COM1_
TERMINAL MODEGET STARTED →
NET://HTTP PASS 2

HTTP is a participant.

An API client that lives in your chat. Profile it, call it, see it reply.

Make your first request

Type /http to open the local manager with Request, Profiles, Config and Saved Requests sections. Or execute directly in the composer:

/http GET https://api.example.com/status
/http POST https://api.example.com/light -j '{"state":"on"}'
/http GET https://api.example.com/status --timeout 10s

Methods include GET, POST, PUT, PATCH, DELETE, HEAD and OPTIONS. The response appears from http@api with status, timing and formatted payload; images and supported files use COM1 file packet handling.

Save a profile and environment

/http profile add home https://api.example.com
/http env add @home prod https://prod.example.com
/http env add @home staging https://staging.example.com
/http use @home/prod
/http home GET /status

Requests through named profiles appear from participants like home@http.

Handle secrets separately

/http secret set @home/prod API_TOKEN
/http auth bearer @home/prod
/http var set @home/prod DEVICE_ID sensor01
/http home/prod GET /devices/{{DEVICE_ID}}

The secure command flow prompts for secret values and stores them in platform secure storage. Do not put real tokens directly into visible command examples or chat messages. Public/plain variables and nonsecret profile settings use local application storage.

Save and run an endpoint

/http save @home status GET /status
/http home/prod status
/http run @home/prod status

Upload a file

/http home/prod POST /upload -F "note=test" -F "file=@pick"

The COM1 file picker provides the multipart upload. Request execution happens locally on the device, so a private network or localhost endpoint can work where the device itself can reach it; permissions and platform restrictions still apply.

Limits and security boundaries

  • Request/response timeouts, redirects and response size are bounded (Pass 1 notes document a 10 MB response cap, up to 60s timeout and max five redirects).
  • Credentials are scrubbed from displayed HTTP transcripts on a best-effort basis, but never paste secrets into chat or trust redaction to catch every possible provider-specific token format.
  • Network requests contact the external server normally even when the COM1 conversation uses Secure Link. That server can observe your request.
  • COM1's profile store and configuration are local to the device/account; you should not assume cross-device sync of API secrets.

More command forms are available via /http help within the app.