http_callout

Calls an external HTTP service during request processing and feeds its response into branch-chain evaluation.
On this page

Calls an external HTTP service during request processing and feeds its response into branch-chain evaluation.

Configuration Notes

Experimental: requires the http-callout-filter cargo feature, which is off by default and activates the experimental marker. This filter is a work in progress and its configuration surface may change between releases.

Makes an outbound HTTP request during request processing, optionally forwarding the request body and downstream headers. Extracts values from the callout response via JSONPath and writes them to [FilterResultSet] for branch-chain evaluation.

Configuration

FieldTypeRequiredDescription
targetTargetConfigyesCallout target configuration.
target.urlstringyesAbsolute HTTP(S) URL to call.
target.allow_private_addressesboolnoAllow the target to resolve to a private, loopback, or link-local address. Defaults to false. Set to true explicitly when a trusted loopback/sidecar or private service is the intended destination. When disabled, the callout is rejected at request time if any resolved peer address is private/loopback/link-local — including a hostname that resolves to such an address (e.g. cloud metadata at 169.254.169.254).
target.timeoutDurationnoRequest timeout (e.g. "2s", "500ms").
target.headersHeaderEntry[]noStatic headers to send with every callout.
target.headers[].namestringyesHeader name.
target.headers[].valuestringyesHeader value. Supports ${VAR} env-var expansion.
target.forward_headersstring[]noHeaders to copy from the downstream request.
target.bodyobject<string, string>noReshape the downstream request body for the callout. Each key becomes a field in the callout JSON body; each value is a JSONPath expression evaluated against the downstream body. When set, only the listed fields are sent — the downstream body goes to upstream untouched. When absent, the downstream body is forwarded verbatim.
requestRequestConfignoRequest phase and body forwarding options.
request.phaserequest_headers | request_bodynoPhase at which the callout executes.
request.max_body_bytesintegernoMaximum body bytes to buffer. Caps both the forwarded request body and the accepted callout response body.
responseResponseConfignoResponse extraction and header injection.
response.extractExtractionConfig[]noJSONPath extractions to write into [FilterResultSet].
response.extract[].json_pathstringyesJSONPath expression to evaluate against the response body.
response.extract[].result_keystringyesKey to write the result under in [FilterResultSet].
response.inject_headersstring[]noCallout response headers to inject into the upstream request on success.
on_failureclosed | opennoBehavior when the callout itself fails (DNS, connect, timeout, I/O): open continues the request, closed rejects it. Note: this is distinct from the pipeline entry’s own failure_mode key, which governs how the pipeline reacts when a filter returns an error. Core strips failure_mode as a structural key before this config is parsed, so it cannot be used as an alias here.
status_on_errorintegernoHTTP error status code (400..=599) to return when rejecting on error.
circuit_breakerCircuitBreakerConfignoCircuit breaker configuration.
circuit_breaker.failure_thresholdintegeryesConsecutive failures to trip the breaker.
circuit_breaker.recovery_timeoutDurationyesRecovery window (e.g. "30s").
max_depthintegernoMaximum callout depth for loop prevention.