Skip to main content
AlonChat

API Actions

Let your agent call your own HTTPS API during a conversation — look up orders, check accounts, or send an update you configured.

API Actions#

An API Action lets your agent call your HTTPS API during a conversation. You choose the URL, method, inputs, and which part of the response the agent may use. AlonChat does not wrap the call in a fixed request body.

Create one under Agent Studio → Tools → API Actions with Create API action.

Note: This is different from project API Keys. API Actions are outbound calls your agent makes to your API. API Keys let external apps call AlonChat. Webhooks are events AlonChat sends to you.


What You Configure#

SettingWhat it controls
Name and when to useThe label in the dashboard, and when the agent should call this action
Read, Send, or AdvancedRead looks up data with GET. Send creates or updates with POST, PUT, or PATCH. Advanced adds DELETE and the fuller controls
URLA public HTTPS endpoint. Variables such as {{item_id}} can come from the conversation
ParametersDetails the agent must collect before it calls
Headers, query, and bodyThe request you design. Send and Advanced can use a JSON, text, form, XML, or multipart body
AuthenticationNone, API key, bearer token, basic auth, a signing secret, or OAuth
Response pathOptional dot path, such as data.result, when the agent should see only part of the body
TimeoutAdvanced only. 1–60 seconds, default 15 seconds
CallbackAdvanced only. Callback webhook means a later result. Accepting the request is not the finished work

The Public API test preset is only for trying the builder. Do not leave it enabled for real customer conversations.

Built-in booking, orders, and payment tools should stay on their own setup pages. Use an API Action when the system is yours.


What the Customer Sees#

ResultWhat it means
The call succeedsThe agent may use the response, or the response path you set
The call fails, times out, or is declinedNo change was confirmed. The agent should not describe the outside system as updated
The result is unclearCheck your system before the customer is asked to submit again
Callback mode accepts the requestYour API received it. The work is not finished until the later result arrives
A required input is missingThe agent asks for it. It should not send a half-filled request

A write can also require the customer to confirm first, or pause for your approval, when you turn those options on. Confirmation from the customer is still not proof that your API succeeded.


Security#

RuleWhy it matters
HTTPS onlyThe endpoint has to be a public secure URL
No local or private addressesLocalhost and private network addresses are rejected
Credentials stay on the serverStore keys in the action's authentication settings rather than pasting them into the prompt

For work that takes longer than the timeout, accept the request and finish it asynchronously. Callback mode is for that case. Do not treat the first acceptance as the completed change.