HTTP addresses
An HTTP address lets another system trigger the agent.
Creating one
| Field | What it defines |
|---|---|
| Identifier | The name that appears in the address |
| Permanent | Only in production, and only with a publishing role |
| Validity | Required in development |
| Limit per minute | Default: 60 |
| Concurrent runs | Default: 5 |
| Maximum body size | Default: 256 KiB |
The credential appears exactly once
When you create the address, the response carries the credential — and that is the only time it exists outside the platform. Store it safely; after that, there is no way to retrieve it, only to generate another.
How to call it
The caller sends the credential in the authorization header and the body with the agent's input data.
The response is immediate and is not the result: it confirms the run was created and says where to follow it. The flow never runs inside the request — an automation waiting for a human approval would not fit inside an HTTP response time.
202 → run created, with an identifier and a follow-up address
Format details in API.
The data is validated
Unlike the other triggers, an HTTP trigger validates the input against what the agent declares: missing required fields, the wrong type, or a value outside the options are refused immediately, with no run created.
The contract for whoever integrates is therefore exactly what the agent declares.
Avoiding duplicate triggers
The caller can send an idempotency key. Repeating the same key with the same body returns the original run instead of creating another — which makes it safe to retry the request after a network timeout.
Repeating the same key with a different body is refused.
Limits
| Limit | What it does |
|---|---|
| Per minute | A ceiling on run creation per address |
| Concurrent | A ceiling on runs in flight per address |
| Body size | A payload ceiling |
Exceeding one of them returns a specific error, not a generic failure. Changing the idempotency key does not get around the limits.
Security
- The credential belongs to the address, not to your session. It gives no access to Studio or to other agents.
- The organization is derived from the address itself — the caller never states an organization.
- A nonexistent identifier and a wrong credential return the same response, so valid identifiers cannot be discovered by trial and error.
- Only the credential's fingerprint is stored; not the value.
Duration
| Environment | Behavior |
|---|---|
development | Always temporary, with a required validity |
production | Can be permanent, with a publishing role |
Common errors
| Response | Meaning | What to do |
|---|---|---|
| Invalid credential | A wrong credential, or a nonexistent identifier | Check both |
| Input refused | The data does not match what the agent declares | Adjust the call's body |
| Address expired | The temporary address lapsed or was revoked | Create another, or make it permanent in production |
| Body too large | Above the limit | Reduce the payload |
| Limit reached | Rate or concurrency | Wait and try again |
Next steps
Was this page helpful?
Report a problem on this pageDo not send passwords, keys, tokens, or customer data.