# Custom API actions: call your API from the chat

> Let your intoCHAT agent call your HTTP API during a chat: set up the request and auth, import a cURL command, fill inputs from the conversation and test it.

A custom API action lets the agent call an HTTP endpoint while it chats, for example to check live stock or prices, and answer from the response. You create actions on the **Actions** tab of your agent. To have the agent offer a link instead of calling an API, see [Custom buttons](/en/docs/custom-buttons).

## Create an action

Click **Add Action**, or **Import a request** to start from a cURL command. The editor has four steps, and you save once at the end with **Create action**. Running a test is optional but recommended.

### 1. The request

- **Method**: GET, POST, PUT, PATCH or DELETE.
- **HTTPS URL**: the endpoint. A query string pasted into the URL moves to the **Parameters** tab.
- **Parameters**, **Headers** and **Body** take key and value pairs. **Body** is available for every method except GET and is sent as JSON.
- **Collect data inputs for action (optional)**: values the agent fills in from the conversation. Each input has a **Name** (letters, numbers and underscores), a **Type** (Text, Number or Boolean), a **Description**, and the options **Required** and **Array**. Up to 25 inputs per action.

Use an input anywhere in the request as `{{name}}`, in the URL path, a parameter, a header or the body:

```text
GET https://api.example.com/products/{{productId}}/stock
```

The agent finds the value in the conversation or asks the visitor for it. A **Required** input stops the agent from calling the action before it has that value. Variables that are used but not declared as inputs are dropped from the request; the editor warns you and offers **Add them**.

### Authentication

| Option | What is sent |
| --- | --- |
| **No authentication** | Nothing |
| **Bearer token / access token** | An `Authorization: Bearer` header with your token |
| **API key in a header** | Your key in the header you name, such as `X-API-Key` |
| **API key in the URL** | Your key as the query parameter you name, such as `api_key` |
| **Username and password** | HTTP basic authentication |
| **Custom — I'll set the headers myself** | Whatever you add on the **Headers** tab |

### Import a request

Paste the cURL example from your API's documentation, or use "Copy as cURL" on a request in your browser's network tools. Method, URL, query parameters, headers and body are filled in, and the credential lands in the **Authentication** picker. Importing replaces the request but keeps the name and description. Multipart uploads (`-F`) are skipped, and a form-encoded body is imported as JSON fields.

### 2. Try it

Enter test values for the inputs and click **Send test request**. The request is built exactly as the agent will build it. The **Response Preview** shows the status, the response body and the request URL.

### 3. When the AI should use it

- **Action Name**: up to 60 characters.
- **When to use**: what the action does, what data it returns and example questions that should trigger it. The model reads the first 1,024 characters.
- **Server-side action** runs on intoCHAT's servers and is the default. **Client-side action** runs in the visitor's browser; see [Client-side actions](/en/docs/client-actions).
- **Enable this action**: switch an action off without deleting it.

### 4. What the AI can see

**Full data access** passes the whole response to the model. **Limited data access** passes only the fields you tick under **Visible**; run a test first to load the field list. For a list response, the fields come from the first item and the filter applies to every item. Until you tick at least one field, the full response is passed.

## Limits and safety

- Up to 25 actions per agent, including [custom buttons](/en/docs/custom-buttons) and actions created by [Connect your store](/en/docs/connect-your-store).
- The URL must point to a public host. Localhost, private networks, link-local addresses and cloud metadata endpoints are refused, also when a hostname resolves to one. The editor then shows "URL points to a blocked or internal host".
- Redirects are not followed. If the test shows "This address redirects somewhere else", click **Use this address**.
- Each call times out after 30 seconds.
- Responses longer than 40,000 characters are cut off. Limited data access keeps them small.
- Server-side actions send your credentials from intoCHAT's servers, never through the visitor's browser.
