Make your first request
Type /http to open the local manager with Request, Profiles, Config and Saved Requests sections. Or execute directly in the composer:
/http GET https://api.example.com/status
/http POST https://api.example.com/light -j '{"state":"on"}'
/http GET https://api.example.com/status --timeout 10s
Methods include GET, POST, PUT, PATCH, DELETE, HEAD and OPTIONS. The response appears from http@api with status, timing and formatted payload; images and supported files use COM1 file packet handling.
Save a profile and environment
/http profile add home https://api.example.com
/http env add @home prod https://prod.example.com
/http env add @home staging https://staging.example.com
/http use @home/prod
/http home GET /status
Requests through named profiles appear from participants like home@http.
Handle secrets separately
/http secret set @home/prod API_TOKEN
/http auth bearer @home/prod
/http var set @home/prod DEVICE_ID sensor01
/http home/prod GET /devices/{{DEVICE_ID}}
The secure command flow prompts for secret values and stores them in platform secure storage. Do not put real tokens directly into visible command examples or chat messages. Public/plain variables and nonsecret profile settings use local application storage.
Save and run an endpoint
/http save @home status GET /status
/http home/prod status
/http run @home/prod status
Upload a file
/http home/prod POST /upload -F "note=test" -F "file=@pick"
The COM1 file picker provides the multipart upload. Request execution happens locally on the device, so a private network or localhost endpoint can work where the device itself can reach it; permissions and platform restrictions still apply.
Limits and security boundaries
- Request/response timeouts, redirects and response size are bounded (Pass 1 notes document a 10 MB response cap, up to 60s timeout and max five redirects).
- Credentials are scrubbed from displayed HTTP transcripts on a best-effort basis, but never paste secrets into chat or trust redaction to catch every possible provider-specific token format.
- Network requests contact the external server normally even when the COM1 conversation uses Secure Link. That server can observe your request.
- COM1's profile store and configuration are local to the device/account; you should not assume cross-device sync of API secrets.
More command forms are available via /http help within the app.