API
Protect the private Workflow to AI API
Connect Workflow servers to AI servers without making the private API public.
Keep this connection private
Workflow servers use private AI requests for model chat, knowledge search, and workflow text.
These requests do not appear in the public OpenAPI file.
Set up both services
- Give Workflow the private AI address.
- Create a long random service token.
- Give the same token to the AI servers.
- Set a request time limit.
- Use HTTPS on the private network.
Limit the network
Only Workflow servers and trusted administrator networks should reach the private AI address. Use mTLS at the internal load balancer or service mesh in production.

The token is not enough by itself
The token proves that the request came from Workflow. Pūnaha still checks access to the model or knowledge database.
Was this page helpful?
Your answer helps us improve the documentation.
Do not include personal information, customer information, passwords, or keys.