If the external request step in a flow fails, check the address, the connection settings, the security limits and the rate window against the reason in the run log.
You added an external request step to your flow — a stock lookup, an order status, a record in your own system — and the step fails, so the flow never continues down the "Then" output. This is the only step that leaves the panel, so it has security rules and rate limits of its own. This guide helps you match the reason in the run log to the right fix.
⚠️ Note: For security, only the public internet is called. Internal and local addresses, the panel's own address and any port other than 80 and 443 are refused. These limits cannot be switched off.
You may be seeing one of these situations:
The log says the external request failed.
The log says the external request was postponed.
The request goes out but values are not written to the contact card.
It works in a test run but not live.
A concrete example: an online shop builds a step that pulls tracking numbers from its own system. The test succeeds, but live the step returns nothing. The cause is that it points at their server's local network address, which is refused for security. Calling the system through a domain reachable on the public internet makes the step work on the first try.
Read the reason in the run log
Open the run under Automations › the automation › Logs.
Find the external request event, or the one saying it failed.
Read the text on the Reason line and match it below.
Address and format errors:
"The request URL is invalid." The address could not be read. Make sure it starts with https:// and that placeholders resolve correctly.
"Only http/https addresses can be called." Another scheme was used (for example ftp://).
"Only ports 80 and 443 can be called." The address carries another port.
"The address could not be resolved." The domain is wrong or has no DNS record.
"A header value is invalid." A header contains a character that is not accepted.
Security refusals:
"A request to an internal address was refused." The address points into a private network. Use a public one.
"The panel's own address cannot be called." A flow cannot call itself.
"Stopped because the redirect went to another address." The target redirected you to a different domain; write the final address directly.
"The redirect could not be followed." The redirect chain could not be traced.
Caused by the other side:
"The external request timed out." The step's timeout was reached. Raise it (1–30 seconds) and connect a branch to the "Timed out" output.
"The server returned an error." The other system responded with an error code; check its own logs.
"The external request could not be reached." A network problem. You can raise the Retries setting; retries apply to GET requests only.
Check the connection settings
If the step uses a saved connection, the address, credentials and default headers come from portfolio settings.
Open Portfolio settings › Connections.
Find the connection and confirm the Base address starts with https://.
Compare the Authentication method with the service's documentation: None, Username and password, Bearer key, API key in a header or Key fetched from a token address.
Use the Test button to try the connection.
These log reasons point at the connection:
"Connection not found." It was deleted, or it is not enabled for this account.
"The connection's secret could not be read." Enter the key again.
"The connection's key could not be fetched." The token address returned nothing usable; check Token address and Path of the key.
"The connection's address is invalid." Correct the base address.
Check the connection's scope: All accounts or Selected accounts? If no account is picked, it does not appear in the step.
If you hit the rate limit
External requests are limited by a per-minute window on each account, which protects both the other system's quota and your account.
A flow's own requests are limited to 30 per minute.
The Test button in the editor is limited to 10 per minute.
The Test button on the Connections screen is limited to 10 per minute per portfolio.
When no slot is available, the run waits and the log shows the request as postponed. After a certain number of postponements the run ends because the request rate limit is full.
The fix: do not call out on every message; put a condition in front of the step to drop unnecessary calls.
If the response is not processed
If the request succeeds but nothing reaches the flow, look at the mappings and the branches.
Open the step and check Response mappings. Write the field name from the response exactly; you can set up to 10 mappings.
Under Branches by response, compare Path in the response with Expected value. The first matching branch is followed; if none match, the Then output is used.
Only the first 256 KB of a response is read. On very large responses the field you need may be cut off; ask the other system for a narrower response.
The "fields written" line in the log shows which contact fields were actually set.
Other known issues and limits
Test runs only make read requests. POST, PUT and DELETE are not executed in the simulator; the log says only read (GET) requests are made in a test.
The step depends on your plan. If you are told your plan does not cover this step, the portfolio owner needs to upgrade.
Keys are never written into the flow. Secrets are stored encrypted and only sent to the connection's own address; sharing a flow does not share the key.
JSON bodies escape placeholders. A quotation mark typed by a contact cannot break the body.
The timeout ceiling is 30 seconds. For longer work, take an immediate response from the other system and poll the result with a separate call.
If you have followed every step and the problem continues, contact our Support team.