bearer
Set Authorization Bearer on later HTTP requests
Resolves a templated token and stores Authorization: Bearer <token> in in-run vars (httpAuthHeaders). Later http nodes on this run send that header unless they set Authorization themselves.
This node does not send a request. It does not copy the previous node’s headers (an HTTP response also has headers). The wire is passthrough: whatever arrived from the previous node is what the next non-HTTP node still sees.
Prefer {{secrets.*}} or {{nodes.<id>…}} for the token. The token is not copied onto this node’s output. This is not OAuth2.
Auth vars last for the rest of the run — every later HTTP node inherits Bearer until something overwrites Authorization (another auth helper, or a header on that HTTP node). You do not add a second bearer for mycart. subflow starts with empty vars.
Typical chain: login → extract → bearer → me → mycart (token on both GETs). Add listProducts with skipInheritedAuth when a hop must stay public. Sample: auth-helpers.flow.json.
Data
| Field | Type | Description |
|---|---|---|
label | string | Optional UI label |
token | string | Required; templated. Empty after resolve fails at execute time |
Input / output
| Value | |
|---|---|
| Execute input | Previous node output (passthrough; unused unless you template it into token) |
| Output | Same as input |
| Vars | Merges httpAuthHeaders.Authorization for following HTTP nodes |
Examples
Login → extract → bearer → me → mycart
Previous node is an extract whose output is the access-token string. Following HTTP nodes have no Authorization header — they all inherit Bearer from vars. One bearer covers me and mycart.
login (http POST) → accessToken (extract body.accessToken) → auth (bearer) → me (http GET) → mycart (http GET)
{
"id": "accessToken",
"type": "extract",
"data": { "expression": "body.accessToken" }
}
{
"id": "auth",
"type": "bearer",
"data": {
"label": "Bearer",
"token": "{{nodes.accessToken}}"
}
}
{
"id": "me",
"type": "http",
"data": {
"method": "GET",
"url": "{{env.API_BASE}}/auth/me",
"headers": {}
}
}
{
"id": "mycart",
"type": "http",
"data": {
"method": "GET",
"url": "{{env.API_BASE}}/carts/user/{{nodes.me.body.id}}",
"headers": {}
}
}
Inspect both me and mycart request snapshots: Authorization: Bearer …. No second bearer node.
You can also take the token from an HTTP body without extract: "token": "{{nodes.login.body.accessToken}}".
Token from secrets (no previous HTTP)
Previous node can be start / input. Next HTTP still inherits the header.
{
"id": "auth",
"type": "bearer",
"data": { "token": "{{secrets.API_TOKEN}}" }
}
Skip inherited auth on one hop
After bearer, me and mycart still send the token. listProducts sets skipInheritedAuth: true so that request has no Authorization. The next HTTP hop after it still inherits Bearer unless it also skips (or a later helper overwrites).
{
"id": "listProducts",
"type": "http",
"data": {
"method": "GET",
"url": "{{env.API_BASE}}/products?limit=3",
"headers": {},
"skipInheritedAuth": true
}
}
Override on a later HTTP node
A following HTTP node that sets Authorization (any casing) wins over the helper.