Skip to main content
Roberty Studio
RPAAPI

Create API client

Create API client

Sets up a reusable API client: client certificate (mTLS), certificate authority (CA), base URL, default headers and OAuth2 authentication. API Request actions that select this client use this configuration, with no need to repeat it in every request.


Options​

Client certificate (mTLS)​

Use it when the API requires the client to identify itself with a digital certificate (mutual TLS), common in banking, government and business-to-business integrations.

Certificate file path (.pfx)​

Enter the path of the certificate file in PKCS#12 format (.pfx or .p12), which bundles the certificate and its private key. The file must exist on the device that runs the robot.

Certificate password​

Enter the password that protects the certificate file.

CA file path (optional)​

Enter the path of the server's certificate authority (CA) certificate. Only needed when the server uses a private or self-signed certificate authority.

Default settings​

Base URL​

Enter the common beginning of the API addresses, for example https://api.partner.com/v1. API Request actions that use this client can send just the path (e.g. /orders).

Default headers​

Enter, as code, the headers sent in every request that uses this client. The code must return the headers, as an object or new Headers(...):

js
return {
"Accept": "application/json",
}

Authentication (OAuth2 client credentials)​

Fill it in when the API uses the OAuth2 client credentials flow. The client obtains the access token on its own and sends it in the Authorization header of each request, so there is no need to build that header by hand.

Token URL​

Enter the address that issues the access token. Authentication is only configured when this field is filled in.

Client ID​

Enter the client identifier provided by the API provider.

Client secret​

Enter the client secret provided by the API provider.

Scope (optional)​

Enter the requested scopes, when the provider requires them.

Audience (optional)​

Enter the token audience, when the provider requires it.

Send credentials in​

Select how the Client ID and Client secret are sent when requesting the token:

  • Authorization header (Basic) — default, the most common.
  • Request body — for providers that expect client_id and client_secret in the body.

Returns​

This action has no output fields to select. The created client is used by the API client (optional) field of the API Request action.

Usage example​

  1. Add the Create API client action at the beginning of the flow, with the certificate, the base URL https://api.partner.com/v1 and the authentication data.
  2. Add an API Request after it, select the client in the API client (optional) field and enter just the path /orders in the URL.
  3. Repeat step 2 for the other calls to the same API — all of them reuse the certificate, the headers and the token.

Rules and Conditions​

  • The action must be in the same flow as the requests that use it, and before them.
  • The certificate and CA files are read on the device that runs the robot.
  • The certificate is validated when the client is created: a missing path, a corrupt file or a wrong password make this action fail, not the first request.
  • With the token URL filled in, the client authenticates right on creation. If the provider rejects the credentials or the response has no access_token, this action fails.
  • The token is renewed automatically shortly before it expires. If the API responds 401, the client authenticates again and retries the request once.
  • When the same header appears in more than one place, the most specific wins: client default headers < authentication token < headers of the request itself. Header names are case-insensitive.
  • The client configuration, including the certificate password and the Client secret, is available in actions["action-id"] during the execution. Avoid writing this value to logs, and keep the password and the Client secret in password parameters instead of typing them in the action.