---
url: 'https://docs.workato.com/en/developing-connectors/http/connection-setup.md'
description: >-
  Create an HTTP connection in Workato using auth types like basic, header,
  query params, OAuth2, and AWS to enable HTTP triggers and actions.
---

# Create an HTTP connection {: #http-connection-setup :}

You must set up your connection to the app you plan to use before you can configure HTTP [triggers](/en/developing-connectors/http/building-http-trigger.md) and [actions](/en/developing-connectors/http/building-http-action.md).

The steps required to create an HTTP connection in Workato vary based on the authentication type you plan to use. The HTTP connector supports the following authentication types:

* [None](#authentication-type-none)
* [Basic](#authentication-type-basic)
* [Header auth](#authentication-type-header-auth)
* [Query params](#authentication-type-query-params)
* [Custom](#authentication-type-custom)
* [OAuth2 (authorization code grant)](#authentication-type-oauth-2-0-authorization-code-grant)
* [OAuth2 (client credentials grant)](#authentication-type-oauth-2-0-client-credentials)
* [AWS access key auth](#authentication-type-aws-key-auth)
* [AWS IAM role auth](#authentication-type-aws-iam-role-auth)
* [Azure OAuth 2 (authorization code grant)](#azure-oauth2-authorization-code-grant-authentication-type)
* [Azure OAuth 2 (client credentials grant)](#azure-oauth2-client-credentials-grant-authentication-type)

## None authentication type {: #authentication-type-none :}

The None authentication type enables you to create a connection without providing authentication details. Use this authentication type when you plan to receive a webhook trigger from an app. Workato generates a URL to direct your webhooks to, and retrieves information from the webhook payload.

Complete the following steps to set up an HTTP connection with the None authentication type:

<Stepper>

<Step>

Provide a **Connection name** that identifies your HTTP instance.

![HTTP connector authentication type: None](/images/http/none-authentication.png)
*HTTP connector authentication type: None*

</Step>

<Step>

Use the **Location** drop-down menu to select the project where you plan to store the connection.

</Step>

<Step>

Use the **Connection type** drop-down menu to select the connection type you plan to use.

</Step>

<Step>

Use the **Authentication type** drop-down menu to select **None**.

</Step>

<Step>

Use the **Endpoint has case-sensitive headers?** drop-down to set the case sensitivity for your connection.

::: warning ASYNC MODE LIMITATION

The **Endpoint has case-sensitive headers?** field has no effect when the **Wait for response** field is set to **Yes** (async mode) in the [HTTP action](/en/developing-connectors/http/building-http-action.md). Configure this option only when **Wait for response** is set to **No**.

:::

</Step>

<Step>

Provide your base URL in the **Base URL** field. Recipes can't override this setting.

</Step>

<Step>

Use the **Use custom TLS/SSL certificate settings** drop-down menu to determine your certificate settings.

</Step>

<Step>

Click **Connect**.

</Step>

</Stepper>

## Basic authentication type {: #authentication-type-basic :}

The Basic authentication type requires your username and password. As an alternative to your username and password, you can use an API key or API token retrieved from your account settings. This is a common authentication flow encoded with Base64 in transit over SSL.

<Stepper>

<Step>

Provide a **Connection name** that identifies your HTTP instance.

![HTTP connector authentication type: Basic](/images/http/basic-authentication.png)
*HTTP connector authentication type: Basic*

</Step>

<Step>

Use the **Location** drop-down menu to select the project where you plan to store the connection.

</Step>

<Step>

Use the **Connection type** drop-down menu to select the connection type you plan to use.

</Step>

<Step>

Use the **Authentication type** drop-down menu to select **Basic**.

</Step>

<Step>

Provide your user authentication name in the **Basic auth user** field.

</Step>

<Step>

Provide your user authentication password in the **Basic auth password** field.

</Step>

<Step>

Use the **Endpoint has case-sensitive headers?** drop-down menu to set the case sensitivity for your connection.

::: warning ASYNC MODE LIMITATION

The **Endpoint has case-sensitive headers?** field has no effect when the **Wait for response** field is set to **Yes** (async mode) in the [HTTP action](/en/developing-connectors/http/building-http-action.md). Configure this option only when **Wait for response** is set to **No**.

:::

</Step>

<Step>

Provide your base URL in the **Base URL** field. Recipes can't override this setting.

</Step>

<Step>

Use the **Use custom TLS/SSL certificate settings** drop-down menu to determine your certificate settings.

</Step>

<Step>

Click **Connect**.

</Step>

</Stepper>

## Header auth authentication type {: #authentication-type-header-auth :}

The Header auth authentication type enables you to customize the headers sent in a request. This is useful if your app requires additional headers beyond the standard username and password or API key. You can also use this authentication type if you have a generated token.

Complete the following steps to create an HTTP connection with the **Header auth** authentication type:

<Stepper>

<Step>

Provide a **Connection name** that identifies your HTTP instance.

![HTTP connector authentication type: Header auth](/images/http/header-auth-authentication.png)
*HTTP connector authentication type: Header authorization*

</Step>

<Step>

Use the **Location** drop-down menu to select the project where you plan to store the connection.

</Step>

<Step>

Use the **Connection type** drop-down menu to select the connection type you plan to use.

</Step>

<Step>

Use the **Authentication type** drop-down menu to select **Header auth**.

</Step>

<Step>

Optional. Expand **Header authorization** to add custom auth headers.

</Step>

<Step>

Use the **Endpoint has case-sensitive headers?** drop-down menu to set the case sensitivity for your connection.

::: warning ASYNC MODE LIMITATION

The **Endpoint has case-sensitive headers?** field has no effect when the **Wait for response** field is set to **Yes** (async mode) in the [HTTP action](/en/developing-connectors/http/building-http-action.md). Configure this option only when **Wait for response** is set to **No**.

:::

</Step>

<Step>

Provide your base URL in the **Base URL** field. Recipes can't override this setting.

</Step>

<Step>

Use the **Use custom TLS/SSL certificate settings** drop-down menu to determine your certificate settings.

</Step>

<Step>

Click **Connect**.

</Step>

</Stepper>

## Query params authentication type {: #authentication-type-query-params :}

Use the Query params authentication type when you plan to use applications that require a validated API key as a parameter.

<Stepper>

<Step>

Provide a **Connection name** that identifies your HTTP instance.

![HTTP connector authentication type: Query params](/images/http/query-params-authentication.png)
*HTTP connector authentication type: Query params*

</Step>

<Step>

Use the **Location** drop-down menu to select the project where you plan to store the connection.

</Step>

<Step>

Use the **Connection type** drop-down menu to select the connection type you plan to use.

</Step>

<Step>

Use the **Authentication type** drop-down menu to select **Query params**.

</Step>

<Step>

Use the **Endpoint has case-sensitive headers?** drop-down menu to set the case sensitivity for your connection.

::: warning ASYNC MODE LIMITATION

The **Endpoint has case-sensitive headers?** field has no effect when the **Wait for response** field is set to **Yes** (async mode) in the [HTTP action](/en/developing-connectors/http/building-http-action.md). Configure this option only when **Wait for response** is set to **No**.

:::

</Step>

<Step>

Optional. Expand **Url parameters** to add URL parameters.

</Step>

<Step>

Provide your base URL in the **Base URL** field. Recipes can't override this setting.

</Step>

<Step>

Use the **Use custom TLS/SSL certificate settings** drop-down menu to determine your certificate settings.

</Step>

<Step>

Click **Connect**.

</Step>

</Stepper>

## Custom authentication type {: #authentication-type-custom :}

The Custom authentication type enables you to use a tailored combination of input fields to satisfy custom authentication requirements.

<Stepper>

<Step>

Provide a **Connection name** that identifies your HTTP instance.

![Custom http connector](/images/http/custom-authentication.png)*HTTP connector authentication type: Custom*

</Step>

<Step>

Use the **Location** drop-down menu to select the project where you plan to store the connection.

</Step>

<Step>

Use the **Connection type** drop-down menu to select the connection type you plan to use.

</Step>

<Step>

Use the **Authentication type** drop-down menu to select **Custom**.

</Step>

<Step>

Optional. Provide your user authentication name in the **Basic auth user** field.

</Step>

<Step>

Optional. Provide your user authentication password in the **Basic auth password** field.

</Step>

<Step>

Expand **Header authorization** to add custom auth headers.

</Step>

<Step>

Use the **Endpoint has case-sensitive headers?** drop-down menu to set the case sensitivity for your connection.

::: warning ASYNC MODE LIMITATION

The **Endpoint has case-sensitive headers?** field has no effect when the **Wait for response** field is set to **Yes** (async mode) in the [HTTP action](/en/developing-connectors/http/building-http-action.md). Configure this option only when **Wait for response** is set to **No**.

:::

</Step>

<Step>

Expand **Url parameters** to add URL parameters.

</Step>

<Step>

Provide your base URL in the **Base URL** field. Recipes can't override this setting.

</Step>

<Step>

Use the **Use custom TLS/SSL certificate settings** drop-down menu to determine your certificate settings.

</Step>

<Step>

Click **Connect**.

</Step>

</Stepper>

## On-prem NTLM authentication type {: #authentication-type-on-prem-ntlm :}

Use the NT LAN Manager (NTLM) authentication type if you have a configured Workato [on-prem agent](/en/on-prem.md) and the application you plan to use requires NTLM authentication.

Complete the following steps to set up your HTTP connection with NTLM authentication:

<Stepper>

<Step>

Provide a **Connection name** that identifies your HTTP instance.

![Custom http connector](/images/http/ntlm-authentication.png)*HTTP connector authentication type: On-prem NTLM*

</Step>

<Step>

Use the **Location** drop-down menu to select the project where you plan to store the connection.

</Step>

<Step>

Use the **Connection type** drop-down menu to select the connection type you plan to use.

</Step>

<Step>

Use the **Authentication type** drop-down menu to select **On-prem NTLM**.

</Step>

<Step>

Skip the **Endpoint has case-sensitive headers?** field. This option sets the case sensitivity for your connection. However, it has no effect for on-prem connections.

</Step>

<Step>

Provide your NTLM authentication domain or workstation name in the **NTLM authentication** field.

</Step>

<Step>

Provide your NTLM authentication username in the **Username** field.

</Step>

<Step>

Provide your NTLM authentication password in the **Password** field.

</Step>

<Step>

Optional. Expand **Optional properties** to configure additional profile properties.

</Step>

<Step>

Click **Connect**.

</Step>

</Stepper>

The following profile properties are supported:

| Property name | Description |
|------------------|-------------------------------------------|
| NTLM authentication | NTLM authentication domain and workstation name. |
| Username | Username for NTLM authentication. |
| Password | Password for NTLM authentication. |
| Base URL | The base URL for NTLM resources. |
| Connections per route | **Optional**. Sets the number of connections per route/host (must be a positive number, default 5). |
| Maximum connections | **Optional**. Sets the maximum number of connections (must be a positive number, default 10). |
| Timeout | **Optional** The timeout in milliseconds used when requesting a connection (must be a positive number, default 10000). |
| Connection request timeout | **Optional** The timeout in milliseconds until a connection is established (must be a positive number, default 10000). |
| Socket timeout | **Optional** The socket timeout in milliseconds, which is the timeout for waiting for data or, put differently, a maximum period inactivity between two consecutive data packets (must be a positive number, default 10000). |
| Verify host | **Optional**. Specifies whether to enable verification of the host name for SSL/TLS connections (default true). |
| Trust all | **Optional**. Specifies whether trust all certificates for SSL/TLS connections (default false). |

Refer to the following list for supported HTTP methods for NTLM connections:

* `GET`
* `POST`
* `PUT`
* `PATCH`
* `DELETE`
* `HEAD`

Refer to the [connection profiles documentation](/en/on-prem/agents/connection/profile.md#ntlm-profile) if your on-prem group connections use `config.yml`.

## OAuth 2.0 authorization code grant authentication type {: #authentication-type-oauth-2-0-authorization-code-grant :}

The OAuth 2.0 authorization code grant authentication type enables you to provide third parties with access to your apps without disclosing your username and password. Confidential and public clients use this authentication type to exchange an authorization code for an access token. Workato redirects you to your app to enter your login credentials when you use this authentication type. This enables Workato to act on your behalf when making API requests.

Complete the following steps to set up your HTTP connection with OAuth 2.0 authorization code grant authentication:

<Stepper>

<Step>

Provide a **Connection name** that identifies your HTTP instance.

![HTTP (OAuth2 auth code grant) connector's connection fields](/images/http/oauth-code-grant-authentication.png)
*HTTP (OAuth2 authorization code grant) connector's connection fields*

</Step>

<Step>

Use the **Location** drop-down menu to select the project where you plan to store the connection.

</Step>

<Step>

Use the **Connection type** drop-down menu to select the connection type you plan to use.

</Step>

<Step>

Use the **Authentication type** drop-down menu to select **OAuth 2 (authorization code grant)**.

</Step>

<Step>

Use the **Endpoint has case-sensitive headers?** drop-down menu to set the case sensitivity for your connection.

::: warning ASYNC MODE LIMITATION

The **Endpoint has case-sensitive headers?** field has no effect when the **Wait for response** field is set to **Yes** (async mode) in the [HTTP action](/en/developing-connectors/http/building-http-action.md). Configure this option only when **Wait for response** is set to **No**.

:::

</Step>

<Step>

Provide your authorization URL in the **OAuth2 authorization URL** field.

</Step>

<Step>

Provide your token in the **OAuth2 token URL** field. This auth token is used to verify that Workato has permission to access your app.

</Step>

<Step>

Provide your client ID in the **OAuth2 client ID** field. The client ID identifies you as the user who’s sending the API requests.

</Step>

<Step>

Use the **How does the API require credentials to be sent to request a token?** drop-down menu to determine whether to send the client ID and secret in the token request body or as a base64 encoded string in the header.

</Step>

<Step>

Provide your base URL in the **Base URL** field. Recipes can't override this setting.

</Step>

<Step>

Use the **Use custom TLS/SSL certificate settings** drop-down menu to determine your certificate settings.

</Step>

<Step>

Optional. Expand **Advanced settings** to configure OAuth2 scopes and token settings.

</Step>

<Step>

Click **Connect**.

</Step>

</Stepper>

## OAuth 2.0 client credentials grant authentication type {: #authentication-type-oauth-2-0-client-credentials :}

Use the OAuth 2.0 client credentials grant authentication type if you plan to enable the client to request an access token using only client credentials. This authentication type is usually used when the client is requesting access to the protected resources under its control or for machine-to-machine authentication where a specific user’s permission to access data is not required. The client credentials grant type can only be used by confidential clients.

Complete the following steps to set up your HTTP connection with OAuth2 client credentials grant authentication:

<Stepper>

<Step>

Provide a **Connection name** that identifies your HTTP instance.

![HTTP (OAuth2 client credentials grant) connector's connection fields](/images/http/oauth-client-credentials-authentication.png)*HTTP (OAuth2 client credentials grant) connector's connection fields*

</Step>

<Step>

Use the **Location** drop-down menu to select the project where you plan to store the connection.

</Step>

<Step>

Use the **Connection type** drop-down menu to select the connection type you plan to use.

</Step>

<Step>

Use the **Authentication type** drop-down menu to select **OAuth 2 (client credentials grant)**.

</Step>

<Step>

Use the **Endpoint has case-sensitive headers?** drop-down menu to set the case sensitivity for your connection.

::: warning ASYNC MODE LIMITATION

The **Endpoint has case-sensitive headers?** field has no effect when the **Wait for response** field is set to **Yes** (async mode) in the [HTTP action](/en/developing-connectors/http/building-http-action.md). Configure this option only when **Wait for response** is set to **No**.

:::

</Step>

<Step>

Provide your OAuth2 token URL in the **OAuth2 token URL** field.

</Step>

<Step>

Provide your client ID in the **OAuth2 client ID** field.

</Step>

<Step>

Provide your client secret in the **OAuth2 client secret** field.

</Step>

<Step>

Use the **How does the API require credentials to be sent to request a token?** drop-down menu to determine whether to send the client ID and secret in the token request body or as a base64 encoded string in the header.

</Step>

<Step>

Provide your base URL in the **Base URL** field. Recipes can't override this setting.

</Step>

<Step>

Use the **Use custom TLS/SSL certificate settings** drop-down menu to determine your certificate settings.

</Step>

<Step>

Optional. Expand **Advanced settings** to configure OAuth2 scopes.

</Step>

<Step>

Click **Connect**.

</Step>

</Stepper>

<details class="accordion-steps">
<summary>OAuth2 client credentials grant example</summary>
<div>

#### Connect to Eventbrite with OAuth 2.0 client credentials grant {: #example-connecting-to-eventbrite-via-oauth2 :}

Go to the app's documentation page to obtain your authorization URL and the access token URL. You must append additional parameters to the URL as specified by the app. For example, Eventbrite requires the following format for a post request:

```
https://www.eventbrite.com/oauth/authorize?response_type=code&client_id=YOUR_CLIENT_KEY`

```

![Eventbrite OAuth 2.0 authentication page](/images/http/eventbrite-authentication.png)
*Eventbrite OAuth 2.0 authentication page*

The following information is required to enable Workato to handle the client key:

Eventbrite authorization URL:

```
https://www.eventbrite.com/oauth/authorize?response_type=code
```

Eventbrite access token URL:

```
https://www.eventbrite.com/oauth/token
```

You must have a client ID and client secret to connect to your Eventbrite account successfully. You must register an app with Eventbrite to obtain these credentials.

Complete the following steps to obtain your credentials:

<Stepper>

<Step>

Log in to Eventbrite and navigate to **Account Settings > App Management**.

![Eventbrite's App Management screen](/images/http/eventbrite-app-management.png)
*Eventbrite's app management screen*

</Step>

<Step>

Locate your client ID (also called key) in the **App Management** page.

</Step>

<Step>

Expand the **Show Client Secret and OAuth Token** section to retrieve the client secret.

</Step>

<Step>

Navigate to the **App Extension** section to input the callback URL: `https://www.workato.com/oauth/callback`

</Step>

</Stepper>

</div>
</details>

## AWS access key auth authentication type {: #authentication-type-aws-key-auth :}

AWS Access key authentication enables you use access keys you have created as either a root user or an IAM user in AWS. You can assign a maximum of two access keys per user (root user or IAM user). A disabled key can't be used, but it does count toward your quota of two access keys. When you delete an access key, it is permanently removed from the app but can be replaced with a new access key. Refer to the [AWS documentation](https://docs.aws.amazon.com/general/latest/gr/aws-sec-cred-types.html#programmatic-access) for more information.

::: tip AWS IAM AUTHENTICATION RECOMMENDED

We recommend that you use AWS IAM authentication instead of access key authentication.

:::

Complete the following steps to set up your HTTP connection with AWS access key authentication:

<Stepper>

<Step>

Provide a **Connection name** that identifies your HTTP instance.

![HTTP (AWS access key auth) connector's connection fields](/images/http/aws-access-key-authentication.png)
*HTTP (AWS Access key auth)*

</Step>

<Step>

Use the **Location** drop-down menu to select the project where you plan to store the connection.

</Step>

<Step>

Use the **Connection type** drop-down menu to select the connection type you plan to use.

</Step>

<Step>

Use the **Authentication type** drop-down menu to select **AWS access key auth**.

</Step>

<Step>

Provide your AWS service name in the **AWS name** field.

</Step>

<Step>

Provide your account region in the **Region** field. Region is typically provided in the account URL. For example, if your account URL is `https://eu-west-1.console.s3.amazon.com`, your region is `eu-west-1`.

</Step>

<Step>

Provide your AWS access key ID in the **AWS access key ID** field. Go to your AWS account and click **My Security Credentials > Users** to find the access key ID.

</Step>

<Step>

Provide your secret access key in the **Secret access key** field. Go to your AWS account and click **My Security Credentials > Users** to find your secret access key.

</Step>

<Step>

Use the **Endpoint has case-sensitive headers?** drop-down menu to set the case sensitivity for your connection.

::: warning ASYNC MODE LIMITATION

The **Endpoint has case-sensitive headers?** field has no effect when the **Wait for response** field is set to **Yes** (async mode) in the [HTTP action](/en/developing-connectors/http/building-http-action.md). Configure this option only when **Wait for response** is set to **No**.

:::

</Step>

<Step>

Provide your base URL in the **Base URL** field. Recipes can't override this setting.

</Step>

<Step>

Click **Connect**.

</Step>

</Stepper>

## AWS IAM role auth authentication type {: #authentication-type-aws-iam-role-auth :}

AWS IAM role authentication enables you to provide a dedicated role in your AWS instance for Workato to use. By provisioning a dedicated IAM profile, the owner of the AWS instance can grant Workato access to AWS resources without sharing AWS security credentials. It also helps to maintain permission boundaries, including controlled access to specific AWS services and actions that are permitted by a third-party application, such as Workato.

We recommend that you only grant required permissions, and avoid using AllAccess policies whenever possible.

::: tip AWS IAM AUTHENTICATION RECOMMENDED

We generally recommend that you use AWS IAM authentication instead of access key authentication.

:::

Complete the following steps to set up your HTTP connection with AWS IAM role authentication:

<Stepper>

<Step>

Provide a **Connection name** that identifies your HTTP instance.

![HTTP (AWS IAM) connector's connection fields](/images/http/aws-iam-role-authentication.png)
*HTTP (AWS IAM role auth) connector's connection fields*

</Step>

<Step>

Use the **Location** drop-down menu to select the project where you plan to store the connection.

</Step>

<Step>

Use the **Connection type** drop-down menu to select the connection type you plan to use.

</Step>

<Step>

Use the **Authentication type** drop-down menu to select **AWS IAM role auth**.

</Step>

<Step>

Provide your AWS service name in the **AWS name** field.

</Step>

<Step>

Provide your account region in the **Region** field. For example, if your account URL is `https://eu-west-1.console.s3.amazon.com`, your region is `eu-west-1`.

</Step>

<Step>

Provide your IAM role ARN in the **IAM role ARN** field. Refer to the [How to retrieve IAM role ARN](/en/developing-connectors/http/connection-setup.md#authentication-type-aws-iam-role-auth) section for more information.

</Step>

<Step>

Use the **Endpoint has case-sensitive headers?** drop-down menu to set the case sensitivity for your connection.

::: warning ASYNC MODE LIMITATION

The **Endpoint has case-sensitive headers?** field has no effect when the **Wait for response** field is set to **Yes** (async mode) in the [HTTP action](/en/developing-connectors/http/building-http-action.md). Configure this option only when **Wait for response** is set to **No**.

:::

</Step>

<Step>

Provide your base URL in the **Base URL** field. Recipes can't override this setting.

</Step>

<Step>

Click **Connect**.

</Step>

</Stepper>

### How to retrieve IAM role ARN {: #how-to-retrieve-iam-role-arn :}

Use the following steps to retrieve the **Role ARN** required for the connection setup. Remember to use the Workato generated external ID found on the connection page.

<Stepper>

<Step>

Go to IAM and select **Roles** > **Create role**.

![AWS IAM authentication page - create role](/images/developing-connectors/http/create-new-iam-role.png)

</Step>

<Step>

Select **Another AWS account** and input Workato's Account ID.

</Step>

<Step>

Select **Require external ID** and provide the Workato generated **External ID**.Every Workato user has a unique **External id**, for example, `workato_iam_external_id_77630`. You can find this value in the **IAM role ARN** section of the [connection setup](#authentication-type-aws-iam-role-auth).

![AWS IAM authentication page - entity type - Another AWS account](/images/developing-connectors/http/select-trusted-entity.png)

If you require more granular control over how your HTTP connector is used in Workato, you can configure the connection at the project level by changing the scope of the external ID, [learn more](/en/security/data-protection/secrets-management/iam-role-based-authentication-for-aws.md)

</Step>

<Step>

Attach permission policies to this role when prompted. This step enables you to provide fine-grained permission controls for Workato. The policies that you attach to this role should be as narrow as possible.

</Step>

<Step>

Select an appropriate tag for the IAM role if you are using object tagging.

</Step>

<Step>

Provide the IAM Role with an appropriate name and description. Workato recommends that you avoid using a non-guessable resource-id in the URN and that you don't include the external ID.

![Review role](/images/developing-connectors/http/review-role.png)

The IAM Role is created.

![AWS Role summary page](/images/developing-connectors/http/role-summary-page.png)

</Step>

</Stepper>

## Azure OAuth2 authorization code grant authentication type {: #azure-oauth2-authorization-code-grant-authentication-type :}

The Azure OAuth2 authorization code grant authentication type enables you to provide third parties with access to your Azure apps without having to disclose your username and password. Confidential and public clients use this authentication type to exchange an authorization code for an access token.

Complete the following steps to set up your HTTP connection with Azure OAuth2 authorization code grant authentication:

<Stepper>

<Step>

Provide a **Connection name** that identifies your HTTP instance.

![Azure OAuth2 code grant authentication](/images/http/azure-oauth-code-grant-authentication.png)*Azure OAuth2 code grant authentication*

</Step>

<Step>

Use the **Location** drop-down menu to select the project where you plan to store the connection.

</Step>

<Step>

Use the **Connection type** drop-down menu to select the connection type you plan to use.

</Step>

<Step>

Use the **Authentication type** drop-down menu to select **Azure OAuth 2 (authorization code grant)**.

</Step>

<Step>

Provide your tenant ID in the **Azure Tenant ID** field. If you have an Azure subscription, enter your Tenant ID. Otherwise, use common.

</Step>

<Step>

Use the **Endpoint has case-sensitive headers?** drop-down menu to set the case sensitivity for your connection.

::: warning ASYNC MODE LIMITATION

The **Endpoint has case-sensitive headers?** field has no effect when the **Wait for response** field is set to **Yes** (async mode) in the [HTTP action](/en/developing-connectors/http/building-http-action.md). Configure this option only when **Wait for response** is set to **No**.

:::

</Step>

<Step>

Provide your client ID in the **OAuth2 client ID** field.

</Step>

<Step>

Provide your client secret in the **OAuth2 client secret** field.

</Step>

<Step>

Use the **Azure endpoint version** to select the version of the Azure endpoints to use. Default is 2.0.

</Step>

<Step>

Provide your base URL in the **Base URL** field. Recipes can't override this setting.

</Step>

<Step>

Optional. Expand **Advanced settings** to configure OAuth2 scopes.

</Step>

<Step>

Click **Sign in with Microsoft**.

</Step>

</Stepper>

## Azure OAuth2 client credentials grant authentication type {: #azure-oauth2-client-credentials-grant-authentication-type :}

You can use the Azure OAuth 2.0 client credentials grant authentication type if you plan to enable the client to request an access token using only client credentials. This authentication type is usually used when the client is requesting access to the protected resources under its control or for machine-to-machine authentication where a specific user’s permission to access data is not required. The client credentials grant type can only be used by confidential clients.

Complete the following steps to set up your HTTP connection with Azure OAuth2 client credentials grant authentication:

<Stepper>

<Step>

Provide a **Connection name** that identifies your HTTP instance.

![Azure OAuth2 client credentials](/images/http/azure-oauth-client-credentials-authentication.png)*Azure OAuth2 client credentials authentication*

</Step>

<Step>

Use the **Location** drop-down menu to select the project where you plan to store the connection.

</Step>

<Step>

Use the **Connection type** drop-down menu to select the connection type you plan to use.

</Step>

<Step>

Use the **Authentication type** drop-down menu to select **Azure OAuth 2 (client credentials grant)**.

</Step>

<Step>

Provide your tenant ID in the **Azure Tenant ID** field. If you have an Azure subscription, enter your Tenant ID. Otherwise, use common.

</Step>

<Step>

Use the **Endpoint has case-sensitive headers?** drop-down to set the case sensitivity for your connection.

::: warning ASYNC MODE LIMITATION

The **Endpoint has case-sensitive headers?** field has no effect when the **Wait for response** field is set to **Yes** (async mode) in the [HTTP action](/en/developing-connectors/http/building-http-action.md). Configure this option only when **Wait for response** is set to **No**.

:::

</Step>

<Step>

Provide your client ID in the **OAuth2 client ID** field.

</Step>

<Step>

Provide your client secret in the **OAuth2 client secret** field.

</Step>

<Step>

Use the **Azure endpoint version** to select the version of the Azure endpoints to use. Default is 2.0.

</Step>

<Step>

Provide your base URL in the **Base URL** field. Recipes can't override this setting.

</Step>

<Step>

Optional. Expand **Advanced settings** to configure OAuth2 scopes.

</Step>

<Step>

Click **Sign in with Microsoft**.

</Step>

</Stepper>

## More resources {: #more-resources :}

* [Build an HTTP trigger](/en/developing-connectors/http/building-http-trigger.md)
* [Build an HTTP action](/en/developing-connectors/http/building-http-action.md)
