# Workflow - HTTP Request Action Source

**URL:** <https://developer.sailpoint.com/discuss/t/workflow-http-request-action-source/115122>\
**Category:** SHF Discussion and Questions\
**Tags:** identity-security-cloud, workflows\
**Created:** [April 24, 2025, 5:25pm UTC](https://developer.sailpoint.com/discuss/t/workflow-http-request-action-source/115122 "2025-04-24T17:25:13Z")\
**Posts on this page:** 9\
**Page:** 1

<div class="post-metadata">

**Author:** ![bostelmann](https://avatars.discourse-cdn.com/v4/letter/b/aca169/32.png) [@bostelmann](https://developer.sailpoint.com/discuss/u/bostelmann)\
**Post date:** [April 24, 2025, 5:25pm UTC](https://developer.sailpoint.com/discuss/t/workflow-http-request-action-source/115122/1 "2025-04-24T17:25:13Z")

</div>

Hello Fellow Developers,

I am currently building out a workflow and need to implement the HTTP Request action. Could someone advise if the Workflow HTTP Request action is cloud executed, or VA executed? If it is cloud executed, do we know the Fully Qualified Domain Name (FQDN) of the source?

I have reviewed the documentation, but I could not identify any such details. This information is needed for network architecture and raising firewall rules.

---

<div class="post-metadata">

**Author:** ![iamnithesh](https://sea1.discourse-cdn.com/sailpoint/discuss/user_avatar/developer.sailpoint.com/iamnithesh/32/4884_2.png) [@iamnithesh](https://developer.sailpoint.com/discuss/u/iamnithesh)\
**Post date:** [April 24, 2025, 6:18pm UTC](https://developer.sailpoint.com/discuss/t/workflow-http-request-action-source/115122/2 "2025-04-24T18:18:34Z")

</div>

All actions/processes in a workflow are cloud executed. As these are run as microservices on AWS cloud (most likely containerized packages) there would not be a FQDN for the source.

Are you trying to call a private API?

---

<div class="post-metadata">

**Author:** ![bostelmann](https://avatars.discourse-cdn.com/v4/letter/b/aca169/32.png) [@bostelmann](https://developer.sailpoint.com/discuss/u/bostelmann)\
**Post date:** [April 24, 2025, 6:36pm UTC](https://developer.sailpoint.com/discuss/t/workflow-http-request-action-source/115122/3 "2025-04-24T18:36:06Z")

</div>

Hello @iamnithesh,

Thank you for the confirmation, that is what I had suspected.

Yes, I am trying to call a private API. Since workflow is cloud executed, I suspect I will need an API Gateway to expose the interface to the cloud. Unless you know of simpler solution? Is there a way to pass the request off as a job to the VA?

---

<div class="post-metadata">

**Author:** ![vishal\_kejriwal1](https://sea1.discourse-cdn.com/sailpoint/discuss/user_avatar/developer.sailpoint.com/vishal_kejriwal1/32/10904_2.png) [@vishal\_kejriwal1](https://developer.sailpoint.com/discuss/u/vishal_kejriwal1)\
**Post date:** [April 24, 2025, 7:16pm UTC](https://developer.sailpoint.com/discuss/t/workflow-http-request-action-source/115122/4 "2025-04-24T19:16:06Z")

</div>

> [@bostelmann](#):
>
> private API

Just curious , What do you mean by private API here?

---

<div class="post-metadata">

**Author:** ![iamnithesh](https://sea1.discourse-cdn.com/sailpoint/discuss/user_avatar/developer.sailpoint.com/iamnithesh/32/4884_2.png) [@iamnithesh](https://developer.sailpoint.com/discuss/u/iamnithesh)\
**Post date:** [April 24, 2025, 8:19pm UTC](https://developer.sailpoint.com/discuss/t/workflow-http-request-action-source/115122/5 "2025-04-24T20:19:58Z")

</div>

I don’t think there is (or am sure there is not 😃 ) a way to pass a job to VA.

In fact, there is no incoming traffic allowed to VA (but for local access via port 22) and it’s actually the VA pinging ISC cloud to pick the job from a task list.

Yes, exposing to cloud via an API Gateway is probably your only option in this case

---

<div class="post-metadata">

**Author:** ![iamnithesh](https://sea1.discourse-cdn.com/sailpoint/discuss/user_avatar/developer.sailpoint.com/iamnithesh/32/4884_2.png) [@iamnithesh](https://developer.sailpoint.com/discuss/u/iamnithesh)\
**Post date:** [April 24, 2025, 8:20pm UTC](https://developer.sailpoint.com/discuss/t/workflow-http-request-action-source/115122/6 "2025-04-24T20:20:27Z")

</div>

> [@vishal\_kejriwal1](#):
>
> private API

something that runs inside a private network like on-prem

---

<div class="post-metadata">

**Author:** ![iamnithesh](https://sea1.discourse-cdn.com/sailpoint/discuss/user_avatar/developer.sailpoint.com/iamnithesh/32/4884_2.png) [@iamnithesh](https://developer.sailpoint.com/discuss/u/iamnithesh)\
**Post date:** [April 24, 2025, 8:37pm UTC](https://developer.sailpoint.com/discuss/t/workflow-http-request-action-source/115122/8 "2025-04-24T20:37:56Z")

</div>

private API URLs are accessible from the network only. those URLs are not public and cannot be accessed over internet

---

<div class="post-metadata">

**Author:** ![vishal\_kejriwal1](https://sea1.discourse-cdn.com/sailpoint/discuss/user_avatar/developer.sailpoint.com/vishal_kejriwal1/32/10904_2.png) [@vishal\_kejriwal1](https://developer.sailpoint.com/discuss/u/vishal_kejriwal1)\
**Post date:** [April 24, 2025, 8:46pm UTC](https://developer.sailpoint.com/discuss/t/workflow-http-request-action-source/115122/9 "2025-04-24T20:46:18Z")

</div>

Got it . Thanks !  
got confused with Private API terminology .

---

<div class="post-metadata">

**Author:** ![system](https://global.discourse-cdn.com/sailpoint/original/2X/f/f2136700ed5e3703e0b85e02f6be799dacca7735.png) [@system](https://developer.sailpoint.com/discuss/u/system)\
**Post date:** [June 23, 2025, 8:47pm UTC](https://developer.sailpoint.com/discuss/t/workflow-http-request-action-source/115122/10 "2025-06-23T20:47:14Z")

</div>

This topic was automatically closed 60 days after the last reply. New replies are no longer allowed.
