Call an API with a saved key
Most APIs worth calling want a key: your shop’s order API, a supplier’s stock feed, your own accounting system. The quick way is to type the key into the step’s Headers, and that is the one thing you shouldn’t do. A key typed there is saved inside the flow. Anyone who can open the flow can read it, it’s copied every time someone duplicates the flow, and it’s written into the details of every run.
Save the key once as a connection instead, and pick it on the step. The flow then stores only which connection to use. Routario attaches the key when the step runs.
1. Save the key as a connection
Section titled “1. Save the key as a connection”- Go to Settings → Connections → Developer.
- Under Outgoing, find Credentials and click + Add connection.
- Give it a name you’ll recognise in a list, for example Stripe prod.
- Pick the Auth type the service expects, fill in its fields, and click Create.
| Auth type | What Routario sends |
|---|---|
| None | Nothing. For an open endpoint. |
| Bearer token | Authorization: Bearer <token> |
| Basic auth | Authorization: Basic …, built from the username and password |
| API key | Your key in the header you name, for example X-API-Key |
| Custom header | Any header name with any value |
The service’s own API docs say which one it uses. “Send your key as a Bearer token” means Bearer token. “Put it in the X-Api-Key header” means API key.
2. Pick it on the HTTP Fetch step
Section titled “2. Pick it on the HTTP Fetch step”Open your flow, add or open an HTTP Fetch step, and choose your connection in Authenticated connection. It’s a dropdown of the connections you saved. Leave it empty for an API that needs no sign-in.
That’s all. Fill in URL, HTTP method and any Request body as usual. The step sends the key with every request.
Worked example: read an order from your shop
Section titled “Worked example: read an order from your shop”Say your shop’s API looks orders up at https://shop.example.com/api/orders/<number> and wants a Bearer token.
- Save a Bearer token connection called Shop API with the token from your shop’s admin.
- In the flow, add HTTP Fetch:
- URL:
https://shop.example.com/api/orders/{{ trigger.order_number }} - Authenticated connection: Shop API
- Headers:
{"Accept": "application/json"}
- URL:
- Run it. The step’s
jsonoutput holds the order, ready for an Ask AI or Format step to use.
The token appears nowhere in the flow, and nowhere in its run history.
What happens at run time
Section titled “What happens at run time”- A header you type still wins. If the step’s Headers set a header the connection also sets, the step’s value is used. Names are matched regardless of case, so
authorizationreplaces the connection’sAuthorizationrather than both being sent. - A missing connection stops the step. If the saved connection has been deleted, the step fails with
connection not found: …. It never sends the request without the key: that would either be refused far from the cause, or, on an API that also accepts anonymous calls, quietly act as the wrong user. - The address is checked before the key is read. A step pointed at an address Routario refuses to call (an internal or private address) fails with
blocked by egress policy. The key is never read, so it can’t be sent there. - A signed-in request is never rendered in a browser. HTTP Fetch’s render option loads a page in a browser, which can’t carry the key. With a connection set, the step always does a plain request instead, so it doesn’t quietly fall back to calling without the key.
Already have a key typed into a flow?
Section titled “Already have a key typed into a flow?”The flow editor flags it. A step whose Headers contain a sign-in header written out in full, such as Authorization, X-API-Key or anything named like a token, secret or password, shows the warning Secret stored in this flow in the Issues panel.
It’s only a warning. The flow keeps running and nothing is changed for you, because moving a key is your call and a guess could break a working integration. To fix it:
- Save the key as a connection (step 1 above).
- Pick it in Authenticated connection.
- Delete the header from Headers and save.
A header whose value is a {{ … }} reference isn’t flagged, because in that case the key isn’t stored in the flow itself.
Where to go next
Section titled “Where to go next”- HTTP Fetch reference: every field and output.
- Keeping your automations healthy: how warnings and errors in the Issues panel work.
- Building an automation: putting steps together into a flow.