, PATCH or DELETE, using no auth, a Bearer token, Basic auth or an API key. Addresses inside private networks are refused for safety.
Question: Can another system send data into a flow?
Answer: No. The HTTP request step only calls out from a flow; there is no incoming webhook that starts or feeds one.
Question: What is the longest an HTTP request can wait?
Answer: 10 seconds, the most the time limit allows (8 by default). People are mid-chat, so shorter is kinder.
Question: Are my API keys safe?
Answer: Auth values and any row marked secret are encrypted when you save, bound to your account, and never shown again, not even in the run history.

Related guides:
- Use the answer in your flow: https://commentwatchdog.com/help/http-requests/use-the-answer-in-your-flow
- Paste a cURL command: https://commentwatchdog.com/help/http-requests/paste-a-curl-command
- Build the request with AI: https://commentwatchdog.com/help/http-requests/build-the-request-with-ai

Plain text of this guide: https://commentwatchdog.com/help/http-requests/send-an-http-request-from-a-flow.md
All guides for assistants: https://commentwatchdog.com/help/llms.txt
