HTTP Endpoint
Overview
| Property | Value |
|---|---|
| Node ID | redelay/http-endpoint |
| Kind | source |
| Module | events-flowdsl |
| Repo | go-flowdsl |
| Module ref | events |
| Handler | github.com/redelay/go-flowdsl/flowexec/module/router.HTTPEndpoint |
| Icon | lucide:globe |
| Color | #0ea5e9 |
| Tags | http, source, endpoint, sync |
Description
Declarative source node that turns the owning flow into an HTTP handler. The flowexec dispatcher reads this node's settings at flow publish time and binds (method, path) to the flow ID. Per request:
- Dispatcher matches (method, path) against its routing table.
- Builds the start payload from the JSON body merged with a
_metaenvelope (method, path, query, headers minus Authorization/Cookie, remote address). - Runs the flow synchronously via flowexec.Executor.Run.
- Reads four optional well-known keys off the workflow's terminal output map — status_code, body, headers, error — and writes the response.
Output convention (all keys optional):
- status_code (int) HTTP status. Defaults to success_status (typically 201).
- body (any) Response body. Falls back to "every other key in output".
- headers (mapstrstr) Extra response headers.
- error (string) When set without status_code, returns 400 + message.
Run-failure mapping: if the flow itself fails (handler returns error, no terminal node fires), dispatcher returns 500 with the sink owning the actual error detail.
Auth: when auth_required is true, requests without an Authorization header get 401 (flow does not run). Token validation is delegated to the upstream auth.AuthMiddleware registered ahead of the dispatcher; the dispatcher itself does not parse JWTs.
Route shadowing: published flows shadow Go-registered routes at the same (method, path). On unpublish, the Go handler resumes serving — no restart required.
Outputs
request— The merged request payload — every JSON body field at the top level, plus a_metaenvelope carrying request metadata (method, path, query, headers, remote). See spec/docs/4.reference/23.flow-driven-endpoints.md for the exact shape and redaction rules.
Settings
| Property | Type | Required | Default | UI Group | Description |
|---|---|---|---|---|---|
auth_required | boolean | — | false | Auth | When true, requests without an Authorization header are rejected with 401 before the flow runs. The dispatcher delegates token validation to the upstream auth.AuthMiddleware. False for public endpoints (signup, password reset request); true for authenticated flows (account deletion, password change). |
description | string | — | — | Spec metadata | Long-form description surfaced in /openapi.json. |
method | string (GET|POST|PUT|PATCH|…) | yes | POST | Routing | HTTP verb the flow accepts. |
path | string | yes | — | Routing | Exact-match HTTP path the flow mounts at. Examples: "/api/v1/users/signup", "/api/v1/auth/login". Path-pattern matching (e.g. "/users/{id}") is reserved for a future version — v1 is exact match only. |
success_status | integer | — | 201 | Routing | Default HTTP status code when the flow completes without setting status_code in its output. 201 is conventional for resource-creating flows (signup, magic link request); use 200 for read-only or idempotent flows. |
summary | string | — | — | Spec metadata | Short human-readable summary surfaced in /openapi.json. |
tags | array | — | — | Spec metadata | Tags for grouping in API docs. |
Example
# Use this node in a flow:
nodes:
- id: my_step
name: My Step
kind: source
action_ref: redelay/http-endpoint
config:
auth_required: false
description: "value"
method: POST
path: "value"
success_status: 201
summary: "value"
tags: []