21.3 HTTP Requests: Web APIs, the Orchestrator API & Connector Requests

Key Takeaways

  • The WebAPI HTTP Request calls any API with configured authentication; the legacy version has a cURL import wizard, many methods, and a 6-second default timeout.

  • Orchestrator HTTP Request calls the Orchestrator API as the robot, with GET, POST, PUT, PATCH, or DELETE, a relative endpoint, and a non-indented JSON payload.

  • Its outputs are Headers, JSON Response, and Status Code, and permissions depend on the endpoint called.

  • Connector HTTP Request activities reuse an Integration Service connection's authentication for endpoints without dedicated activities.

  • Check the status code before parsing, and keep API keys in Credential or Secret assets.

Last updated: September 2026

21.3 HTTP Requests: Web APIs, the Orchestrator API & Connector Requests

Core Concept: The exam description lists "REST API and Orchestrator HTTP Request" and "HTTP Request for IS connectors". UiPath offers several ways to call APIs, and each handles authentication differently. Choosing the right one is the key skill.


Three Ways to Send HTTP Requests

ActivityCallsAuthentication
HTTP Request (WebAPI package)Any web APIYou configure it (none, basic, OAuth tokens, client certificates)
Orchestrator HTTP Request (System activities)The Orchestrator API of the robot's tenantAutomatically as the robot running the job
HTTP Request inside an Integration Service connectorThe connector's application APIThe connection's authentication

The HTTP Request Activity (WebAPI)

The WebAPI package's HTTP Request activity calls any REST endpoint. WebAPI 2.0 introduced an improved HTTP Request; the earlier version is now labeled HTTP Request (legacy). The legacy activity illustrates the settings you meet in any version:

  • A wizard to build and preview requests, and an import option for requests in cURL format.
  • Methods: GET, POST, PUT, DELETE, HEAD, OPTIONS, PATCH, and MERGE.
  • Authentication: None, Simple HTTP (username and password), OAuth1, or OAuth2 (an access token, usually obtained from another request).
  • Parameters: query or form parameters, headers, and URL segments written as {id} in the endpoint.
  • Client certificates (.pfx or .p12) and SSL certificate verification.
  • Timeout: 6,000 ms (6 seconds) by default in the legacy activity.
  • Outputs: the response body, headers, and status code. A status code of 0 means the server returned no response, which usually points to connectivity problems.

Working with JSON responses

Use Deserialize JSON to turn the response string into a JObject, then read values such as jObj("customer")("id").ToString. For arrays, use Deserialize JSON Array. Always check the status code before parsing.


The Orchestrator HTTP Request Activity

Orchestrator HTTP Request calls the Orchestrator API authenticated as the robot that runs it, so there are no tokens to manage.

SettingMeaning
MethodGET (default), POST, PUT, PATCH, or DELETE
Relative EndpointThe path relative to the Orchestrator URL, for example /odata/Jobs
JSON PayloadThe request body as non-indented JSON
Folder PathThe folder to act in, if different from the job's folder
TimeoutDefault 300,000 ms (5 minutes); opening the connection is limited to 30 seconds
OutputsHeaders, JSON Response (string), and Status Code (integer)

Permissions depend on the endpoint. The robot account needs the Orchestrator permissions the endpoint requires, for example Assets View for /odata/Assets and Jobs View for /odata/Jobs, plus Folders View to use the Folder Path field.

Typical uses: reading queue statistics, starting another process's job, or updating an asset from a workflow when no dedicated activity exists.


HTTP Requests Through Connectors

Integration Service connectors offer an HTTP Request activity for endpoints that have no dedicated activity. It reuses the connection, so authentication, token refresh, and base URL are handled for you. In API workflows, the HTTP activity can likewise use connector-based authentication instead of manual credentials.

The UiPath Orchestrator connector also includes a UiPath Orchestrator HTTP Request activity, alongside activities such as Get Asset, Get Queue Items, and Run Job.


Choosing the Right Tool

ScenarioChoose
Read jobs or queue data from the robot's own OrchestratorOrchestrator HTTP Request
Call an endpoint of Salesforce that has no activity, with an existing connectionThe Salesforce connector's HTTP Request
Call a partner's REST API that has no connector, with an API keyWebAPI HTTP Request with the key in a header, stored in a Credential or Secret asset
Call many APIs quickly without a robotAn API workflow
Repeatedly use a REST API without a connector across many projectsBuild a connector with Connector Builder

Worked Example: Checking Queue Backlog

A dispatcher should only add new items if the queue has fewer than 5,000 New items.

  1. Orchestrator HTTP Request with Method GET and a relative endpoint that filters the queue's items by status New and returns the count.
  2. Check that Status Code is 200.
  3. Deserialize JSON on the JSON Response and read the count.
  4. If the count is below 5,000, continue with Bulk Add Queue Items; otherwise, log a warning and end.

The robot account needs the queue permissions required by the endpoint in that folder, for example Queues View and Transactions View.


Common Traps

  • Storing API keys in workflow code instead of Credential or Secret assets.
  • Forgetting that Orchestrator HTTP Request permissions come from the robot's role.
  • Parsing a response without checking the status code.
  • Sending an indented JSON payload to Orchestrator HTTP Request.
Test Your Knowledge

A workflow uses Orchestrator HTTP Request to GET /odata/Assets and receives a 403 status. What is the most likely cause?

A

The JSON payload was indented.

B

The robot account running the job lacks the Assets View permission required by the endpoint.

C

The activity requires an OAuth token in the headers.

D

GET is not supported by the activity.

Test Your Knowledge

An automation must call a Salesforce endpoint that has no dedicated activity, and a Salesforce connection already exists. What is the best option?

A

WebAPI HTTP Request with the Salesforce password in a Text asset.

B

Orchestrator HTTP Request.

C

Browser automation of the Salesforce UI.

D

The Salesforce connector's HTTP Request activity, which reuses the connection's authentication.

Test Your Knowledge

The legacy HTTP Request activity returns status code 0. What does this usually indicate?

A

The server returned no actual response, which usually points to connectivity or network issues.

B

The request succeeded with an empty body.

C

The endpoint returned a redirect.

D

The request was cached.

Sections you finish are checked off in the contents.