← Node guide
Network

HTTP Request

Calls an API from inside the run — to fetch something the test needs, or to tell your own systems what happened.

http.request
The piece

Call an external API from the workflow — fetch test data, tell your own backend what happened, drive a staging fixture.

Reach for it when

  • Seeding a staging fixture before the phone touches it: create the order, then check the app shows it.
  • Reading a test account's state back from your backend instead of trusting the screen.
  • Posting the result somewhere the notify blocks do not reach.
HTTP Request
Idle
In the bag

Every setting this block has. A field marked only when appears once you have chosen the mode above it — those are alternatives to each other, not extra things to fill in.

  • Method
    starts at GET
    GETPOSTPUTPATCHDELETEHEAD
  • URLRequired
    starts at —

    Must be http:// or https:// on the public internet — a private or link-local address is refused.

  • Authentication
    starts at None
    NoneBearer tokenBasic (user + password)Custom header
  • TokenRequired
    write-only

    only when Authentication = Bearer token

  • UsernameRequired
    starts at —

    only when Authentication = Basic (user + password)

  • Password
    write-only

    only when Authentication = Basic (user + password)

  • Header nameRequired
    starts at X-API-Key

    only when Authentication = Custom header

  • Header valueRequired
    write-only

    only when Authentication = Custom header

  • Extra headers
    starts at —

    One "Name: value" per line. Lines starting with # are notes.

  • Body
    starts at None
    NoneJSONForm fieldsPlain text

    only when Method = POST or PUT or PATCH or DELETE

  • JSON
    starts at —

    Checked before it's sent, so a typo fails here instead of coming back as someone else's 400. Drop a whole field from the data panel and it's sent as the object it is.

    only when Body = JSON

  • Fields
    starts at —

    One "name = value" per line; sent form-encoded.

    only when Body = Form fields

  • Text
    starts at —

    only when Body = Plain text

  • Response
    starts at Detect from content-type

    Auto fills json only when the response really is JSON and really parses — an HTML error page from a proxy never becomes an empty object.

    Detect from content-typeAlways JSONAlways text
  • Timeout
    starts at 20s

    This is billed device time — the device sits idle while the call is out.

  • Fail on error status
    starts at on

    Treat 4xx / 5xx as a failed step. Turn off when the status is the answer (a 404 meaning "not created yet") — it's still reported as {{ $HTTP Request.json.status }}.

Build it
  1. Say what to call

    Must be http:// or https:// on the public internet. A private or link-local address is refused — including on a redirect, which is checked at every hop.

    HTTP RequestSettings
    Method
    POST
    URLRequired
    https://staging.acme.com/api/orders
    Authentication
    Bearer token
    TokenSave it as a credential
    write-only
  2. Send a body when the method takes one

    JSON is checked before it leaves, so a typo fails here with your own error instead of coming back as somebody else's 400. Drop a whole field in from the data panel and it is sent as the object it is.

    POSThttps://staging.acme.com/api/orders
    Authorization: Bearer ••••••
    201 Created
    {
      "id": "ord_1042",
      "status": "pending"
    }
  3. Decide what an error status means here

    Fail on error status is on by default. Turn it off when the status is the answer — a 404 meaning “not created yet” is information, not a broken step. The code is still readable either way.

    HTTP RequestSettings
    ResponseOnly parses when it really is JSON
    Detect from content-type
    TimeoutBilled device time
    20s
    Fail on error status
    on
What comes out
  • The status code, the headers, and the body — parsed as JSON when it really is JSON.
  • Reference a field from a later step, e.g. the order id you just created.
Watch out
  • The phone sits idle while the call is out, and that is billed. A slow API costs the full timeout on every run.
  • “Detect from content-type” only fills the parsed body when the response actually parses — an HTML error page from a proxy never quietly becomes an empty object you then read a field off.
  • Private addresses are refused on purpose. Reaching a service on your own network needs it to be reachable from the public internet, or a tunnel.
Usually next to