# Can't use Variable acess/token on headers value on Call API column

**URL:** <https://community.glideapps.com/t/cant-use-variable-acess-token-on-headers-value-on-call-api-column/65726>\
**Category:** Ask for Help\
**Created:** [September 2, 2023, 10:01pm UTC](https://community.glideapps.com/t/cant-use-variable-acess-token-on-headers-value-on-call-api-column/65726 "2023-09-02T22:01:19Z")\
**Posts on this page:** 20\
**Page:** 1

<div class="post-metadata">

**Author:** ![luizgstein](https://sea2.discourse-cdn.com/flex002/user_avatar/community.glideapps.com/luizgstein/32/63513_2.png) [@luizgstein](https://community.glideapps.com/u/luizgstein)\
**Post date:** [September 2, 2023, 10:01pm UTC](https://community.glideapps.com/t/cant-use-variable-acess-token-on-headers-value-on-call-api-column/65726/1 "2023-09-02T22:01:19Z")

</div>

The headers of the CALL API column is just allowing me to use a custom value on the headers I am setting up. The problem is that I need to use different access/token when calling the API, depending on the Company I’m trying to reach. The field “Headers” can be variable, but the value is custom only. How can I solve it?

---

<div class="post-metadata">

**Author:** ![ThinhDinh](https://sea2.discourse-cdn.com/flex002/user_avatar/community.glideapps.com/thinhdinh/32/49_2.png) [@ThinhDinh](https://community.glideapps.com/u/ThinhDinh)\
**Post date:** [September 2, 2023, 11:11pm UTC](https://community.glideapps.com/t/cant-use-variable-acess-token-on-headers-value-on-call-api-column/65726/2 "2023-09-02T23:11:24Z")

</div>

That function was removed to secure the header, and I’m not sure they would bring that back. Like you, I have a few services where my token is expiring after a certain amount of time, and I have had no solutions for it.

---

<div class="post-metadata">

**Author:** ![luizgstein](https://sea2.discourse-cdn.com/flex002/user_avatar/community.glideapps.com/luizgstein/32/63513_2.png) [@luizgstein](https://community.glideapps.com/u/luizgstein)\
**Post date:** [September 2, 2023, 11:24pm UTC](https://community.glideapps.com/t/cant-use-variable-acess-token-on-headers-value-on-call-api-column/65726/3 "2023-09-02T23:24:55Z")

</div>

Thank you very much for your answer. It will defininetively limit a lot tha capacity of system construction. I really need it to build a multi-company platform, since the payments come from different payments solutions. Do you know any way to solve it?

---

<div class="post-metadata">

**Author:** ![ThinhDinh](https://sea2.discourse-cdn.com/flex002/user_avatar/community.glideapps.com/thinhdinh/32/49_2.png) [@ThinhDinh](https://community.glideapps.com/u/ThinhDinh)\
**Post date:** [September 2, 2023, 11:32pm UTC](https://community.glideapps.com/t/cant-use-variable-acess-token-on-headers-value-on-call-api-column/65726/4 "2023-09-02T23:32:31Z")

</div>

I think you would have to resort to the JavaScript column to do something like that.

---

<div class="post-metadata">

**Author:** ![luizgstein](https://sea2.discourse-cdn.com/flex002/user_avatar/community.glideapps.com/luizgstein/32/63513_2.png) [@luizgstein](https://community.glideapps.com/u/luizgstein)\
**Post date:** [September 2, 2023, 11:51pm UTC](https://community.glideapps.com/t/cant-use-variable-acess-token-on-headers-value-on-call-api-column/65726/5 "2023-09-02T23:51:52Z")

</div>

I’ll do some research and see if I can figure out how to do this. If I find some solution I let you know here too. Thank you very much for your help

---

<div class="post-metadata">

**Author:** ![ThinhDinh](https://sea2.discourse-cdn.com/flex002/user_avatar/community.glideapps.com/thinhdinh/32/49_2.png) [@ThinhDinh](https://community.glideapps.com/u/ThinhDinh)\
**Post date:** [September 3, 2023, 12:08am UTC](https://community.glideapps.com/t/cant-use-variable-acess-token-on-headers-value-on-call-api-column/65726/6 "2023-09-03T00:08:01Z")

</div>

Thanks a lot!

---

<div class="post-metadata">

**Author:** ![Darren\_Murphy](https://sea2.discourse-cdn.com/flex002/user_avatar/community.glideapps.com/darren_murphy/32/47326_2.png) [@Darren\_Murphy](https://community.glideapps.com/u/Darren_Murphy)\
**Post date:** [September 3, 2023, 3:26am UTC](https://community.glideapps.com/t/cant-use-variable-acess-token-on-headers-value-on-call-api-column/65726/7 "2023-09-03T03:26:29Z")

</div>

JavaScript wouldn’t be secure, because it’s executed client side, which means the tokens would be on the client device. I think the only way to do it securely is via Make.

---

<div class="post-metadata">

**Author:** ![ThinhDinh](https://sea2.discourse-cdn.com/flex002/user_avatar/community.glideapps.com/thinhdinh/32/49_2.png) [@ThinhDinh](https://community.glideapps.com/u/ThinhDinh)\
**Post date:** [September 4, 2023, 12:28am UTC](https://community.glideapps.com/t/cant-use-variable-acess-token-on-headers-value-on-call-api-column/65726/8 "2023-09-04T00:28:31Z")

</div>

Ah yes… Would be better if we don’t need a third-party service, but it is what it is.

---

<div class="post-metadata">

**Author:** ![luizgstein](https://sea2.discourse-cdn.com/flex002/user_avatar/community.glideapps.com/luizgstein/32/63513_2.png) [@luizgstein](https://community.glideapps.com/u/luizgstein)\
**Post date:** [September 4, 2023, 11:59pm UTC](https://community.glideapps.com/t/cant-use-variable-acess-token-on-headers-value-on-call-api-column/65726/9 "2023-09-04T23:59:12Z")

</div>

it makes sense. How would you do this key management via Make?

---

<div class="post-metadata">

**Author:** ![ThinhDinh](https://sea2.discourse-cdn.com/flex002/user_avatar/community.glideapps.com/thinhdinh/32/49_2.png) [@ThinhDinh](https://community.glideapps.com/u/ThinhDinh)\
**Post date:** [September 5, 2023, 12:12am UTC](https://community.glideapps.com/t/cant-use-variable-acess-token-on-headers-value-on-call-api-column/65726/10 "2023-09-05T00:12:12Z")

</div>

Use a Webhook action to send relevant info from Glide to [Make.com](http://Make.com) when needed, make a HTTP call over there, take the results and bring that back to Glide (either using the Glide API or Google Sheets/Airtable depending on your backend).

---

<div class="post-metadata">

**Author:** ![Darren\_Murphy](https://sea2.discourse-cdn.com/flex002/user_avatar/community.glideapps.com/darren_murphy/32/47326_2.png) [@Darren\_Murphy](https://community.glideapps.com/u/Darren_Murphy)\
**Post date:** [September 5, 2023, 3:02am UTC](https://community.glideapps.com/t/cant-use-variable-acess-token-on-headers-value-on-call-api-column/65726/11 "2023-09-05T03:02:02Z")

</div>

> [@luizgstein](#):
>
> it makes sense. How would you do this key management via Make?

Keep all your tokens in a Make Data Store, then include a company identifier in the webhook from Glide, so that you can retrieve and send the correct token.

---

<div class="post-metadata">

**Author:** ![luizgstein](https://sea2.discourse-cdn.com/flex002/user_avatar/community.glideapps.com/luizgstein/32/63513_2.png) [@luizgstein](https://community.glideapps.com/u/luizgstein)\
**Post date:** [September 6, 2023, 2:14am UTC](https://community.glideapps.com/t/cant-use-variable-acess-token-on-headers-value-on-call-api-column/65726/12 "2023-09-06T02:14:58Z")

</div>

Glide just added dynamic headers values hahah It keeps getting better

---

<div class="post-metadata">

**Author:** ![ThinhDinh](https://sea2.discourse-cdn.com/flex002/user_avatar/community.glideapps.com/thinhdinh/32/49_2.png) [@ThinhDinh](https://community.glideapps.com/u/ThinhDinh)\
**Post date:** [September 6, 2023, 2:28am UTC](https://community.glideapps.com/t/cant-use-variable-acess-token-on-headers-value-on-call-api-column/65726/13 "2023-09-06T02:28:24Z")

</div>

But they made it exclusively Business/Enterprise…

---

<div class="post-metadata">

**Author:** ![james](https://sea2.discourse-cdn.com/flex002/user_avatar/community.glideapps.com/james/32/71213_2.png) [@james](https://community.glideapps.com/u/james)\
**Post date:** [January 28, 2025, 3:40pm UTC](https://community.glideapps.com/t/cant-use-variable-acess-token-on-headers-value-on-call-api-column/65726/14 "2025-01-28T15:40:51Z")

</div>

@ThinhDinh @Darren_Murphy  
Is there a tutorial/example floating around anywhere for this Glide Webhook \> Make \> API Call \> Glide using the Make Data Store?

I’m trying to deal with an expiring access token, similar to the below post

> [@API with expiring access token](https://community.glideapps.com/t/api-with-expiring-access-token/76591/4):
>
> Exactly, but then you have to save the token in the database. Won’t this be a security issue?

---

<div class="post-metadata">

**Author:** ![ThinhDinh](https://sea2.discourse-cdn.com/flex002/user_avatar/community.glideapps.com/thinhdinh/32/49_2.png) [@ThinhDinh](https://community.glideapps.com/u/ThinhDinh)\
**Post date:** [January 28, 2025, 4:08pm UTC](https://community.glideapps.com/t/cant-use-variable-acess-token-on-headers-value-on-call-api-column/65726/15 "2025-01-28T16:08:05Z")

</div>

If they have an expiring access token, I would think they have a way to regenerate that token when needed.

I would just generate a token every time I need to call that API, then pass that to the actual call for authentication. Is that a valid approach?

---

<div class="post-metadata">

**Author:** ![Darren\_Murphy](https://sea2.discourse-cdn.com/flex002/user_avatar/community.glideapps.com/darren_murphy/32/47326_2.png) [@Darren\_Murphy](https://community.glideapps.com/u/Darren_Murphy)\
**Post date:** [January 28, 2025, 4:40pm UTC](https://community.glideapps.com/t/cant-use-variable-acess-token-on-headers-value-on-call-api-column/65726/16 "2025-01-28T16:40:16Z")

</div>

> [@ThinhDinh](#):
>
> I would just generate a token every time I need to call that API, then pass that to the actual call for authentication. Is that a valid approach?

That’s exactly what I do.

---

<div class="post-metadata">

**Author:** ![james](https://sea2.discourse-cdn.com/flex002/user_avatar/community.glideapps.com/james/32/71213_2.png) [@james](https://community.glideapps.com/u/james)\
**Post date:** [January 28, 2025, 11:16pm UTC](https://community.glideapps.com/t/cant-use-variable-acess-token-on-headers-value-on-call-api-column/65726/17 "2025-01-28T23:16:56Z")

</div>

That should work. To do this are you storing the token in a column for the duration of the API Call and then clearing it as the final step in the action?

---

<div class="post-metadata">

**Author:** ![ThinhDinh](https://sea2.discourse-cdn.com/flex002/user_avatar/community.glideapps.com/thinhdinh/32/49_2.png) [@ThinhDinh](https://community.glideapps.com/u/ThinhDinh)\
**Post date:** [January 29, 2025, 12:03am UTC](https://community.glideapps.com/t/cant-use-variable-acess-token-on-headers-value-on-call-api-column/65726/18 "2025-01-29T00:03:39Z")

</div>

Yes, I would store it in a user-specific column, then build out a template for the header if needed (say if you need something like `Bearer XXX`).

Then as the last action of your chain, clear the user-specific column.

---

<div class="post-metadata">

**Author:** ![Jimmy\_Carter](https://sea2.discourse-cdn.com/flex002/user_avatar/community.glideapps.com/jimmy_carter/32/84627_2.png) [@Jimmy\_Carter](https://community.glideapps.com/u/Jimmy_Carter)\
**Post date:** [January 30, 2025, 12:17am UTC](https://community.glideapps.com/t/cant-use-variable-acess-token-on-headers-value-on-call-api-column/65726/19 "2025-01-30T00:17:21Z")

</div>

I’m building something similar. Originally I planned on just having a backend connected to a DB to call an API and pass the data to the glide app’s connected Google sheet. But that’s not an option anymore, so I’m going to be using Glide’s call API.

Could I store a company\_secret and the refresh\_token inside of Glide using the secret variable or would I need to store it in made like was mentioned previously?

---

<div class="post-metadata">

**Author:** ![ThinhDinh](https://sea2.discourse-cdn.com/flex002/user_avatar/community.glideapps.com/thinhdinh/32/49_2.png) [@ThinhDinh](https://community.glideapps.com/u/ThinhDinh)\
**Post date:** [January 30, 2025, 12:24am UTC](https://community.glideapps.com/t/cant-use-variable-acess-token-on-headers-value-on-call-api-column/65726/20 "2025-01-30T00:24:45Z")

</div>

Couldn’t you just do this?

> [@ThinhDinh](#):
>
> Yes, I would store it in a user-specific column, then build out a template for the header if needed (say if you need something like `Bearer XXX`).
> 
> Then as the last action of your chain, clear the user-specific column.

[Next page](https://community.glideapps.com/t/cant-use-variable-acess-token-on-headers-value-on-call-api-column/65726.md?page=2)
