Lesson 16 / 25

HTTP Requests, Tools and Plugins

Reach outside the workflow.

Call APIs safely

The HTTP request node calls external APIs (look up an order, create a ticket) with method, URL, headers and body built from variables. Tools and plugins add ready-made integrations (search, weather, databases, custom APIs described by an OpenAPI schema) that LLM and agent nodes can use. Store credentials in Dify's secure settings or environment variables, never in prompts; set timeouts; handle error responses explicitly; and give tools the narrowest permissions possible, especially for actions that change data. Dify's node names, menus and options change between versions; check the current Dify documentation.

An HTTP node configuration

Variables inserted into a request.

method   GET
url      https://api.example.com/orders/{{#start.order_id#}}
headers  Authorization: Bearer {{#env.ORDERS_API_KEY#}}
timeout  10 s
outputs  status_code, body
next     if status_code == 200 -> code node (parse body)
         else                  -> answer "We could not look up that order right now."

Use environment variables for secrets

Reference API keys from environment or secret settings so they never appear in prompts, logs or exported DSL files.

Quick check: Where should API credentials for an HTTP node live?

  • In the end node output
  • Inside the system prompt
  • In secure environment or secret settings, not in prompts
  • In the user's message
Answer

In secure environment or secret settings, not in prompts — Keep secrets out of model-visible text.