REST queries
REST queries are configured in API Editor for a saved REST connection.
Create a query
- Open the API builder
- Click New API in the sidebar to create a draft query
- Select the API connection to use
- Enter a clear query name
- Set HTTP method
- Enter endpoint path or full URL. Note that full URLs must include the protocol (e.g.,
https://example.com) and must match the origin (protocol and host) of the datasource base URL. - Configure Params, Headers, Body, and Bindings
- Select an auth config (if required)
- Click Send
- Validate request, response, and schema
- Click Save Query
You can also start from Workspace Settings > Connections > APIs and click Open in API Editor on an existing connection.
Inspecting requests and responses
After clicking Send, the side panel displays the results of your query. You can toggle between two views using the switcher at the top of the panel:
Response view
Displays the status code, execution time, and payload size. You can inspect the raw response body, view the generated schema, and configure a transformer if needed.
Request view
Displays the exact HTTP request that Budibase sent to the endpoint, including the final URL, headers, query parameters, and body.
To protect your security, Budibase automatically sanitizes this preview:
- Credentials: Sensitive headers like
Authorization,Cookie, orx-api-keyare redacted and displayed as badges (e.g.,Auth tokenorRedacted). - Environment variables: Any environment variables used in the query are displayed as their variable name (e.g.,
{{ env.API_KEY }}) rather than their resolved secret value.
Query fields reference
| Area | What to configure | Notes |
|---|---|---|
| Method | GET, POST, PUT, PATCH, DELETE | Must match endpoint contract |
| URL/Path | Endpoint path or full URL | Usually path + connection base URL. Full URLs require a protocol prefix and must match the datasource origin. |
| Params | Query-string key/value pairs | Supports bindings |
| Headers | Request headers | Supports bindings and shared defaults |
| Body | Payload for write/query APIs | Use valid JSON/XML/Text as required |
| Projects | Assign query to one or more projects | Used for organizing workspace resources |
| Auth selection | Connection auth config to apply | Choose per-query |
| Transformer | JavaScript response shaping | Re-test schema after changes |
Query lifecycle checklist
Before first use:
- Send query and confirm status code
- Inspect the Request to ensure bindings and headers are correctly formed
- Validate response shape matches expected schema
- Save query
Before production use:
- Test with realistic runtime bindings
- Validate empty-state response behavior
- Validate error-state handling in app actions
Transformer example (flatten nested response)
const from = data.from
const to = data.to
return {
fromId: from.id,
fromSections: from.sections,
toId: to.id,
toSections: to.sections,
}After applying a transformer:
- Click Send.
- Confirm schema fields.
- Save the query.
Common issues
- Missing protocol: Full URLs must include
http://orhttps://to be valid. The Send button will be disabled and a warning displayed if the protocol is missing. 401/403: wrong or missing auth config.404: wrong path or base URL.400: REST query path must remain on the datasource origin. This occurs if an absolute URL or dynamic binding targets a different origin than the one configured in the datasource.400: Redirect to a different origin is not permitted. Cross-origin redirects are blocked for security to prevent datasource credentials from being sent off-origin.400/422: request payload does not match API contract.- Empty rows with
200: binding values not populated as expected. - Schema mismatch in app: query changed but app bindings not updated.
Related guides
Updated about 1 month ago