HTTP Request
Calls an API from inside the run — to fetch something the test needs, or to tell your own systems what happened.
Call an external API from the workflow — fetch test data, tell your own backend what happened, drive a staging fixture.
Reach for it when
- Seeding a staging fixture before the phone touches it: create the order, then check the app shows it.
- Reading a test account's state back from your backend instead of trusting the screen.
- Posting the result somewhere the notify blocks do not reach.
Every setting this block has. A field marked only when appears once you have chosen the mode above it — those are alternatives to each other, not extra things to fill in.
- Methodstarts at GETGETPOSTPUTPATCHDELETEHEAD
- URLRequiredstarts at —
Must be http:// or https:// on the public internet — a private or link-local address is refused.
- Authenticationstarts at NoneNoneBearer tokenBasic (user + password)Custom header
- TokenRequiredwrite-only
only when Authentication = Bearer token
- UsernameRequiredstarts at —
only when Authentication = Basic (user + password)
- Passwordwrite-only
only when Authentication = Basic (user + password)
- Header nameRequiredstarts at X-API-Key
only when Authentication = Custom header
- Header valueRequiredwrite-only
only when Authentication = Custom header
- Extra headersstarts at —
One "Name: value" per line. Lines starting with # are notes.
- Bodystarts at NoneNoneJSONForm fieldsPlain text
only when Method = POST or PUT or PATCH or DELETE
- JSONstarts at —
Checked before it's sent, so a typo fails here instead of coming back as someone else's 400. Drop a whole field from the data panel and it's sent as the object it is.
only when Body = JSON
- Fieldsstarts at —
One "name = value" per line; sent form-encoded.
only when Body = Form fields
- Textstarts at —
only when Body = Plain text
- Responsestarts at Detect from content-type
Auto fills json only when the response really is JSON and really parses — an HTML error page from a proxy never becomes an empty object.
Detect from content-typeAlways JSONAlways text - Timeoutstarts at 20s
This is billed device time — the device sits idle while the call is out.
- Fail on error statusstarts at on
Treat 4xx / 5xx as a failed step. Turn off when the status is the answer (a 404 meaning "not created yet") — it's still reported as {{ $HTTP Request.json.status }}.
Say what to call
Must be http:// or https:// on the public internet. A private or link-local address is refused — including on a redirect, which is checked at every hop.
HTTP RequestSettings MethodPOSTURLRequiredhttps://staging.acme.com/api/ordersAuthenticationBearer tokenTokenSave it as a credentialwrite-onlySend a body when the method takes one
JSON is checked before it leaves, so a typo fails here with your own error instead of coming back as somebody else's 400. Drop a whole field in from the data panel and it is sent as the object it is.
POSThttps://staging.acme.com/api/ordersAuthorization: Bearer ••••••201 Created{ "id": "ord_1042", "status": "pending" }Decide what an error status means here
Fail on error status is on by default. Turn it off when the status is the answer — a 404 meaning “not created yet” is information, not a broken step. The code is still readable either way.
HTTP RequestSettings ResponseOnly parses when it really is JSONDetect from content-typeTimeoutBilled device time20sFail on error statuson
- The status code, the headers, and the body — parsed as JSON when it really is JSON.
- Reference a field from a later step, e.g. the order id you just created.
- The phone sits idle while the call is out, and that is billed. A slow API costs the full timeout on every run.
- “Detect from content-type” only fills the parsed body when the response actually parses — an HTML error page from a proxy never quietly becomes an empty object you then read a field off.
- Private addresses are refused on purpose. Reaching a service on your own network needs it to be reachable from the public internet, or a tunnel.