Setting one up
A worked example
Checking a hotel reservation. URL
Response fields — the API returns a lot; the assistant only needs some of it:
Now the assistant can answer “when am I arriving again?” without seeing the
customer’s payment details.
Keeping credentials out of the prompt
Never paste an API key into a tool’s URL or a prompt. Store it in your vault and reference it as{{secret.name}}.
Secrets resolve in requests only. They’re never readable by the assistant and
can’t end up in anything the caller hears.
Limits
Your endpoint must be reachable from the internet. Requests to private and
internal addresses are refused, so a URL pointing at
localhost or an internal
range won’t work — this is what stops a misconfigured tool reaching somewhere it
shouldn’t.