Skip to content
Flexday AI Docs

Capabilities

APIs and integrations

Expose a Solution as a public API, accept data from other systems, act in business applications such as ServiceNow, and call out with stored credentials.

Written for
  • Everyone
  • Technical

Last reviewed

Every Solution can be part of your wider estate. Its Flex Gateway is a public API that other systems can call, protected by the sign-in you attach. Flows can receive signed webhooks, act in business applications such as ServiceNow, and call any HTTP API with credentials kept in a Connection.

What you can do

  • Publish an API. When the Builder finishes an app, each saved read query becomes an endpoint. Add endpoints yourself for queries that change data, or to start a Flow, talk to an Agent, or upload and download files.
  • Protect it the way you need. Use your single sign-on for people, and API keys, signed requests, Basic credentials, token introspection or, where your deployment is set up to check them, client certificates for machines.
  • Accept data pushed from other systems. A partner system can call a flow endpoint with an API key, or a signed webhook can start a Flow, and the Flow writes the data into a Fact Base.
  • Raise and update tickets in ServiceNow. The Integration step creates, finds, updates, comments on, assigns and resolves incidents, without any integration code.
  • Call any HTTP API. The HTTP request step can use a stored Connection, so the credential need not appear in the workflow.
  • Send email your way. Through the platform's mail relay where your deployment offers it, or your own SMTP server, under the Solution's email rules.
  • Automate the platform itself. Studio's REST API is described by a published OpenAPI specification.
The Endpoints tab of the Harbourline Energy Flex Gateway: seven query endpoints the Builder made for the dashboard, each a POST route under the gateway's own path, with its kind, an access rule of Inherit resolving to open, and its mode
Notice the Auth column: each endpoint follows the gateway's sign-in, and this gateway has no Identity attached, so the dashboard's reads are open to anyone with the address.

How it works

DirectionMechanismProtected by
Into a SolutionA gateway endpoint (query, flow, agent or file)The gateway's Identity and per-endpoint rules
Into a SolutionA webhook-triggered FlowAn unguessable address and an HMAC-SHA256 signature over the body, with duplicate suppression for deliveries that carry an idempotency key
Out to an applicationThe Integration stepAn Application Connection; writes never follow redirects; duplicate-prevention checks
Out to any APIThe HTTP request step, or an Agent's HTTP grantA Connection; Agent calls allow-listed and kept off private networks
Out by email or TeamsSend email; Send channel messageRecipient allow-lists and send allowances per Solution; consent for Teams outreach
The Create ticket step of the Raise incident Flow, open in its drawer: ServiceNow as the application, Create ticket as the action, the ServiceNow Connection, and a summary and details taken from the Flow's trigger
Notice what the step does not hold: no address, no credential and no request format, only the application, the action, a Connection and the action's fields.

Every outside effect (an email, an HTTP write, an application write, a Teams message) claims an idempotency key first, so a step that already succeeded is not repeated when it is retried; a duplicate is rare rather than impossible.

Example

An IT team wants ServiceNow incidents mirrored into a dashboard. ServiceNow posts each new or updated incident to a flow endpoint on the Solution's gateway, using an API key held by a machine Identity. The Flow saves the incident with a write query that inserts or updates the row. A nightly Flow uses the Integration step's Find tickets action to catch anything missed. When an engineer asks the service desk Agent to raise a ticket, the Agent runs a Flow whose Create ticket step returns the new incident number and a link.

Who uses it

PersonaWhat they get
DeveloperNamed endpoints, a consistent response envelope, and a machine credential of their choice
Integration analystServiceNow actions from a form, with no code
IT and securityCredentials sealed in Connections; per-endpoint auth; keyed writes
Functional userSolutions that plug into the systems their process already runs on, instead of becoming new silos