21.2 API Workflows in Studio Web

Key Takeaways

  • API workflows are built in Studio Web and run on cloud-managed serverless infrastructure without robot machines.

  • Activities include Connector, HTTP, Script, If, For Each, Do While, Assign, Try Catch, Wait, Log Message, Response, and Base64 file conversions.

  • Expressions and scripts use JavaScript; inside loops use $input for the previous object's output.

  • Manual HTTP requests go out through serverless robots, while connector-based calls go through Integration Service.

  • Published API workflows run as Orchestrator processes and serve as agent tools and Maestro tasks.

Last updated: September 2026

21.2 API Workflows in Studio Web

Core Concept: API workflows are headless workflows built in Studio Web that chain API calls and transform data on UiPath's cloud-managed, serverless infrastructure. They run fast, need no robot machine, and can serve as reusable APIs, as tools for agents, or as tasks in Maestro processes.


API Workflows Versus RPA Workflows

API workflowRPA workflow
Built inStudio WebStudio or Studio Web
Runs onCloud-managed serverless infrastructureRobots on machines (or serverless robots)
Interacts throughAPIs onlyUI and APIs
ExpressionsJavaScriptVB.NET or C#
Typical useSystem-to-system integrations, data transformation, tools for agentsAnything that needs UI automation or desktop applications

The Activities

ActivityPurpose
ConnectorCall an Integration Service connector operation through a connection
HTTPSend an HTTP request, with manual authentication or connector-based authentication
ScriptRun JavaScript to transform data
IfBranch on a condition
For Each / Do WhileLoop over items or while a condition holds
AssignSet values
Try CatchHandle errors
WaitPause for a time
Log MessageWrite a log entry
ResponseEnd the workflow early with a Success or Failure response
File to Base64 / Base64 to FileConvert files for API payloads

Tips from UiPath's documentation:

  • Define clear input and output schemas, so other UiPath products can call the workflow correctly.
  • Inside For Each and Do While, use $input instead of $context to access the previous object's output.
  • Use Autopilot to generate context-aware JavaScript expressions, and validate them in the expression editor's output panel before running.
  • Test quickly with the Run Output panel, which shows inputs and outputs you can expand or copy.

Outbound Traffic and IP Allow Lists

Calls inside the UiPath platform, for example to Orchestrator, need no allow-listing. External calls do, and the source depends on the activity:

ActivityAuthenticationOutbound path
HTTP RequestManualServerless robots (serverless static IPs)
HTTP RequestConnector-basedIntegration Service (Integration Service IPs)
ConnectorNot applicableIntegration Service

If a partner's firewall blocks requests, check which path the activity uses and allow the matching IP range.


Publishing and Consuming

  • From Orchestrator: publish the API workflow; it appears as a process. Start a job from Automations > Processes, supply the input (the request schema), and read the response in the job details.
  • As an agent tool: add it to an agent with Add tool > API workflow and describe its inputs clearly so the agent can call it. The agent then uses only the data the API workflow returns, which limits what the model sees.
  • In Maestro: use API workflows as tasks that encapsulate API chaining and data transformation, keeping the main process readable.

Worked Example: Enriching a New Lead

  1. Input schema: email (string).
  2. Connector activity: search the CRM for a contact with that email.
  3. If the contact exists, Response with Success and the contact ID.
  4. Otherwise, an HTTP activity with manual authentication calls a company-data API.
  5. A Script activity maps the response to the CRM's fields in JavaScript.
  6. A Connector activity creates the contact.
  7. Try Catch around steps 4 to 6 returns a Failure response with a clear message if the external API fails.
  8. Response with Success and the new contact ID.

The workflow runs in a few seconds without any robot machine, and the sales agent that calls it as a tool never sees the raw data from the external API.


Design Guidelines

  • Keep each API workflow focused on one integration task with a clear contract, so it can be reused by processes, agents, and Maestro alike.
  • Validate inputs first and return a Failure response with a clear message when required values are missing.
  • Handle partial failures: decide what happens if the second of three API calls fails, and use Try Catch to return a meaningful response.
  • Log identifiers, not payloads, to keep sensitive data out of logs.
  • Prefer connectors when one exists, because they manage authentication and tokens; use manual HTTP only when necessary.

Key Terms

  • Input and output schema: the JSON structure of the request and response, which callers such as agents rely on.
  • $context and $input: expression variables for accessing workflow data; inside loops, $input holds the previous object's output.
  • Run Output panel: the design-time view of each activity's inputs and outputs during a test run.
  • Platform connector: a connector for UiPath services, such as Orchestrator or Data Fabric, used from API workflows.

Common Traps

  • Writing VB.NET expressions: API workflows use JavaScript.
  • Forgetting to allow serverless IPs for manual HTTP calls to firewalled systems.
  • Using $context inside loops where $input holds the previous object's output.
  • Trying to automate a UI: API workflows cannot; use an RPA workflow.
Test Your Knowledge

An API workflow calls a partner API through an HTTP activity with manual authentication, and the partner's firewall blocks the requests. Which IPs must the partner allow?

A

The developer's workstation IP.

B

Integration Service IPs.

C

The Orchestrator tenant's web IP.

D

The serverless static IPs, because manual HTTP requests go out through serverless robots.

Test Your Knowledge

Which statement about API workflows is correct?

A

They run on cloud-managed serverless infrastructure, use JavaScript expressions, and cannot automate user interfaces.

B

They require an unattended robot machine.

C

They use VB.NET expressions like Studio workflows.

D

They can only be started by agents.

Test Your Knowledge

How does an API workflow end early with an error result for its caller?

A

By throwing an exception from a Log Message activity.

B

With a Response activity configured as Failure.

C

By stopping the job in Orchestrator.

D

With a Wait activity of zero seconds.

Sections you finish are checked off in the contents.