Capabilities
APIs and integrations
Expose a Solution as a public API, accept data from other systems, act in business applications such as ServiceNow, and call out with stored credentials.
- Everyone
- Technical
Last reviewed
Every Solution can be part of your wider estate. Its Flex Gateway is a public API that other systems can call, protected by the sign-in you attach. Flows can receive signed webhooks, act in business applications such as ServiceNow, and call any HTTP API with credentials kept in a Connection.
What you can do
- Publish an API. When the Builder finishes an app, each saved read query becomes an endpoint. Add endpoints yourself for queries that change data, or to start a Flow, talk to an Agent, or upload and download files.
- Protect it the way you need. Use your single sign-on for people, and API keys, signed requests, Basic credentials, token introspection or, where your deployment is set up to check them, client certificates for machines.
- Accept data pushed from other systems. A partner system can call a flow endpoint with an API key, or a signed webhook can start a Flow, and the Flow writes the data into a Fact Base.
- Raise and update tickets in ServiceNow. The Integration step creates, finds, updates, comments on, assigns and resolves incidents, without any integration code.
- Call any HTTP API. The HTTP request step can use a stored Connection, so the credential need not appear in the workflow.
- Send email your way. Through the platform's mail relay where your deployment offers it, or your own SMTP server, under the Solution's email rules.
- Automate the platform itself. Studio's REST API is described by a published OpenAPI specification.

How it works
| Direction | Mechanism | Protected by |
|---|---|---|
| Into a Solution | A gateway endpoint (query, flow, agent or file) | The gateway's Identity and per-endpoint rules |
| Into a Solution | A webhook-triggered Flow | An unguessable address and an HMAC-SHA256 signature over the body, with duplicate suppression for deliveries that carry an idempotency key |
| Out to an application | The Integration step | An Application Connection; writes never follow redirects; duplicate-prevention checks |
| Out to any API | The HTTP request step, or an Agent's HTTP grant | A Connection; Agent calls allow-listed and kept off private networks |
| Out by email or Teams | Send email; Send channel message | Recipient allow-lists and send allowances per Solution; consent for Teams outreach |

Every outside effect (an email, an HTTP write, an application write, a Teams message) claims an idempotency key first, so a step that already succeeded is not repeated when it is retried; a duplicate is rare rather than impossible.
Example
An IT team wants ServiceNow incidents mirrored into a dashboard. ServiceNow posts each new or updated incident to a flow endpoint on the Solution's gateway, using an API key held by a machine Identity. The Flow saves the incident with a write query that inserts or updates the row. A nightly Flow uses the Integration step's Find tickets action to catch anything missed. When an engineer asks the service desk Agent to raise a ticket, the Agent runs a Flow whose Create ticket step returns the new incident number and a link.
Who uses it
| Persona | What they get |
|---|---|
| Developer | Named endpoints, a consistent response envelope, and a machine credential of their choice |
| Integration analyst | ServiceNow actions from a form, with no code |
| IT and security | Credentials sealed in Connections; per-endpoint auth; keyed writes |
| Functional user | Solutions that plug into the systems their process already runs on, instead of becoming new silos |