How to Configure HTTP API Headers in ZazzyAgent
HTTP headers are additional pieces of information sent with an API request.
Many external APIs require them before they will accept a request.
For example, an API may require:
Content-TypeAuthorizationapi-keyanother custom header required by the API provider
Without the correct headers, the API may reject an otherwise valid request.
When do you need API headers?
You typically need headers when the external API requires authentication or expects a specific request format.
Common examples include:
Authentication
Authorization: Bearer YOUR_TOKEN
API key
x-api-key: YOUR_API_KEY
JSON request
Content-Type: application/json
The exact header names and values must come from the API documentation for the service you are connecting.
Headers vs request parameters
These are different parts of an API request.
Header
Carries request metadata or credentials.
Authorization: Bearer abc123
Parameter
Carries information the API needs to process the request.
order_id = 12345
Request body
Contains structured data being sent to the API, commonly with POST or PUT requests.
{
"name": "Rahul",
"email": "rahul@example.com"
}
Using the correct section matters. Putting a value in the wrong place can cause an API request to fail.
How to add headers to an HTTP API integration
Open the HTTP API integration you want to configure.
Create a new API integration or edit an existing one.
Choose the required HTTP method and enter the API endpoint.
Locate the request header configuration.
Add each required header as a separate key-value pair.
For example:
| Header Key | Header Value |
|---|---|
Content-Type |
application/json |
Authorization |
Bearer YOUR_TOKEN |
Save the configuration after adding the required headers.
Example: Bearer token authentication
Suppose an API requires:
Authorization: Bearer abc123
Configure:
Header Key:
Authorization
Header Value:
Bearer abc123
Do not include extra quotation marks unless the API documentation specifically requires them.
Example: API key authentication
Another API may require:
x-api-key: abc123
Configure:
Header Key:
x-api-key
Header Value:
abc123
The header name matters.
For example:
x-api-key
is not necessarily equivalent to:
api-key
Follow the exact format required by the external service.
Add Content-Type when required
If the API expects JSON in the request body, it may require:
Content-Type: application/json
This tells the receiving system how to interpret the request body.
For example:
{
"name": "Rahul",
"phone": "+919999999999"
}
Without the expected content type, some APIs may reject or misinterpret the request.
Can headers contain dynamic values?
The exact dynamic behavior depends on the API configuration and the values exposed by your ZazzyAgent workflow.
For example, you may need an API request to contain customer-specific information while keeping authentication fixed.
A common structure is:
Customer Input
↓
Saved Customer Data
↓
HTTP API
↓
Headers + Request Data
↓
External System
Keep authentication credentials separate from customer-facing messages.
Never put secrets in messages
Do not send API keys or private tokens to customers.
Avoid placing credentials inside:
Customer messages
Buttons
Public URLs
Customer-facing instructions
Credentials belong in the API configuration used for the integration.
Multiple headers
An API can require more than one header.
For example:
Content-Type: application/json
Authorization: Bearer YOUR_TOKEN
X-Organization-ID: 12345
Add each required header individually.
Do not combine unrelated headers into one value.
How to troubleshoot header errors
If the request fails, check the API error first.
401 Unauthorized
Usually indicates an authentication problem.
Check:
Token
API key
Authorization header
Credential status
403 Forbidden
The credential may be valid but not allowed to perform the requested operation.
Check:
Account permissions
API permissions
Token scope
Correct account or environment
400 Bad Request
The headers may be correct, but another part of the request may be invalid.
Check:
Parameters
Request body
Required fields
Data format
Common header mistakes
Wrong header name
The API expects:
Authorization
but the request sends:
Authentication
The API may reject it.
Missing prefix
The API expects:
Bearer abc123
but you provide:
abc123
The token format is incomplete.
Incorrect Content-Type
Your body is JSON, but the API expects a different content type.
Check the API documentation.
Expired credentials
A previously valid token may no longer work.
Generate or refresh the credential where required.
Testing against the wrong environment
Development and production APIs may use different credentials or endpoints.
Make sure the header belongs to the same environment as the API URL.
Test the complete request
Don't test headers in isolation.
Test:
Endpoint
↓
Method
↓
Headers
↓
Parameters
↓
Request Body
↓
External API
↓
Response
If the request fails, change one part at a time.
Best practice
Keep your API configuration documented.
Record:
Endpoint
HTTP method
Required headers
Authentication method
Required parameters
Request body format
Expected response
This makes future troubleshooting much easier.
For the broader HTTP API setup, see HTTP API in ZazzyAgent: Complete Guide to External API Automation.
For API failures, see API Errors in ZazzyAgent Flow Builder: Troubleshooting Guide.
The key idea
Headers are part of the API request, not part of the customer conversation.
Configure them correctly, keep credentials protected, and test the complete request before connecting it to a live automation.
