Lesson 16 / 25
HTTP Requests, Tools and Plugins
Reach outside the workflow.
Call APIs safely
The HTTP request node calls external APIs (look up an order, create a ticket) with method, URL, headers and body built from variables. Tools and plugins add ready-made integrations (search, weather, databases, custom APIs described by an OpenAPI schema) that LLM and agent nodes can use. Store credentials in Dify's secure settings or environment variables, never in prompts; set timeouts; handle error responses explicitly; and give tools the narrowest permissions possible, especially for actions that change data. Dify's node names, menus and options change between versions; check the current Dify documentation.
An HTTP node configuration
Variables inserted into a request.
method GET
url https://api.example.com/orders/{{#start.order_id#}}
headers Authorization: Bearer {{#env.ORDERS_API_KEY#}}
timeout 10 s
outputs status_code, body
next if status_code == 200 -> code node (parse body)
else -> answer "We could not look up that order right now."Use environment variables for secrets
Reference API keys from environment or secret settings so they never appear in prompts, logs or exported DSL files.
Quick check: Where should API credentials for an HTTP node live?
- In the end node output
- Inside the system prompt
- In secure environment or secret settings, not in prompts
- In the user's message
Answer
In secure environment or secret settings, not in prompts — Keep secrets out of model-visible text.