Skip to content
Agentic Workflowdocs
v0.8.2Install free

use the app / connections

Connect any API (HTTP, OpenAPI, MCP)

Pick the right credential type for an API that has no dedicated node: HTTP Request, Custom API, RSS, MCP servers and HMAC signing.

≈ 2 min Extension Web app Bearer Token Basic Auth JWT

These nodes take any credential. The Auth Type decides what AWFlow sends in the Authorization header:

Auth Type Fields Sent as
Bearer Token Bearer Token Authorization: Bearer <token>
Basic Auth Username, Password Authorization: Basic <base64 of username:password>
JWT JWT Authorization: <value>, exactly as typed. Use it for schemes like Token abc123.
OAuth2 Client ID, Client Secret Only for Google and Microsoft 365. See Connect Google.
  • The API’s documentation: it says how it expects the key (header, query or Basic Auth).
Method Use it when
Bearer token Recommended Most modern APIs: “send Authorization: Bearer YOUR_KEY”. Also MCP servers that need a login.
Basic Auth “Use your username and password”, or an API key plus secret sent as Basic Auth.
Raw header value (JWT) The API wants another scheme in Authorization, such as Token abc123, or a JWT you got elsewhere.
  1. Create a key in the service’s developer settings.

  2. Save it in AWFlow. Open Credentials and click Add Credential (or + Add Credential in the node’s Authentication field), then fill the New Credential form. In the browser side panel the form comes in two steps: tap Simple Credential (or click Continue), then fill the rest.

    The New Credential dialog for a simple credential (no app picked, so Integration App / Service reads Select an integration...): Name and Description fields, the Auth Type menu set to Bearer Token, a Bearer Token field, a note that the secret is saved locally and encrypted in this browser, and the Cancel and Create Credential buttons. The New Credential dialog for a simple credential (no app picked, so Integration App / Service reads Select an integration...): Name and Description fields, the Auth Type menu set to Bearer Token, a Bearer Token field, a note that the secret is saved locally and encrypted in this browser, and the Cancel and Create Credential buttons.

    Numbered areas in the screenshot: 1. Integration App / Service: none (Simple Credential); 2. Name; 3. Auth Type: Bearer Token; 4. Bearer Token; 5. Where the secret is stored (here, locally in this browser); 6. Create Credential.

  3. Pick it in the node: Authentication on Http Request, HTTP Request Tool and RSS Feed Read; Credential on Custom API; Authentication next to the server on MCP Client Tool.

Key in another header or in the query string? On Custom API, a Bearer Token credential is sent the way the API’s spec says (in the named header such as X-API-Key, or as a query parameter such as ?api_key=). On Http Request, add the header under the node’s headers instead, but keep in mind that values typed into a node travel with the workflow when you share it.

Signing with HMAC. The Crypto node’s HMAC Key reads the secret from a credential so it never travels with a shared workflow. Use a Bearer Token (or JWT) credential holding only the secret.

  • 401 Unauthorized. The Auth Type doesn’t match what the API expects: Bearer for Authorization: Bearer, Basic Auth for username and password, JWT for any other scheme.
  • The API says the key is malformed. You pasted Bearer … into a Bearer Token credential. Paste only the key: AWFlow adds the word.
  • 403 Forbidden. The key is valid but lacks access to this endpoint. Check its permissions in the service.
  • The MCP server shows as unavailable. The server URL is wrong or the credential was deleted. Pick it again next to the server.
Edit page

Last updated:

Was this page useful?
Ask Aria