Fini’s configurable calls are HTTP calls. A database or warehouse connection means
Fini -> HTTPS endpoint -> warehouse -> JSON response -> Fini, not arbitrary SQL generated by the agent.Recommended architecture
The recommended setup is a customer-hosted data access endpoint. Host a small API in AWS Lambda, API Gateway, Cloud Run, Cloud Functions, your backend, or another service that already has secure access to the warehouse. The endpoint should expose named lookup routes, not a general SQL interface. For example:Setup patterns
Customer-hosted endpoint
Use this pattern by default.1
Expose a scoped HTTPS route
Create one route per lookup or workflow. The route receives known user or conversation identifiers, queries the warehouse with predefined SQL, and returns JSON.
2
Protect the route
Require an API key, bearer token, mTLS, signed request, or another auth method your team can rotate. If your firewall restricts inbound traffic, allow Fini’s static outbound IPs to reach the endpoint on port 443.
3
Return a minimal JSON shape
Return only the fields Fini should use. Prefer stable field names such as
accountStatus, planName, isEligible, and policyReason.4
5
Map and test the response
In the Data Step, save the response fields Fini should keep. Then run the Test panel with staging users before attaching the Attribute to an agent or wiring the Action into a rule.
Fini-hosted connector endpoint
Fini can also host or configure the HTTPS endpoint with you. In that case, your team must provide the connection details Fini needs to reach the warehouse or private network, and you must allowlist the relevant Fini egress addresses. For Redshift, confirm the actual database port before allowlisting. The default Redshift port is usually5439, though some clusters are configured differently.
If you are testing against a staging warehouse or staging API, ask your Fini contact which staging egress addresses to allowlist. Production outbound IPs are listed on the Static IP Addresses page.
Attribute or Action
Use the same data access endpoint from either product surface. The difference is when the call runs.Configure the Data Step
Whether you are using an Attribute or an Action, the warehouse endpoint is configured as a Data Step: one HTTP request with a URL, method, headers, optional body, and response mapping. Example Attribute lookup:Customer checklist
Before testing, align on the exact integration contract:- HTTPS endpoint URL for staging and production
- Auth method and header format
- Input fields Fini can pass, such as email, account ID, user ID, order ID, or SKU
- Response JSON schema and example responses
- Which response fields are safe for Visible to AI
- Which fields should only be available to Rulebooks
- Whether the endpoint is read-only or can trigger writes
- Network allowlisting requirements
- Expected latency, timeout behavior, and rate limits
- Sample staging users and test flows
Why a warehouse lookup isn’t working
Fini cannot reach the endpoint
Fini cannot reach the endpoint
Confirm the endpoint is HTTPS, reachable from Fini’s outbound IPs, and listening on the expected port. For customer-hosted APIs this is usually port 443. For Fini-hosted connector work, confirm the actual warehouse port and network route.
The endpoint works locally but fails in Fini
The endpoint works locally but fails in Fini
Check the auth header format, allowlist, and environment. Staging and production endpoints often use different tokens, hostnames, and egress IPs.
The call succeeds but fields are empty
The call succeeds but fields are empty
Compare the Data Step Save From Response paths with the real JSON body. If your endpoint returns
data.account.status, mapping status will not populate anything.The agent mentions data it should not see
The agent mentions data it should not see
Turn off Visible to AI for that field. Use Use in Rulebooks when the value should drive branching without being included in the model context.
The lookup adds too much latency
The lookup adds too much latency
Move expensive queries behind a cached endpoint, reduce the response size, or use an Action instead of an Attribute so the call runs only for the intents that need it.
Related
Attributes
Fetch warehouse-backed context automatically before each reply.
Actions
Run a warehouse lookup only when a Rulebook Tool node invokes it.
External API calls
Create and manage the Data Steps that call your HTTPS endpoint.
Static IP Addresses
Allowlist Fini’s outbound traffic when your endpoint is behind a firewall.

