Workato HTTP connector: call an API with a key and JSON

Workato's HTTP connector calls any HTTP API: a Header auth connection holds the key, and Send request via HTTP POSTs a JSON body and maps the reply.

5 min readSume
All posts

The Workato HTTP connector calls any API that has no prebuilt Workato connector. Create an HTTP connection that holds the API key (the Header auth type), then add the Send request via HTTP action with the method, URL, headers and a JSON request body, and map fields from the response. For slow jobs, start the job in one recipe and catch the finished result in a second recipe with a webhook trigger.

Workato facts come from its HTTP connector, connection setup, Send request via HTTP, HTTP error handling and webhook trigger pages. Sume facts come from Create a run, Runs and results and Authentication. All were read on 2026-09-29. Sume has no Workato connector; the example is a plain HTTPS call.

How do I set up the HTTP connection with an API key?

Pick the authentication type that matches the API. For a key sent in a header, choose Header auth and add the header under Header authorization. Set the Base URL; recipes can't override it, and each action can then use a relative URL.

  • For Sume, the header is Authorization with Bearer plus your key, or x-api-key with the key. Send exactly one: a request carrying both is refused with 401 unauthorized.
  • Base URL: https://api.sume.com/.
  • Workato warns against hard-coding tokens in action fields; keep the key in the connection or a secrets manager.

How do I send a POST with a JSON body?

In Send request via HTTP, set the method to POST, enter the relative URL, and choose JSON request body as the request content type. Workato builds input fields from a sample JSON; Raw JSON request body lets you write the payload directly. Add request headers for Content-Type: application/json and an Idempotency-Key built from the record, not the clock. A Sume Format run body:

POST v1/formats/acme/product-promo/runs
Idempotency-Key: order-<Order ID>-promo-v1

{
  "instruction": "15-second vertical promo for this product.",
  "input": { "product_url": "<Product URL>" },
  "generation_spend_cap_usd": 20,
  "communication": {
    "webhook_url": "https://webhooks.workato.com/webhooks/rest/<id>/sume-run"
  }
}

What happens when the API returns an error?

The connector treats any non-2xx response as an error, which stops the job unless a Handle errors step catches it. Workato recommends branching on error_type_id or http_response.code, not on the display text. The action retries timed-out GET, HEAD, PUT and DELETE requests on its own; POST is not in that list, and Disable retries turns implicit retries off.

From Sume's Create a run and Errors pages and Workato's HTTP error handling page, read 2026-09-29.
Sume responseMeaningWhat the recipe should do
202Fresh run acceptedStore data.id
200Same key, same body: the original runTreat as success; no second charge
409 idempotency_key_in_useSame key sent twice at onceWait about a second and resend
409 idempotency_conflictSame key, different bodyStop; nothing ran
429 rate_limitedThe key's write budget is spentWait for retry-after seconds, then resend

Should I turn on Wait for response for a slow job?

Usually not. Wait for response turns the action into a long action for requests that time out or last longer than 120 seconds, with a Response timeout from 11 to 3,600 seconds. Workato marks it public beta. An API that answers with a job id right away doesn't need it: a Sume create answers 202 Accepted with the run's status_url and result_url while the work continues.

How do I get the finished result back into Workato?

Build a second recipe that starts with the Webhooks connector's New event via HTTP webhook trigger, set Webhook type to PUT/POST with JSON payload, and use its URL as communication.webhook_url. Sume POSTs the terminal receipt there once, when the run completes or fails.

  • The trigger answers 200 with {"status":"ok"} by default, and Sume counts any 2xx returned within 10 seconds as delivered.
  • The trigger doesn't process webhooks while the recipe is stopped. Sume retries up to 10 attempts; after that, fetch the run from its result_url.
  • Dedupe on request_id, which repeats on every retry.
  • Before acting on the body, re-read GET /v1/format-runs/{run_id} with the key, so a forged POST to the trigger URL can't mark work as done. A canceled run sends no webhook.

Sources

Related posts

More in Integrations

All Integrations posts

Written by Sume