Appearance
Xano actions reference
The Xano integration gives you four workflow actions. API Request is available as soon as Xano is connected. The three others are sign in actions: they only appear when Xano is your Authentication System, in the Authentication subtab of Data & API.
All actions
| Action | Description | Where it runs |
|---|---|---|
| API Request | Call one of your Xano endpoints. | Interface and backend workflows |
| Authenticate | Store the Xano session after a user signs in or signs up. | Interface workflows |
| Set User | Set the signed-in user, after retrieving it from Xano. | Interface and backend workflows |
| Clear Session | Sign the user out by clearing their Xano session. | Interface workflows |
Action details
API Request
Call one endpoint of a Xano API group, with the inputs it expects.
Inputs
| Display Key | Example Input | Description | Restrictions |
|---|---|---|---|
API Group | "jobs" | The Xano API group of the endpoint. | Listed from your workspace. Click the refresh button to load new groups. |
Endpoint | "POST /job" | The endpoint to call, shown as its method and path. | Listed from the API documentation of the group. |
URL ParamsOptional | {"job_id":12} | Values for the parts of the path in curly braces. | Shown only if the path has some. A missing value stays in the path and Xano answers 404. |
Query ParametersOptional | {"page":1,"search":"designer"} | Inputs sent in the address of a GET request. | Shown only if the endpoint has some. Ignored for other methods. |
BodyOptional | {"title":"Product designer","company_id":3} | Inputs sent with a POST, PUT, PATCH, or DELETE request. File inputs accept a file. | Hidden for GET endpoints. |
Custom HeadersOptional | {"X-Request-Source":"weweb"} | Extra headers for this request only, under Advanced. | In Interface workflows, an Authorization header is replaced by the user's session. |
Stream ResponseOptional | true | Receive the response piece by piece, under Advanced. | Interface workflows only, for GET, POST, PUT, and PATCH. Off by default. |
Example output
json
{
"body": { "id": 12, "title": "Product designer", "company_id": 3 },
"status": 200,
"headers": { "content-type": "application/json; charset=utf-8" }
}What your endpoint returned is in body. With Stream Response on, the action returns the pieces of the response as they arrive instead.
Learn more about calling Xano from workflows →
Authenticate
Store the session returned by your Xano sign in or sign up endpoint, so WeWeb treats the user as signed in.
Inputs
| Display Key | Example Input | Description | Restrictions |
|---|---|---|---|
Auth Token | "eyJhbGciOiJIUzI1NiIs…" | The token returned by your Xano sign in or sign up endpoint. | Required. |
Refresh TokenOptional | "rt_8f2c…" | A refresh token, if your endpoint returns one. | Text. |
MetadataOptional | {"id":"123"} | Extra data to keep with the session. | Object. |
Persist SessionOptional | true | Keep the session in the browser, so the user stays signed in after a refresh. | On by default. |
Example output
This action returns nothing. Once the session is stored, WeWeb runs your On user load workflows.
Learn more about the Authenticate action →
Set User
Set the user WeWeb treats as signed in, usually at the end of an On user load workflow.
Inputs
| Display Key | Example Input | Description | Restrictions |
|---|---|---|---|
User | {"id":"123","name":"John Doe","email":"john@example.com"} | The user, usually the body of a request to your current-user endpoint, such as GET /auth/me. | Required. Object. |
Example output
In Interface workflows, this action returns nothing. In backend workflows, it returns the user you set:
json
{ "id": "123", "name": "John Doe", "email": "john@example.com" }The user is then available exactly as you passed it, in the interface and in your backend workflows.
Learn more about the Set User action →
Clear Session
Sign the user out of your app by clearing their Xano session in WeWeb.
Inputs
This action has no inputs.
Example output
This action returns nothing. If your Xano project also has a sign out endpoint, call it with API Request before Clear Session.
Learn more about the Clear Session action →
CONTINUE LEARNING
Something doesn't work as expected? Check the most common errors and how to fix them.

