> For clean Markdown of any page, append .md to the page URL.
> For a complete documentation index, see https://apidocs.polytomic.com/llms.txt.
> For AI client integration (Claude Code, Cursor, etc.), connect to the MCP server at https://apidocs.polytomic.com/_mcp/server.

# Execute Connection Proxy

POST https://app.polytomic.com/api/connections/{id}/proxy
Content-Type: application/json

Proxies an HTTP request to a connection's underlying API using the connection's stored credentials, subject to per-connection rate limits and size caps.

This endpoint is intended for controlled passthrough use, not as a general
replacement for Polytomic's modeled endpoints. The request is executed with the
connection's stored credentials and inherited base URL, headers, and query
parameters.

Before building requests dynamically, call
[`GET /api/connections/{id}/proxy/info`](../../../../api-reference/connections/get-proxy-info)
to inspect the inherited base URL, blocked headers, accepted body types, and
size and rate limits.

## Important behavior

* For connections that expose more than one API (listed in `apis` in the proxy
  info response), set `request.api` to the name of the API to call. Requests
  without `request.api` go to the default API. `request.api` is rejected for
  connections that expose a single API.
* `request.path` must be relative and start with `/`.
* Use either `request.query` or `request.rawQuery`, not both.
* Caller-supplied headers are merged with inherited headers, but inherited auth
  headers cannot be overridden.
* The proxy strips a fixed set of request and response headers for safety.
* Response bodies larger than the configured maximum are truncated, and
  `truncated` is set to `true`.
* A `429` means Polytomic's proxy rate limit was reached, or the connection's
  upstream quota, which the proxy shares with the connection's syncs, is
  exhausted.

To run a `GET` request asynchronously, set `async` to `true`. The initial
response returns `status: 202`, `jobId`, `jobStatus`, and `jobUrl`. Poll
[`GET /api/jobs/{type}/{id}`](../../../../api-reference/jobs/get-job) with
`type=connectionproxy` and the returned `jobId` until the job is complete. The
completed job result includes the upstream `status`, sanitized `headers`,
`contentType`, `contentLength`, `latencyMs`, and a short-lived
`bodyDownloadUrl` for the upstream response body.

The response includes `proxyCallId`, which you can use to correlate the call
with audit logs.

Reference: https://apidocs.polytomic.com/api-reference/connections/proxy/execute-proxy

## Authentication

- `Authorization` header (bearer token, required) — Bearer user API key
- `Authorization` header (basic auth, required) — Basic organization-scoped API key

## Request

### Path parameters

- `id` (string, required) — Unique identifier of the connection to proxy the request through.

### Body (application/json)

This endpoint expects an ExecuteConnectionProxyRequest.

- `request` (ConnectionProxyCall, required)
- `async` (boolean, optional) — When true, submits a GET request for asynchronous execution and returns a job handle instead of a synchronous upstream response.

## Response

### 200

OK

- `data` (ConnectionProxyResponse, optional)

## Errors

### 400 Bad Request Error

Bad Request

- `key` (string, optional)
- `message` (string, optional)
- `metadata` (map from string to any, optional)
- `status` (integer, optional)

### 401 Unauthorized Error

Unauthorized

- `key` (string, optional)
- `message` (string, optional)
- `metadata` (map from string to any, optional)
- `status` (integer, optional)

### 403 Forbidden Error

Forbidden

- `key` (string, optional)
- `message` (string, optional)
- `metadata` (map from string to any, optional)
- `status` (integer, optional)

### 404 Not Found Error

Not Found

- `key` (string, optional)
- `message` (string, optional)
- `metadata` (map from string to any, optional)
- `status` (integer, optional)

### 429 Too Many Requests Error

Too Many Requests

- `key` (string, optional)
- `message` (string, optional)
- `metadata` (map from string to any, optional)
- `status` (integer, optional)

### 500 Internal Server Error

Internal Server Error

- `key` (string, optional)
- `message` (string, optional)
- `metadata` (map from string to any, optional)
- `status` (integer, optional)

### 502 Bad Gateway Error

Bad Gateway

- `key` (string, optional)
- `message` (string, optional)
- `metadata` (map from string to any, optional)
- `status` (integer, optional)

### 504 Gateway Timeout Error

Gateway Timeout

- `key` (string, optional)
- `message` (string, optional)
- `metadata` (map from string to any, optional)
- `status` (integer, optional)

## Types

### ConnectionProxyCall

- `method` (string, required) — HTTP method. Must be one of GET, POST, PUT, PATCH, DELETE.
- `path` (string, required) — Relative upstream path. Query strings must be passed in request.query or request.rawQuery.
- `api` (string, optional) — Name of the upstream API to call, for connections that expose more than one (see apis in the proxy info response). Defaults to the connection's default API.
- `body` (any, optional) — Request body. May be a string, a JSON object, a JSON array, or null.
- `headers` (map from string to string, optional) — Additional request headers to send upstream. Headers listed in the connection's blockedRequestHeaders are rejected, and inherited auth headers cannot be overridden.
- `query` (map from string to any, optional) — Structured query parameters. Keys and values are URL-encoded before forwarding. Mutually exclusive with rawQuery.
- `rawQuery` (string, optional) — Exact query string fragment appended as-is after inherited query parameters. Do not include a leading '?'. Caller is responsible for encoding and syntax. Mutually exclusive with query.

### ConnectionProxyResponse

- `body` (string, optional) — Upstream response body. If the upstream returned JSON, the body is returned as-is; otherwise it is returned as a string.
- `contentType` (string, optional) — Content-Type of the upstream response.
- `headers` (map from string to string, optional, nullable) — Response headers returned by the upstream service. Headers listed in blockedResponseHeaders are removed.
- `jobId` (string, optional) — Identifier for the async proxy job when async is true.
- `jobStatus` (enum, optional)
  - Allowed values: `created`, `running`, `done`, `failed`
- `jobUrl` (string, optional) — Polling URL for the async proxy job when async is true.
- `latencyMs` (long, optional) — End-to-end latency of the proxied request in milliseconds.
- `proxyCallId` (string, optional) — Identifier for this proxy call, suitable for correlating with audit logs.
- `status` (integer, optional) — HTTP status code returned by the upstream service for synchronous calls, or 202 when an async proxy job is accepted.
- `truncated` (boolean, optional) — True if the response body was truncated because it exceeded maxResponseBodyBytes.

## Examples

**Request**

```json
{
  "request": {
    "method": "GET",
    "path": "/v1/objects"
  }
}
```

**Response**

```json
{
  "data": {
    "body": "string",
    "contentType": "application/json",
    "headers": {},
    "jobId": "248df4b7-aa70-47b8-a036-33ac447e668d",
    "jobStatus": "created",
    "jobUrl": "string",
    "latencyMs": 1,
    "proxyCallId": "248df4b7-aa70-47b8-a036-33ac447e668d",
    "status": 200,
    "truncated": true
  }
}
```

**SDK Code**

```python
import requests

url = "https://app.polytomic.com/api/connections/248df4b7-aa70-47b8-a036-33ac447e668d/proxy"

payload = { "request": {
        "method": "GET",
        "path": "/v1/objects"
    } }
headers = {
    "Authorization": "Bearer <token>",
    "Content-Type": "application/json"
}

response = requests.post(url, json=payload, headers=headers)

print(response.json())
```

```javascript
const url = 'https://app.polytomic.com/api/connections/248df4b7-aa70-47b8-a036-33ac447e668d/proxy';
const options = {
  method: 'POST',
  headers: {Authorization: 'Bearer <token>', 'Content-Type': 'application/json'},
  body: '{"request":{"method":"GET","path":"/v1/objects"}}'
};

try {
  const response = await fetch(url, options);
  const data = await response.json();
  console.log(data);
} catch (error) {
  console.error(error);
}
```

```go
package main

import (
	"fmt"
	"strings"
	"net/http"
	"io"
)

func main() {

	url := "https://app.polytomic.com/api/connections/248df4b7-aa70-47b8-a036-33ac447e668d/proxy"

	payload := strings.NewReader("{\n  \"request\": {\n    \"method\": \"GET\",\n    \"path\": \"/v1/objects\"\n  }\n}")

	req, _ := http.NewRequest("POST", url, payload)

	req.Header.Add("Authorization", "Bearer <token>")
	req.Header.Add("Content-Type", "application/json")

	res, _ := http.DefaultClient.Do(req)

	defer res.Body.Close()
	body, _ := io.ReadAll(res.Body)

	fmt.Println(res)
	fmt.Println(string(body))

}
```

```ruby
require 'uri'
require 'net/http'

url = URI("https://app.polytomic.com/api/connections/248df4b7-aa70-47b8-a036-33ac447e668d/proxy")

http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true

request = Net::HTTP::Post.new(url)
request["Authorization"] = 'Bearer <token>'
request["Content-Type"] = 'application/json'
request.body = "{\n  \"request\": {\n    \"method\": \"GET\",\n    \"path\": \"/v1/objects\"\n  }\n}"

response = http.request(request)
puts response.read_body
```

```java
import com.mashape.unirest.http.HttpResponse;
import com.mashape.unirest.http.Unirest;

HttpResponse<String> response = Unirest.post("https://app.polytomic.com/api/connections/248df4b7-aa70-47b8-a036-33ac447e668d/proxy")
  .header("Authorization", "Bearer <token>")
  .header("Content-Type", "application/json")
  .body("{\n  \"request\": {\n    \"method\": \"GET\",\n    \"path\": \"/v1/objects\"\n  }\n}")
  .asString();
```

```php
<?php
require_once('vendor/autoload.php');

$client = new \GuzzleHttp\Client();

$response = $client->request('POST', 'https://app.polytomic.com/api/connections/248df4b7-aa70-47b8-a036-33ac447e668d/proxy', [
  'body' => '{
  "request": {
    "method": "GET",
    "path": "/v1/objects"
  }
}',
  'headers' => [
    'Authorization' => 'Bearer <token>',
    'Content-Type' => 'application/json',
  ],
]);

echo $response->getBody();
```

```csharp
using RestSharp;

var client = new RestClient("https://app.polytomic.com/api/connections/248df4b7-aa70-47b8-a036-33ac447e668d/proxy");
var request = new RestRequest(Method.POST);
request.AddHeader("Authorization", "Bearer <token>");
request.AddHeader("Content-Type", "application/json");
request.AddParameter("application/json", "{\n  \"request\": {\n    \"method\": \"GET\",\n    \"path\": \"/v1/objects\"\n  }\n}", ParameterType.RequestBody);
IRestResponse response = client.Execute(request);
```

```swift
import Foundation

let headers = [
  "Authorization": "Bearer <token>",
  "Content-Type": "application/json"
]
let parameters = ["request": [
    "method": "GET",
    "path": "/v1/objects"
  ]] as [String : Any]

let postData = JSONSerialization.data(withJSONObject: parameters, options: [])

let request = NSMutableURLRequest(url: NSURL(string: "https://app.polytomic.com/api/connections/248df4b7-aa70-47b8-a036-33ac447e668d/proxy")! as URL,
                                        cachePolicy: .useProtocolCachePolicy,
                                    timeoutInterval: 10.0)
request.httpMethod = "POST"
request.allHTTPHeaderFields = headers
request.httpBody = postData as Data

let session = URLSession.shared
let dataTask = session.dataTask(with: request as URLRequest, completionHandler: { (data, response, error) -> Void in
  if (error != nil) {
    print(error as Any)
  } else {
    let httpResponse = response as? HTTPURLResponse
    print(httpResponse)
  }
})

dataTask.resume()
```