Skip to content

Call an API with a saved key

Most APIs worth calling want a key: your shop’s order API, a supplier’s stock feed, your own accounting system. The quick way is to type the key into the step’s Headers, and that is the one thing you shouldn’t do. A key typed there is saved inside the flow. Anyone who can open the flow can read it, it’s copied every time someone duplicates the flow, and it’s written into the details of every run.

Save the key once as a connection instead, and pick it on the step. The flow then stores only which connection to use. Routario attaches the key when the step runs.

  1. Go to Settings → Connections → Developer.
  2. Under Outgoing, find Credentials and click + Add connection.
  3. Give it a name you’ll recognise in a list, for example Stripe prod.
  4. Pick the Auth type the service expects, fill in its fields, and click Create.
Auth typeWhat Routario sends
NoneNothing. For an open endpoint.
Bearer tokenAuthorization: Bearer <token>
Basic authAuthorization: Basic …, built from the username and password
API keyYour key in the header you name, for example X-API-Key
Custom headerAny header name with any value

The service’s own API docs say which one it uses. “Send your key as a Bearer token” means Bearer token. “Put it in the X-Api-Key header” means API key.

Open your flow, add or open an HTTP Fetch step, and choose your connection in Authenticated connection. It’s a dropdown of the connections you saved. Leave it empty for an API that needs no sign-in.

That’s all. Fill in URL, HTTP method and any Request body as usual. The step sends the key with every request.

Worked example: read an order from your shop

Section titled “Worked example: read an order from your shop”

Say your shop’s API looks orders up at https://shop.example.com/api/orders/<number> and wants a Bearer token.

  1. Save a Bearer token connection called Shop API with the token from your shop’s admin.
  2. In the flow, add HTTP Fetch:
    • URL: https://shop.example.com/api/orders/{{ trigger.order_number }}
    • Authenticated connection: Shop API
    • Headers: {"Accept": "application/json"}
  3. Run it. The step’s json output holds the order, ready for an Ask AI or Format step to use.

The token appears nowhere in the flow, and nowhere in its run history.

  • A header you type still wins. If the step’s Headers set a header the connection also sets, the step’s value is used. Names are matched regardless of case, so authorization replaces the connection’s Authorization rather than both being sent.
  • A missing connection stops the step. If the saved connection has been deleted, the step fails with connection not found: …. It never sends the request without the key: that would either be refused far from the cause, or, on an API that also accepts anonymous calls, quietly act as the wrong user.
  • The address is checked before the key is read. A step pointed at an address Routario refuses to call (an internal or private address) fails with blocked by egress policy. The key is never read, so it can’t be sent there.
  • A signed-in request is never rendered in a browser. HTTP Fetch’s render option loads a page in a browser, which can’t carry the key. With a connection set, the step always does a plain request instead, so it doesn’t quietly fall back to calling without the key.

The flow editor flags it. A step whose Headers contain a sign-in header written out in full, such as Authorization, X-API-Key or anything named like a token, secret or password, shows the warning Secret stored in this flow in the Issues panel.

It’s only a warning. The flow keeps running and nothing is changed for you, because moving a key is your call and a guess could break a working integration. To fix it:

  1. Save the key as a connection (step 1 above).
  2. Pick it in Authenticated connection.
  3. Delete the header from Headers and save.

A header whose value is a {{ … }} reference isn’t flagged, because in that case the key isn’t stored in the flow itself.