Fini can use customer data from databases and data warehouses, but the agent flow does not connect to Redshift, Snowflake, BigQuery, Postgres, or another warehouse over JDBC or ODBC directly. Fini calls an HTTPS endpoint. That endpoint owns the warehouse credentials, network access, query logic, and response shape. Use this pattern when an agent needs account status, subscription details, eligibility, order history, risk flags, or other structured customer context stored in a warehouse.
Fini’s configurable calls are HTTP calls. A database or warehouse connection means Fini -> HTTPS endpoint -> warehouse -> JSON response -> Fini, not arbitrary SQL generated by the agent.
The recommended setup is a customer-hosted data access endpoint. Host a small API in AWS Lambda, API Gateway, Cloud Run, Cloud Functions, your backend, or another service that already has secure access to the warehouse. The endpoint should expose named lookup routes, not a general SQL interface. For example:
Do not give the agent unrestricted warehouse access or let it construct arbitrary SQL. Keep query selection predefined, read-only when possible, and return only fields needed for personalization, guardrails, or workflow logic.

Setup patterns

Customer-hosted endpoint

Use this pattern by default.
1

Expose a scoped HTTPS route

Create one route per lookup or workflow. The route receives known user or conversation identifiers, queries the warehouse with predefined SQL, and returns JSON.
2

Protect the route

Require an API key, bearer token, mTLS, signed request, or another auth method your team can rotate. If your firewall restricts inbound traffic, allow Fini’s static outbound IPs to reach the endpoint on port 443.
3

Return a minimal JSON shape

Return only the fields Fini should use. Prefer stable field names such as accountStatus, planName, isEligible, and policyReason.
4

Configure Fini

Use an Attribute when the data should be fetched before every reply. Use an Action when a Rulebook Tool node should run the lookup only for a specific intent.
5

Map and test the response

In the Data Step, save the response fields Fini should keep. Then run the Test panel with staging users before attaching the Attribute to an agent or wiring the Action into a rule.

Fini-hosted connector endpoint

Fini can also host or configure the HTTPS endpoint with you. In that case, your team must provide the connection details Fini needs to reach the warehouse or private network, and you must allowlist the relevant Fini egress addresses. For Redshift, confirm the actual database port before allowlisting. The default Redshift port is usually 5439, though some clusters are configured differently.
If you are testing against a staging warehouse or staging API, ask your Fini contact which staging egress addresses to allowlist. Production outbound IPs are listed on the Static IP Addresses page.

Attribute or Action

Use the same data access endpoint from either product surface. The difference is when the call runs.

Configure the Data Step

Whether you are using an Attribute or an Action, the warehouse endpoint is configured as a Data Step: one HTTP request with a URL, method, headers, optional body, and response mapping. Example Attribute lookup:
Example Action lookup:
Use External API calls for the public API object model if you are creating these configurations programmatically.

Customer checklist

Before testing, align on the exact integration contract:
  • HTTPS endpoint URL for staging and production
  • Auth method and header format
  • Input fields Fini can pass, such as email, account ID, user ID, order ID, or SKU
  • Response JSON schema and example responses
  • Which response fields are safe for Visible to AI
  • Which fields should only be available to Rulebooks
  • Whether the endpoint is read-only or can trigger writes
  • Network allowlisting requirements
  • Expected latency, timeout behavior, and rate limits
  • Sample staging users and test flows
Keep the endpoint response narrow. A field can be useful to a rule without being useful to the LLM. Toggle Visible to AI only for fields the agent should be able to reference in a reply.

Why a warehouse lookup isn’t working

Confirm the endpoint is HTTPS, reachable from Fini’s outbound IPs, and listening on the expected port. For customer-hosted APIs this is usually port 443. For Fini-hosted connector work, confirm the actual warehouse port and network route.
Check the auth header format, allowlist, and environment. Staging and production endpoints often use different tokens, hostnames, and egress IPs.
Compare the Data Step Save From Response paths with the real JSON body. If your endpoint returns data.account.status, mapping status will not populate anything.
Turn off Visible to AI for that field. Use Use in Rulebooks when the value should drive branching without being included in the model context.
Move expensive queries behind a cached endpoint, reduce the response size, or use an Action instead of an Attribute so the call runs only for the intents that need it.

Attributes

Fetch warehouse-backed context automatically before each reply.

Actions

Run a warehouse lookup only when a Rulebook Tool node invokes it.

External API calls

Create and manage the Data Steps that call your HTTPS endpoint.

Static IP Addresses

Allowlist Fini’s outbound traffic when your endpoint is behind a firewall.