Where to set authentication

Most services need to know who’s calling them. In Echo7, you can set authentication on the integration, on an individual agent action, or in the header field.

Level Use it when
Integration Several agents use the same service and credentials. This is the recommended approach, and the only option for OAuth 2.1.
Agent action A single action needs different credentials, or the agent isn’t part of an integration.
Header field The service uses an API key or a custom format, such as X-API-Key.

Choosing an authentication type

Scenario Choose
Public endpoint, no sign-in needed None
API key in a header such as X-API-Key or X-Goog-Api-Key None + add the header
Username and password over HTTPS Basic
A token you already have Bearer
Legacy server that asks for Digest Digest
Legacy OAuth 1.0 API OAuth 1.0
System-to-system access with a client ID and secret OAuth 2.0 – client credentials
A user must sign in and give consent OAuth 2.1 on the integration

Using an API key in a header

1

Create an integration parameter of type Password, for example integration_api_key.

2

Set the authentication type to None, defined by the integration or in the header field.

3

In Header, add one header per line, for example X-API-Key: {{integration_api_key}}.

Echo7 replaces {{integration_api_key}} with each assistant’s own value at the time of the call.

How integration and action settings combine

  • If an action has its own URL or server, it’s used; otherwise the integration’s is used.
  • If an action has its own headers, they replace the integration’s headers – they aren’t merged. Include every header you need.
  • If an action is set to “None, defined by the integration”, it inherits the integration’s authentication.
  • When Echo7 manages authentication (Basic, Bearer, OAuth), it creates the Authorization header for you – don’t add one manually.

OAuth 2.1

OAuth 2.1 is for services where a user signs in and grants access. It’s configured on the integration; when you add the integration to an assistant (save the assistant first), Echo7 shows the provider’s sign-in page. The tokens are then stored for that assistant, so its agents can use the service without further setup.

Security tips

  • Always use HTTPS with Basic authentication.
  • Store secrets in Password-type parameters, not in agent bodies or endpoints.
  • Use separate credentials per customer or assistant where possible.

Prefer a guided walkthrough? Book a training session and an Echo7 specialist will help your team set it up.

Book a training session

Want to go deeper?

This guide covers the essentials. For detailed reference on every setting and feature, explore the full Echo7 Wiki.

Echo7 Wiki

Want a hand getting set up?

Book a training session with an Echo7 specialist and get your assistant working for your team.