Skip to main content

HTTP addresses

An HTTP address lets another system trigger the agent.

Creating one​

FieldWhat it defines
IdentifierThe name that appears in the address
PermanentOnly in production, and only with a publishing role
ValidityRequired in development
Limit per minuteDefault: 60
Concurrent runsDefault: 5
Maximum body sizeDefault: 256 KiB

The credential appears exactly once​

When you create the address, the response carries the credential — and that is the only time it exists outside the platform. Store it safely; after that, there is no way to retrieve it, only to generate another.

How to call it​

The caller sends the credential in the authorization header and the body with the agent's input data.

The response is immediate and is not the result: it confirms the run was created and says where to follow it. The flow never runs inside the request — an automation waiting for a human approval would not fit inside an HTTP response time.

202 → run created, with an identifier and a follow-up address

Format details in API.

The data is validated​

Unlike the other triggers, an HTTP trigger validates the input against what the agent declares: missing required fields, the wrong type, or a value outside the options are refused immediately, with no run created.

The contract for whoever integrates is therefore exactly what the agent declares.

Avoiding duplicate triggers​

The caller can send an idempotency key. Repeating the same key with the same body returns the original run instead of creating another — which makes it safe to retry the request after a network timeout.

Repeating the same key with a different body is refused.

Limits​

LimitWhat it does
Per minuteA ceiling on run creation per address
ConcurrentA ceiling on runs in flight per address
Body sizeA payload ceiling

Exceeding one of them returns a specific error, not a generic failure. Changing the idempotency key does not get around the limits.

Security​

  • The credential belongs to the address, not to your session. It gives no access to Studio or to other agents.
  • The organization is derived from the address itself — the caller never states an organization.
  • A nonexistent identifier and a wrong credential return the same response, so valid identifiers cannot be discovered by trial and error.
  • Only the credential's fingerprint is stored; not the value.

Duration​

EnvironmentBehavior
developmentAlways temporary, with a required validity
productionCan be permanent, with a publishing role

Common errors​

ResponseMeaningWhat to do
Invalid credentialA wrong credential, or a nonexistent identifierCheck both
Input refusedThe data does not match what the agent declaresAdjust the call's body
Address expiredThe temporary address lapsed or was revokedCreate another, or make it permanent in production
Body too largeAbove the limitReduce the payload
Limit reachedRate or concurrencyWait and try again

Next steps​