HTTP
The HTTP connector facilitates interaction with web services and APIs by enabling the construction and dispatch of custom HTTP requests.
The HTTP connector enables seamless integration with web services and APIs, allowing users to automate HTTP requests within their security workflows. By leveraging this connector, Swimlane Turbine users can build and send custom HTTP requests to specified endpoints, facilitating flexible web interactions. This integration empowers security teams to automate web service interactions, enhancing the efficiency and effectiveness of their security operations.
Prerequisites
Before you can use the HTTP connector for Turbine, you'll need to configure authentication mechanisms based on your requirements. This includes:
- Bearer token authentication using the following parameters:
- URL: The endpoint URL for the HTTP request.
- Token: The bearer token used for authentication.
- Basic authentication using the following parameters:
- URL: The endpoint URL for the HTTP request.
- Username: The username for basic authentication.
- Password: The password associated with the username.
- API key authentication using the following parameters:
- URL: The endpoint URL for the HTTP request.
- API Key: The key used to authenticate the request.
- API Key Name: The name of the API key parameter.
- API Key Location: The location where the API key should be included (e.g., header, query).
- OAuth 2.0 client credentials using the following parameters:
- URL: The endpoint URL for the HTTP request.
- Client ID: The client identifier issued by the authorization server. ... and so on
Capabilities
This connector provides the following capabilities:
- Send an HTTP Request
Limitations
This connector works for any API that conforms to a standard authentication scheme. Any API that has implemented its own custom method is not supported by this connector.
Asset Setup
Please read the API documentation of the product you would like to connect to Swimlane in order to understand which authentication type is required.
This connector supports the following authentication types:
- No Auth,
- Basic,
- Bearer Token,
- API Key/Token
- OAuth2.0 Client Credentials
Configuring an Asset
- Host (required) = The hostname of the product's API.
- Authentication Type (required) = Type of authentication to use for this API.
- Options: no_auth, basic, bearer, api_key, oauth2_client_credentials
- Verify SSL = Toggle SSL verification support.
- HTTP Proxy = A proxy URL where all requests can get routed through.
No Auth Authentication
Not recommended and most likely not supported by your API. Nothing is required to authenticate.
Basic Authentication
This means you have select Authentication Type to be basic.
- Basic Username (required) = The API username.
- Basic Password (required) = The API password, sometimes this is an API token.
Bearer Token Authentication
This means you have select Authentication Type to be bearer.
- Bearer Token (required) = The bearer token for the API.
API Key Authentication
This means you have select Authentication Type to be api_key.
- API Key Name (required) = The API key name.
- API Key Value (required) = Value of the API key.
- API Key Location (required) = Location of the API Key name and value.
- Options: query_params or headers
OAuth2.0 Client Credentials Authentication
This means you have select Authentication Type to be oauth2_client_credentials.
- OAuth2 Client ID (required) = Client ID.
- OAuth2 Client Secret (required) = Client Secret.
- OAuth2 Token URL (required) = The full URL, including host, of where to get the access token.
- OAuth2 Scope (required) = Space separated string of scopes to apply to the access token.
Actions Setup
After configuring an asset for the API you can create as many Generic HTTP Request actions as you would like.
- Endpoint (required) = The endpoint of the API to send a request to. This includes everything that comes after the host except for query parameters.
- Method (required) = HTTP Request method and typically one of: GET, POST, PATCH, DELETE, PUT
When provided, the following inputs must be valid JSON strings. For creating dynamic strings please use the new string interpolation feature. Documentation can be found here: Input Configuration String Interpolation
- Query Parameters = Optional URL query parameters to send with the request.
- Headers = Optional headers to send with the request.
- Request Body = Request payload as JSON.
Configurations
API Key Authentication
Authenticates using an API Key
Configuration Parameters
Parameter | Description | Type | Required |
|---|---|---|---|
url | A URL to the target host. | string | Required |
apikey | API key value | string | Required |
apikey_name | The header key name for which to apply the API key. | string | Required |
apikey_in | The location of the API Key. Options: header, cookie or query | string | Required |
verify_ssl | Verify SSL certificate | boolean | Optional |
http_proxy | A proxy to route requests through. | string | Optional |
headers | Additional headers to send with each request such as a User-Agent. | object | Optional |
ca_cert | A Base64 encoded CA certificate to use for SSL verification | string | Optional |
HTTP Basic Authentication
Authenticates using username and password.
Configuration Parameters
Parameter | Description | Type | Required |
|---|---|---|---|
url | A URL to the target host. | string | Required |
username | Username | string | Required |
password | Password | string | Required |
verify_ssl | Verify SSL certificate | boolean | Optional |
http_proxy | A proxy to route requests through. | string | Optional |
headers | Additional headers to send with each request such as a User-Agent. | object | Optional |
ca_cert | A Base64 encoded CA certificate to use for SSL verification | string | Optional |
HTTP Bearer Authentication
Authenticates using bearer token such as a JWT, etc.
Configuration Parameters
Parameter | Description | Type | Required |
|---|---|---|---|
url | A URL to the target host. | string | Required |
token | The API key, token, etc. | string | Required |
verify_ssl | Verify SSL certificate | boolean | Optional |
http_proxy | A proxy to route requests through. | string | Optional |
headers | Additional headers to send with each request such as a User-Agent. | object | Optional |
ca_cert | A Base64 encoded CA certificate to use for SSL verification | string | Optional |
Oauth 2.0 Client Credentials
Authenticates using oauth 2.0 client credentials
Configuration Parameters
Parameter | Description | Type | Required |
|---|---|---|---|
url | A URL to the target host. | string | Required |
token_url | ο»Ώ | string | Required |
client_id | The client ID | string | Required |
client_secret | The client secret. | string | Required |
scope | Permission scopes for this action. | array | Optional |
verify_ssl | Verify SSL certificate | boolean | Optional |
http_proxy | A proxy to route requests through. | string | Optional |
headers | Additional headers to send with each request such as a User-Agent. | object | Optional |
ca_cert | A Base64 encoded CA certificate to use for SSL verification | string | Optional |
Actions
Send HTTP Request
Build and send a custom HTTP request to specified endpoints for flexible web interactions.
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
endpoint | string | Optional | Path to the endpoint after url in asset. Use double brackets with path parameters for dynamic URLs. |
method | string | Optional | Method of the request such as: POST, GET, PUT, PATCH, DELETE. (Note, others are available to use) |
data_body | object | Optional | Body to send as data, this allows you to set the content-type in the headers manually. |
headers | object | Optional | Request headers to send with the individual request. |
Input Example
{"endpoint":"api/v3/users"}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | The HTTP response status code |
data | object | The JSON response body |
response_text | string | Output field: response_text |
reason | string | The HTTP reason, often times an error message can be here. OK means success. |
Output Example
{"response_text":"string"}
Response Headers
Header | Description | Example |
|---|---|---|
Content-Type | The media type of the resource | application/json |
Date | The date and time at which the message was originated | Thu, 01 Jan 2024 00:00:00 GMT |