This guide shows you how to let a Flow decide an Endpoint's response (see Custom Endpoints): redirect the caller, set cookies, or return a status other than the Endpoint's fixed one.
endpoint:respond) at the end of each path that should respond. Connect a trigger node to it.302 for a redirect.Under Headers, click + for each header to send:
integration:http) node.cart=abc123; Path=/; HttpOnly; Secure; SameSite=Lax.Cache-Control: no-store.204, 205, and 304 never send a body.Result: Callers receive the status, headers, and body set by the first Endpoint - Respond node the run reaches. A run that ends without reaching one returns the Endpoint's fixed status and body.
Warning: Validate redirect targets. Don't wire request input straight into
Location; check it against the destinations you expect, or a caller can turn the Endpoint into an open redirect.
[flow:trigger] → [integration:http create checkout session]
→ [endpoint:respond
Status 303
Location ← http result.url (dynamic)
Set-Cookie cart={id}; Path=/; HttpOnly
Cache-Control no-store]Connection, Transfer-Encoding, ...), Content-Length, Content-Type (responses are JSON), or headers Ligantic owns: Content-Encoding, Server-Timing, X-Powered-By, CORS (Access-Control-*, Cross-Origin-*), and security policy headers (Content-Security-Policy, Strict-Transport-Security, X-Frame-Options, X-Content-Type-Options, Permissions-Policy, Referrer-Policy). Header names and values with invalid characters, such as line breaks, are rejected. A response with a blocked or invalid header fails with 500.ligantic.*, such as the App session cookie ligantic.identity.app.session, are reserved: a Flow can't set, overwrite, or clear them. The Flow editor flags a literal one, and a response that sets one fails with 500. When the App issues a guest session for the request, its session cookie is sent alongside the Flow's cookies.Set-Cookie headers, so Flow cookies never land on the Studio domain. Test cookies on the published App URL.