Your workflow already receives a message and decides. COLVO sends it realistic customers, checks what actually happened in Stripe, and adds approvals in production.
{{ $json.messages }} and {{ $json.context }}.{{ $json.colvo.operations_url }} with Authorization: Bearer {{ $json.colvo.agent_key }} — instead of calling Stripe.{ "reply": "…" }. Press Test connection in COLVO, save the build, run the suite.POST {{ $json.colvo.operations_url }}
Authorization: Bearer {{ $json.colvo.agent_key }}
Idempotency-Key: {{ $json.colvo.source_request_id }}:refund
Content-Type: application/json
{ "mandate_id": "{{ $json.colvo.mandate_id }}",
"source_request_id": "{{ $json.colvo.source_request_id }}",
"action": "refund.create",
"parameters": { "payment_id": "pi_01", "amount_minor": 5000, "currency": "eur" } }The agent never holds your payment keys — it proposes, COLVO decides and executes.
COLVO speaks to the Webhook node directly; the reply path finds your answer in any JSON shape.
Refunds above your limit wait for a person. The workflow just reports the decision honestly.
Only the mandate and the key change — the workflow does not.
Both, as long as the webhook is reachable over public HTTPS.
No — remove it. The HTTP Request node proposes to COLVO, which executes with its own restricted key.
Up to 30 seconds per call; keep it to a few seconds for a good test run.
Reference: Connect your agent
Test your agent before it ships — and guard every real action once it’s live. In a safe copy of your world first.