> ## Documentation Index
> Fetch the complete documentation index at: https://docs.qall.io/llms.txt
> Use this file to discover all available pages before exploring further.

# HTTP tools

> Let your assistant call an API.

An HTTP tool sends a request to your system and gives the assistant the answer.
It's the kind you'll use most: looking up an order, checking availability, writing
a ticket.

## Setting one up

| Field | What it does |
| - | - |
| **URL** | Where the request goes. Can contain [variables](/variables). |
| **Method** | `GET`, `POST`, `PUT`, `PATCH` or `DELETE`. |
| **Headers** | Sent with every request. Put API keys here as `{{secret.name}}`. |
| **Body** | What to send. Use `{{input.*}}` for values the assistant collects. |
| **Parameters** | What the assistant must work out before calling, each with a description. |
| **Response fields** | Which parts of the response the assistant should see. |
| **Timeout** | How long to wait. Defaults to 5 seconds. |
| **If it fails** | What the assistant says when the request doesn't work. |

## A worked example

Checking a hotel reservation.

**URL**

```text theme={null}
https://api.example.com/reservations/{{input.reservation_id}}
```

**Headers**

```text theme={null}
Authorization: Bearer {{secret.pms_api_key}}
```

**Parameters**

| Name | Description |
| - | - |
| `reservation_id` | The booking reference, six characters, letters and digits. The caller may read it in groups or with dashes. |

**Response fields** — the API returns a lot; the assistant only needs some of it:

| Show as | From |
| - | - |
| `guest_name` | `guest.full_name` |
| `arrival` | `stay.arrival_date` |
| `room_type` | `stay.room.type` |

Now the assistant can answer "when am I arriving again?" without seeing the
customer's payment details.

<Tip>
  Pick out only the fields you need. Sending the whole response wastes tokens on
  every turn and gives the assistant more chances to say something you didn't
  intend.
</Tip>

## Keeping credentials out of the prompt

Never paste an API key into a tool's URL or a prompt. Store it in your
[vault](/organisation) and reference it as `{{secret.name}}`.

Secrets resolve in requests only. They're never readable by the assistant and
can't end up in anything the caller hears.

## Limits

| | |
| - | - |
| Timeout | 5 seconds by default |
| Response size | 64 KB |
| Redirects | Not followed |

Your endpoint must be reachable from the internet. Requests to private and
internal addresses are refused, so a URL pointing at `localhost` or an internal
range won't work — this is what stops a misconfigured tool reaching somewhere it
shouldn't.

## Testing

Click **Test** on the tool, enter a reservation id, and check what comes back
before you attach it to anything.


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.