API

Protect the private Workflow to AI API

Connect Workflow servers to AI servers without making the private API public.

Keep this connection private

Workflow servers use private AI requests for model chat, knowledge search, and workflow text.

These requests do not appear in the public OpenAPI file.

Set up both services

  1. Give Workflow the private AI address.
  2. Create a long random service token.
  3. Give the same token to the AI servers.
  4. Set a request time limit.
  5. Use HTTPS on the private network.

Limit the network

Only Workflow servers and trusted administrator networks should reach the private AI address. Use mTLS at the internal load balancer or service mesh in production.

The System operations page used to watch Workflow and AI services
Watch both services and their queues when you test the private connection. Earlier development interface, captured 22 August 2026. Follow the current text for RC1. Open the full image.

The token is not enough by itself

The token proves that the request came from Workflow. Pūnaha still checks access to the model or knowledge database.

Pūnaha Docs

Search the guides

Enter at least two characters.

    Product screen

    View the full screenshot