Skip to content
Anlyon
Esc
↑↓navigate↵open⌘Jpreview

Create an action

Define a secret-backed, SSRF-protected hosted HTTP tool.

POST/api/v2/actions
Authorization
AuthorizationBearer token (Anlyon API key) · headerrequired

Workspace API key sent as Authorization: Bearer <key>.

or
better-auth.session_tokenAPI key · cookierequired

Browser session used by dashboard-only operations.

Header parameters
X-Request-Idstring

Optional caller correlation ID. Unsafe or oversized values are replaced.

max length 128
Idempotency-Keystring

Stable retry key for a mutation. The key is claimed atomically before the handler runs, so concurrent retries execute the side effect at most once. Replaying the key for the same request (same method, path, workspace and JSON body) returns the original response with an X-Idempotent-Replay: true header. Reusing the key for a different request returns 409 with error code idempotency_key_reuse. A duplicate arriving while the first is still in flight waits and then replays; if the first does not finish in time the duplicate gets 409 idempotency_request_in_progress. Keys are retained for 24 hours. Only successful (2xx) responses are stored; a failed request frees the key so it can be retried.

min length 1 · max length 255
Request body
requiredapplication/json
namestringrequired
min length 1 · max length 100 · matches ^[a-zA-Z0-9_-]+$
descriptionstring
max length 1000
methodstring
default: "POST"
Allowed:GETPOSTPUTPATCHDELETE
urlTemplatestring
min length 1 · max length 2048
headersobject
bodyTemplateobject
inputSchemaobject
requiresApprovalboolean
default: false
enabledboolean
default: true
adapterActionAdapter

Makes the action a governed effect (see the Governed effects guide). The request is built by the adapter from config; the credential is a vault secret referenced by name. Available types: stripe.refund (config account, mode: test, currency), github.file_update (config owner, repo, branch, optional pathPrefix, allowDefaultBranch) and resend.email_send (config domain, optional fromAddresses).

Show properties
typestringrequired
Allowed:stripe.refundgithub.file_updateresend.email_send
configobjectrequired
credentialSecretstringrequired
matches ^[A-Z0-9_]+$
impactActionImpact

How much one invocation changes, declared on a template action. Declaring it makes the action governed: the quantity is reserved against every applicable impact limit before dispatch. amount is an expression over the input, evaluated at admission after schema validation. It may be an integer, input.<path>, or count(input.<path>), followed by one optional * <integer>, and it must produce a non-negative integer. An amount that reads an optional input the caller left out yields no quantity. The effect is then unbounded for that dimension: an applicable limit refuses it with impact_unbounded, and with no applicable limit it runs. Anlyon evaluates the expression as written. It does not check that the expression describes what the provider will do.

Show properties
dimensionstringrequired

money, resource_mutations, or a workspace-declared unit such as emails, messages or rows.

matches ^[a-z][a-z0-9_]{0,31}$
unitstring

The currency for money (lowercase ISO 4217, required). For every other dimension the unit is the dimension name and may be left out.

min length 1 · max length 32
amountstringrequired
min length 1 · max length 200
boundstringrequired
Allowed:exactupper_bound
verifyActionVerify

A read-back that confirms a write, declared on a template action. After the provider accepts the write, Anlyon issues this GET through the same pinned transport with the action's own headers and compares the answer. A match grades the effect confirmed. Without one a 2xx grades acknowledged. The URL must be on the action's own host. It may reference {{input.field}}, {{response.field}} (a value from the provider's response to the write) and {{secret:NAME}}. A rule that needs response cannot run after a lost response, so that effect stays unknown until an operator resolves it.

Show properties
urlstringrequired
min length 1 · max length 2048
statusintegerrequired

The status the read-back must answer with.

min 100 · max 599
matchobject[]

JSON path equality checks on the read-back body. Every one must hold.

max items 10
Show properties
Array of object
pathstringrequired

A dotted path into the read-back body. A numeric segment indexes an array.

min length 1 · max length 200
equalsany | nullrequired

A string, number, boolean or null. A string may be exactly one {{input.field}} or {{response.field}}.

governedboolean

Set true to govern a template action that declares neither impact nor verify. Its 2xx then grades acknowledged.

Responses
201

Action created.

successbooleanrequired
Allowed:true
dataActionrequired
Show properties
idstringrequired
environmentIdstring<uuid>required

The environment this action lives in. An action belongs to exactly one.

namestringrequired
descriptionstring | nullrequired
methodstringrequired
Allowed:GETPOSTPUTPATCHDELETE
urlTemplatestringrequired
headersobjectrequired
bodyTemplateobject | nullrequired
inputSchemaobjectrequired
requiresApprovalbooleanrequired
enabledbooleanrequired
secretsstring[]required

Referenced secret names only; values are never returned.

currentVersionIdstring | nullrequired

The immutable version this definition currently is. An agent version pins a version id, so this is what to pin to hold an action at its present definition. Null only for actions that predate versioning and have not been edited since.

adapterActionAdapter | nullrequired

The governed-effect adapter, or null for a template action.

Show properties
Any of:
ActionAdapter
typestringrequired
Allowed:stripe.refundgithub.file_updateresend.email_send
configobjectrequired
credentialSecretstringrequired
matches ^[A-Z0-9_]+$
null
null
governedbooleanrequired

True when every invocation creates a governed effect. The action has an adapter, or it carries a declaration.

impactActionImpact | nullrequired

The declared impact, or null when the action declares none.

Show properties
Any of:
ActionImpact
dimensionstringrequired

money, resource_mutations, or a workspace-declared unit such as emails, messages or rows.

matches ^[a-z][a-z0-9_]{0,31}$
unitstring

The currency for money (lowercase ISO 4217, required). For every other dimension the unit is the dimension name and may be left out.

min length 1 · max length 32
amountstringrequired
min length 1 · max length 200
boundstringrequired
Allowed:exactupper_bound
null
null
verifyActionVerify | nullrequired

The declared read-back, or null when the action declares none.

Show properties
Any of:
ActionVerify
urlstringrequired
min length 1 · max length 2048
statusintegerrequired

The status the read-back must answer with.

min 100 · max 599
matchobject[]

JSON path equality checks on the read-back body. Every one must hold.

max items 10
Show properties
Array of object
pathstringrequired

A dotted path into the read-back body. A numeric segment indexes an array.

min length 1 · max length 200
equalsany | nullrequired

A string, number, boolean or null. A string may be exactly one {{input.field}} or {{response.field}}.

null
null
createdAtstring<date-time>required
updatedAtstring<date-time>required
400

Bad Request - Invalid input data

successbooleanrequired
requestIdstringrequired

Correlation ID matching the X-Request-Id response header.

errorobjectrequired
Show properties
codestring
messagestring
detailsobject
401

Unauthorized - Invalid or missing API key

successbooleanrequired
requestIdstringrequired

Correlation ID matching the X-Request-Id response header.

errorobjectrequired
Show properties
codestring
messagestring
detailsobject
402

Payment Required - Usage quota exceeded

successbooleanrequired
requestIdstringrequired

Correlation ID matching the X-Request-Id response header.

errorobjectrequired
Show properties
codestring
messagestring
detailsobject
403

Authenticated credential lacks the required scope or workspace access.

successbooleanrequired
requestIdstringrequired

Correlation ID matching the X-Request-Id response header.

errorobjectrequired
Show properties
codestring
messagestring
detailsobject
409

The request conflicts with current resource state or a concurrent decision.

successbooleanrequired
requestIdstringrequired

Correlation ID matching the X-Request-Id response header.

errorobjectrequired
Show properties
codestring
messagestring
detailsobject
429

Too Many Requests - Rate limit exceeded

successbooleanrequired
requestIdstringrequired

Correlation ID matching the X-Request-Id response header.

errorobjectrequired
Show properties
codestring
messagestring
detailsobject
Try it
Server
Authorization
Parameters
Bodyapplication/json
Request
curl -X POST 'https://api.anlyon.com/api/v2/actions' \
  -H 'Authorization: Bearer YOUR_TOKEN' \
  -H 'Content-Type: application/json' \
  -d '{
  "name": "string",
  "description": "string",
  "method": "GET",
  "urlTemplate": "https://api.example.com/users/{{input.userId}}",
  "headers": {
    "Authorization": "Bearer {{secret:EXAMPLE_TOKEN}}"
  },
  "bodyTemplate": {},
  "inputSchema": {},
  "requiresApproval": false,
  "enabled": true,
  "adapter": {
    "type": "stripe.refund",
    "config": {
      "account": "acct_123",
      "mode": "test",
      "currency": "usd"
    },
    "credentialSecret": "STRIPE_TEST_KEY"
  },
  "impact": {
    "dimension": "emails",
    "unit": "emails",
    "amount": "count(input.to)",
    "bound": "exact"
  },
  "verify": {
    "url": "https://api.example.com/v1/messages/{{response.id}}",
    "status": 200,
    "match": [
      {
        "path": "status",
        "equals": "sent"
      }
    ]
  },
  "governed": true
}'
Response
{
  "success": true,
  "data": {
    "id": "act_01JABCDEF",
    "environmentId": "19f5cc2e-7657-437a-9268-83cd3d563563",
    "name": "create-ticket",
    "description": "string",
    "method": "GET",
    "urlTemplate": "string",
    "headers": {},
    "bodyTemplate": {},
    "inputSchema": {},
    "requiresApproval": true,
    "enabled": true,
    "secrets": [
      "string"
    ],
    "currentVersionId": "acv_01JABCDEF",
    "adapter": {
      "type": "stripe.refund",
      "config": {
        "account": "acct_123",
        "mode": "test",
        "currency": "usd"
      },
      "credentialSecret": "STRIPE_TEST_KEY"
    },
    "governed": true,
    "impact": {
      "dimension": "emails",
      "unit": "emails",
      "amount": "count(input.to)",
      "bound": "exact"
    },
    "verify": {
      "url": "https://api.example.com/v1/messages/{{response.id}}",
      "status": 200,
      "match": [
        {
          "path": "status",
          "equals": "sent"
        }
      ]
    },
    "createdAt": "2019-08-24T14:15:22Z",
    "updatedAt": "2019-08-24T14:15:22Z"
  }
}