For a service Bizomate has no steps for, the HTTP Request step calls its web API. Its key is kept in Connections as an API key connection, never typed into the step or the web address. You choose how the service expects the key, and every request through the connection carries it that way.
Who can do this
Workspace Admins and Editors, on any plan — API key connections are not premium.
Before you start
Have the key from the service, and read its API documentation for how the key is sent — "Authorization: Bearer", a header such as X-API-Key, a query parameter such as api_key, or a user name and password.
Steps
- Open the dialog in either of two ways:
- On Connections, select + Add connection, then under Developer Tools select Generic API Key.
- In the designer, on an HTTP Request step, select + Add connection under Authentication. You come back to the step once it is added.
- In Connection name, type a name — for example Northwind shipping API.
- Paste the key in Key. "Stored encrypted. It is never shown again after you save."
- Optional: if the key has an end date, choose it in This key expires on · optional.
- Under Send it as ("How the service expects the key. Its API documentation says which."), choose one:
Authorization: Bearerfollowed by the key — what most APIs want. This is the default.- A header named — type the header's name, for example
X-API-Key. - A query parameter named — type the parameter's name, for example
api_key. - Basic sign-in (user and password) — type the User. "The key is sent as the password."
- Check the line under it: "Every request through this connection carries" — for example
X-API-Key: ••••a41f, or?api_key=••••a41f on the address. Only the last four characters of the key are shown. - Select Save connection.
The toast "Connection added" says "“Northwind shipping API” is ready. Every workflow in this workspace can use it."
To use it in a step:
- Open the workflow in the designer and select the HTTP Request step.
- In Authentication, choose Northwind shipping API · API key. ("None — the request goes as it is" sends no credential.)
- Under the list the step shows what it sends — "Sends X-API-Key: ••••a41f" — with Set in Connections to change it.
What happens next
- Every request the step makes carries the key as chosen.
- Authentication also lists your sign-in connections — "Consulace Outlook · Sign in with Microsoft 365" — which send "Authorization: Bearer — the Microsoft 365 sign-in, renewed as needed". "Keys live in Connections, never in the URL. Only connections this step can use are listed."
- If the step's own Headers include the header the connection sets, the connection wins: "The connection sets Authorization, so this header is not sent. Remove it, or change how the connection sends its key in Connections."
Changing it later: rename, how it is sent, or a new key
- On Connections, select the connection, then Edit in its panel. The window Edit connection opens.
- Change Connection name to rename it.
- Under Key you see "Saved 27 Sep · ends a41f". The key is not shown again. "Changing how it is sent does not show the key again. Replace it only if the service gave you a new one."
- To give a new key, select Replace key and paste it.
- Change This key expires on or Send it as if needed. If workflows use it, a note says "2 workflows use this connection. They send the key the new way from their next run."
- Select Save changes. The toast "Connection saved" confirms it.
Good to know
- There is no Test for an API key: "There is no address to test a bare key against. Run the HTTP Request step once it is set up — that is the test."
- A key shorter than 8 characters shows no ending at all, only "••••".
- Headers that belong to the request itself cannot carry a key: Host, Content-Length, Content-Type, Transfer-Encoding, Connection, Cookie, Expect and Upgrade.
- In the connections list, this kind reads API key.
If something goes wrong
| What you see | Why | What to do |
|---|---|---|
| "Give the header's name, as the service's documentation writes it." | A header named is chosen but empty. | Type the header's name. |
| "A header name is letters, digits and hyphens — X-API-Key, say." | The name has other characters, or is over 64. | Correct it. |
| "Content-Type belongs to the request itself and cannot carry a key." | A reserved header was named. | Use the header the service asks for. |
| "Give the parameter's name, as the service's documentation writes it." | A query parameter named is chosen but empty. | Type the parameter's name. |
| "A parameter name is letters, digits, hyphens and underscores — api_key, say." | The name has other characters. | Correct it. |
| "Give the user name the service signs in with." | Basic sign-in is chosen with no User. | Type the user name. |
| "Its connection no longer works. Reconnect it, choose another, or set Authentication to None." (in the step) | The chosen connection was revoked or deleted. | Reconnect it on Connections, or choose another. |
| Not saved — "That connection no longer exists." | Someone deleted it meanwhile. | Add it again. |