Create API client
Create API client
Sets up a reusable API client: client certificate (mTLS), certificate authority (CA), base URL, default headers and OAuth2 authentication. API Request actions that select this client use this configuration, with no need to repeat it in every request.
Options
Client certificate (mTLS)
Use it when the API requires the client to identify itself with a digital certificate (mutual TLS), common in banking, government and business-to-business integrations.
Certificate file path (.pfx)
Enter the path of the certificate file in PKCS#12 format (.pfx or .p12), which bundles the certificate and its private key. The file must exist on the device that runs the robot.
Certificate password
Enter the password that protects the certificate file.
CA file path (optional)
Enter the path of the server's certificate authority (CA) certificate. Only needed when the server uses a private or self-signed certificate authority.
Default settings
Base URL
Enter the common beginning of the API addresses, for example https://api.partner.com/v1. API Request actions that use this client can send just the path (e.g. /orders).
Default headers
Enter, as code, the headers sent in every request that uses this client. The code must return the headers, as an object or new Headers(...):
return {
"Accept": "application/json",
}
Authentication (OAuth2 client credentials)
Fill it in when the API uses the OAuth2 client credentials flow. The client obtains the access token on its own and sends it in the Authorization header of each request, so there is no need to build that header by hand.
Token URL
Enter the address that issues the access token. Authentication is only configured when this field is filled in.
Client ID
Enter the client identifier provided by the API provider.
Client secret
Enter the client secret provided by the API provider.
Scope (optional)
Enter the requested scopes, when the provider requires them.
Audience (optional)
Enter the token audience, when the provider requires it.
Send credentials in
Select how the Client ID and Client secret are sent when requesting the token:
- Authorization header (Basic) — default, the most common.
- Request body — for providers that expect
client_idandclient_secretin the body.
Returns
This action has no output fields to select. The created client is used by the API client (optional) field of the API Request action.
Usage example
- Add the Create API client action at the beginning of the flow, with the certificate, the base URL
https://api.partner.com/v1and the authentication data. - Add an API Request after it, select the client in the API client (optional) field and enter just the path
/ordersin the URL. - Repeat step 2 for the other calls to the same API — all of them reuse the certificate, the headers and the token.
Rules and Conditions
- The action must be in the same flow as the requests that use it, and before them.
- The certificate and CA files are read on the device that runs the robot.
- The certificate is validated when the client is created: a missing path, a corrupt file or a wrong password make this action fail, not the first request.
- With the token URL filled in, the client authenticates right on creation. If the provider rejects the credentials or the response has no
access_token, this action fails. - The token is renewed automatically shortly before it expires. If the API responds
401, the client authenticates again and retries the request once. - When the same header appears in more than one place, the most specific wins: client default headers < authentication token < headers of the request itself. Header names are case-insensitive.
- The client configuration, including the certificate password and the Client secret, is available in
actions["action-id"]during the execution. Avoid writing this value to logs, and keep the password and the Client secret in password parameters instead of typing them in the action.