Connections
The service connections used by outbound request steps in your flows. Base URL, the five authentication methods, default headers, scope and testing.
Last updated: September 30, 2026
The service connections used by outbound request steps in your flows. Base URL, the five authentication methods, default headers, scope and testing.
Last updated: September 30, 2026
If a flow needs to ask your own system for a customer's order status, the panel has to know how to reach that system. Portfolio settings › Connections is where you record that once: the address, the credentials and the default headers. In the flow step you then pick only the connection and the path; no key is written into the flow. This guide covers every field on the screen.
⚠️ Owner and Admin can open this screen, and it only appears in the menu if integrations is enabled on your plan. The screen carries secret values; on a plan without it, knowing the address won't get you in.
The info box at the top defines the job: "A connection is an address and a credential for an outbound request step to use. In the step you pick only the connection and the path; no key is written into the flow."
That separation has two benefits:
The second info line lists the safeguards: "Addresses are called with internal-network protection and a timeout; secret values are stored encrypted and are only sent to the connection's own address." So the panel checks that the address you typed doesn't point at an internal network, doesn't wait forever, and never sends your secret anywhere else.
Lists your saved connections. Each row shows its name, base URL, scope and status badge (Active / Off), with Edit, Test and Delete connection buttons beside it.
With none saved, the list reads "No connections yet."
The Test button really tries the connection. Press it and it briefly says "Testing…", then reports one of three results:
Under the result it also says whether credentials were sent: "Credentials were sent." or "No authentication: the request went out without credentials." That second line is how you catch having accidentally left authentication on None.
The confirmation states the consequence: "Delete …? Steps using this connection will not run."
This differs from AI keys: a key has a fallback, a connection does not. Outbound request steps using a deleted connection simply do not run. Know which flows use it before you delete.
The section below the list, titled Add connection or, while editing, Edit connection.
This is the name the step picks it by. Keep it clear: "Order system", "Stock API", "CRM". Only this name shows in the step box; the address does not.
The service's root address, and it starts with https://. The path you type in the step is appended to it.
A concrete example: with a base URL of https://api.myshop.com/v1, you type /order/12345 as the path in the step and the call goes to https://api.myshop.com/v1/order/12345. Splitting the base URL correctly is what lets you reuse one connection with many different paths.
The list where you pick what kind of credential the service expects. Which one is stated in the service's own documentation. There are five options, each opening different fields.
None. No credentials are sent. Enough for a public endpoint.
Username and password. Opens two fields: Username and Password. The panel sends them in the standard basic authentication header.
Bearer token. Opens a single Key field. The most common method; the panel sends the key in an Authorization: Bearer … header.
API key in a header. Opens three fields:
Authorization is used.Token or ApiKey .Token fetched from a token URL. The most involved method: the panel first calls an address to obtain a temporary key, then makes the request with it. Its fields:
scope or grant_type.access_token is used.expires_in is used.Every secret field follows the same rule: stored encrypted, never shown again. Leave it blank while editing and the saved value is kept.
A list of headers to send on every request; you can add up to 10 rows. Each row takes a name and a value; to drop a row, tap Delete row next to it.
This is usually where Accept: application/json or a version header the service wants goes. There is one rule in the hint: the authentication header does not go here. Use the authentication section above for credentials; mixing the two sends the header twice and the service rejects it.
Exactly the same logic as AI keys:
A checkbox that decides whether the connection is Active or Off. Turning it off is safer than deleting: the connection stays saved, steps won't find it, but it isn't gone.
Press Add connection for a new one, or Save while editing.
Putting the authentication header in the "Default headers" list. There is a separate section for credentials; doing both breaks the request.
Including the path in the base URL. Write https://api.example.com/v1/order and then /order in the step, and the address takes the path twice.
Using an http:// address. The address must start with https.
Trying to read the key back after saving. It is never shown again.
Going live without testing. The Test button costs you a minute and saves hours of hunting.
Deleting a connection without checking your flows. Steps using a deleted connection won't run; unlike AI keys, there is no fallback.
Setting the scope to "Selected accounts" and ticking none. The connection is used nowhere.
For how an outbound request step is built, see the Flow steps section. For what happens to connections when an account moves see Moving an account to another portfolio, and for the same scope logic on AI keys see AI keys.
Was this article helpful?