Skip to main content
An HTTP tool sends a request to your system and gives the assistant the answer. It’s the kind you’ll use most: looking up an order, checking availability, writing a ticket.

Setting one up

A worked example

Checking a hotel reservation. URL
Headers
Parameters Response fields — the API returns a lot; the assistant only needs some of it: Now the assistant can answer “when am I arriving again?” without seeing the customer’s payment details.
Pick out only the fields you need. Sending the whole response wastes tokens on every turn and gives the assistant more chances to say something you didn’t intend.

Keeping credentials out of the prompt

Never paste an API key into a tool’s URL or a prompt. Store it in your vault and reference it as {{secret.name}}. Secrets resolve in requests only. They’re never readable by the assistant and can’t end up in anything the caller hears.

Limits

Your endpoint must be reachable from the internet. Requests to private and internal addresses are refused, so a URL pointing at localhost or an internal range won’t work — this is what stops a misconfigured tool reaching somewhere it shouldn’t.

Testing

Click Test on the tool, enter a reservation id, and check what comes back before you attach it to anything.