API Actions
Let your agent call your own HTTPS API during a conversation — look up orders, check accounts, or send an update you configured.
API Actions#
An API Action lets your agent call your HTTPS API during a conversation. You choose the URL, method, inputs, and which part of the response the agent may use. AlonChat does not wrap the call in a fixed request body.
Create one under Agent Studio → Tools → API Actions with Create API action.
Note: This is different from project API Keys. API Actions are outbound calls your agent makes to your API. API Keys let external apps call AlonChat. Webhooks are events AlonChat sends to you.
What You Configure#
| Setting | What it controls |
|---|---|
| Name and when to use | The label in the dashboard, and when the agent should call this action |
| Read, Send, or Advanced | Read looks up data with GET. Send creates or updates with POST, PUT, or PATCH. Advanced adds DELETE and the fuller controls |
| URL | A public HTTPS endpoint. Variables such as {{item_id}} can come from the conversation |
| Parameters | Details the agent must collect before it calls |
| Headers, query, and body | The request you design. Send and Advanced can use a JSON, text, form, XML, or multipart body |
| Authentication | None, API key, bearer token, basic auth, a signing secret, or OAuth |
| Response path | Optional dot path, such as data.result, when the agent should see only part of the body |
| Timeout | Advanced only. 1–60 seconds, default 15 seconds |
| Callback | Advanced only. Callback webhook means a later result. Accepting the request is not the finished work |
The Public API test preset is only for trying the builder. Do not leave it enabled for real customer conversations.
Built-in booking, orders, and payment tools should stay on their own setup pages. Use an API Action when the system is yours.
What the Customer Sees#
| Result | What it means |
|---|---|
| The call succeeds | The agent may use the response, or the response path you set |
| The call fails, times out, or is declined | No change was confirmed. The agent should not describe the outside system as updated |
| The result is unclear | Check your system before the customer is asked to submit again |
| Callback mode accepts the request | Your API received it. The work is not finished until the later result arrives |
| A required input is missing | The agent asks for it. It should not send a half-filled request |
A write can also require the customer to confirm first, or pause for your approval, when you turn those options on. Confirmation from the customer is still not proof that your API succeeded.
Security#
| Rule | Why it matters |
|---|---|
| HTTPS only | The endpoint has to be a public secure URL |
| No local or private addresses | Localhost and private network addresses are rejected |
| Credentials stay on the server | Store keys in the action's authentication settings rather than pasting them into the prompt |
For work that takes longer than the timeout, accept the request and finish it asynchronously. Callback mode is for that case. Do not treat the first acceptance as the completed change.
Related Pages#
- Agent Studio Tools
- Custom Forms — collect structured data without calling your API
- Webhooks — receive events from AlonChat