Skip to main content
Glama

Create Bruno Request

create_request

Create API testing request files in Bruno collections, supporting HTTP, WebSocket, and gRPC, with .bru or .yml formats, including scripts, assertions, and variables.

Instructions

Generate request files for API testing (supports .bru and .yml formats). Authors HTTP requests by default, WebSocket requests with kind "websocket" (url plus websocket.messages) and gRPC requests with kind "grpc" (url plus grpc.method, grpc.protoPath and grpc.messages); neither takes an HTTP method or a body. Supports multipart/form-data with file uploads and per-part contentType (body.type "form-data" with formData entries of type "file"), and inline scripts (pre-request/post-response/tests) so no separate add_test_script call is needed. Scripts run as async functions: top-level await works, and bru.sleep(ms)/setTimeout/setInterval are available, spending the script timeout (settings.timeout, default 5000ms) — raise it via the settings argument.

Input Schema

TableJSON Schema
NameRequiredDescriptionDefault
urlYes
authNo
bodyNo
grpcNogRPC-only fields. Applies to kind "grpc" and is refused otherwise. Headers given for a gRPC request are written as metadata, which is that transport's only header surface.
kindNoTransport. Defaults to "http". "websocket" and "grpc" take no method and no body; their payloads are websocket.messages and grpc.messages.
nameYes
varsNo
queryNo
assertNoDeclared assertions, evaluated on every run without needing a test() block.
folderNo
methodNoRequired for kind "http", refused for "websocket" and "grpc", which have no HTTP method. A gRPC request names its RPC method in grpc.method.
headersNo
scriptsNoInline scripts to persist with the request. Keys: pre-request, post-response, tests (aliases before-request/after-response accepted). Avoids a separate add_test_script call. IMPORTANT for tests/post-response: only assertions inside a test() block are reported. Write test("status is 200", function() { expect(res.getStatus()).to.equal(200); }); — a bare expect() at the top level still runs, but a passing one records nothing, so run_collection reports "tests": [] and the request looks green with no assertions. Available in scripts: res.getStatus()/getStatusText()/getHeader(name)/getHeaders()/getBody()/getResponseTime(), res.getStopReason()/getCloseCode()/getSessionTruncated() on a websocket request, which report the same session outcome the result does (all null or false on an HTTP response, which has no session), bru.setVar(name, value)/getVar(name)/getEnvVar(name)/hasEnvVar(name), and expect(actual) with .to.equal/.contain/.include, .to.have.property/.lengthOf, .to.be.a/.an, .to.be.above/.below/.at.least/.at.most (aliases .gt/.lt/.gte/.lte/.greaterThan/.lessThan), .to.be.within(min, max), .to.be.oneOf([...]), .to.match(/re/), .to.startWith/.endWith, .to.be.true/.false/.null/.undefined/.empty/.json,and .to.not.* negations. VARIABLES: bru.getVar(name) resolves environment and collection variables as well as anything a script set, so an environment variable needs no shadow copy to be readable. bru.getEnvVar(name) is narrower on purpose: it reads the environment layer only, so a runtime variable of the same name does not shadow it. There is no setEnvVar — nothing here writes an environment file. RETURN TYPE: res.getBody() returns the response already parsed into a JS object/array when the Content-Type is application/json or a +json type (raw text otherwise). Access fields directly — res.getBody().field — and do NOT JSON.parse() it, which throws SyntaxError: "[object Object]" is not valid JSON.
sequenceNo
settingsNoRequest-level settings: transport behaviour (timeouts, redirects, URL encoding), not payload. What reaches the file depends on the dialect, because Bruno's own two writers differ: a .yml request always carries a fully resolved settings block whether or not you pass one, while a .bru request carries only what you supply. On modify_request the fields are merged individually over the existing block, so setting one does not clear the rest. Note the encodeUrl field: in .bru, creating a block at all changes the URL-encoding default.
websocketNoWebSocket-only fields. Applies to kind "websocket" and is refused otherwise.
pathParamsNoValues for :name segments in the URL, e.g. { id: "42" } for /users/:id.
collectionPathYesAbsolute path to existing collection directory.

Schema Changelog

Changes observed during successful MCP inspections.

  1. Changed5 schema fields changedv2.4.0
    • changedInput schema / properties / body / properties / formData / description
      Previous value: -"multipart/form-data parts, for body.type \"form-data\" or \"multipart-form\"."New value: +"Key/value parts, and the only field here that carries them: multipart/form-data parts for body.type \"form-data\" or \"multipart-form\", and the pairs of a \"form-urlencoded\" body, which read_request returns under formUrlEncoded rather than here (a form-urlencoded body can also be given as an encoded string in `content`). The per-entry type and contentType describe a multipart part and are rejected on a form-urlencoded body, where every pair is text and neither field is stored: pass type \"file\" or a contentType there and the call fails rather than writing a request that drops them."
    • changedInput schema / properties / scripts / description
      Previous value: -"Inline scripts to persist with the request. Keys: pre-request, post-response, tests (aliases before-request/after-response accepted). Avoids a separate add_test_script call. IMPORTANT for tests/post-response: only assertions inside a test() block are reported. Write test(\"status is 200\", function() { expect(res.getStatus()).to.equal(200); }); — a bare expect() at the top level still runs, but a passing one records nothing, so run_collection reports \"tests\": [] and the request looks green with no assertions. Available in scripts: res.getStatus()/getStatusText()/getHeader(name)/getHeaders()/getBody()/getResponseTime(), bru.setVar(name, value)/getVar(name), and expect(actual) with .to.equal/.contain/.include, .to.have.property/.lengthOf, .to.be.a/.an, .to.be.above/.below/.at.least/.at.most (aliases .gt/.lt/.gte/.lte/.greaterThan/.lessThan), .to.be.within(min, max), .to.be.oneOf([...]), .to.match(/re/), .to.startWith/.endWith, .to.be.true/.false/.null/.undefined/.empty/.json,and .to.not.* negations. RETURN TYPE: res.getBody() returns the response already parsed into a JS object/array when the Content-Type is application/json or a +json type (raw text otherwise). Access fields directly — res.getBody().field — and do NOT JSON.parse() it, which throws SyntaxError: \"[object Object]\" is not valid JSON."New value: +"Inline scripts to persist with the request. Keys: pre-request, post-response, tests (aliases before-request/after-response accepted). Avoids a separate add_test_script call. IMPORTANT for tests/post-response: only assertions inside a test() block are reported. Write test(\"status is 200\", function() { expect(res.getStatus()).to.equal(200); }); — a bare expect() at the top level still runs, but a passing one records nothing, so run_collection reports \"tests\": [] and the request looks green with no assertions. Available in scripts: res.getStatus()/getStatusText()/getHeader(name)/getHeaders()/getBody()/getResponseTime(), res.getStopReason()/getCloseCode()/getSessionTruncated() on a websocket request, which report the same session outcome the result does (all null or false on an HTTP response, which has no session), bru.setVar(name, value)/getVar(name)/getEnvVar(name)/hasEnvVar(name), and expect(actual) with .to.equal/.contain/.include, .to.have.property/.lengthOf, .to.be.a/.an, .to.be.above/.below/.at.least/.at.most (aliases .gt/.lt/.gte/.lte/.greaterThan/.lessThan), .to.be.within(min, max), .to.be.oneOf([...]), .to.match(/re/), .to.startWith/.endWith, .to.be.true/.false/.null/.undefined/.empty/.json,and .to.not.* negations. VARIABLES: bru.getVar(name) resolves environment and collection variables as well as anything a script set, so an environment variable needs no shadow copy to be readable. bru.getEnvVar(name) is narrower on purpose: it reads the environment layer only, so a runtime variable of the same name does not shadow it. There is no setEnvVar — nothing here writes an environment file. RETURN TYPE: res.getBody() returns the response already parsed into a JS object/array when the Content-Type is application/json or a +json type (raw text otherwise). Access fields directly — res.getBody().field — and do NOT JSON.parse() it, which throws SyntaxError: \"[object Object]\" is not valid JSON."
    • addedInput schema / properties / settings / properties / keepAliveInterval
      Added value: +{
      +  "description": "WebSocket requests only: milliseconds between the pings Bruno sends to hold the connection open, where 0 means never. A .yml WebSocket request always carries the key and records an unset value as 0, so this is how you change it; on .bru it is written only when you supply it. It is read back by read_request either way. This server's own runner sends no periodic pings of its own — it answers a ping the peer sends and records both frames — so the value is carried for Bruno rather than acted on here.",
      +  "minimum": 0,
      +  "type": "integer"
      +}
    • changedInput schema / properties / settings / properties / timeout / description
      Previous value: -"Milliseconds, capping two separate things. The HTTP request itself, which defaults to 30000ms when unset. And the per-script budget shared by pre-request, post-response and tests code, including time spent in bru.sleep, setTimeout and setInterval, which defaults to 5000ms when unset — a script that waits longer than its budget is aborted, and setting this is the only way to lift that 5000ms cap. 0 means no timeout at all."New value: +"Milliseconds, capping two separate things — and 0 does not mean the same to both. The request itself: 0 means no deadline at all, and the 30000ms default is reached only by a request whose file carries no timeout key, which a .yml request written here never does (that dialect always writes a fully resolved settings block, and an unset timeout is written as 0). So pass a positive value if you want a deadline on a .yml request. And the per-script budget shared by pre-request, post-response and tests code, including time spent in bru.sleep, setTimeout and setInterval: that one cannot be switched off, so 0 and an unset timeout both leave it at its 5000ms default, and a positive value is the only way to raise it. A script that waits longer than its budget is aborted."
    • changedInput schema / properties / websocket / properties / messages / items / properties / selected / description
      Previous value: -"Whether the message is sent. Defaults to true, and is always written, because a .yml message without it is one Bruno will not send. A false is refused in a .bru collection, which cannot record it."New value: +"Whether the message is sent. Defaults to true, and is written for every message that is sent, because a message without it is one Bruno will not send. A false is written as such in .yml; .bru can only record it by omitting the flag, which reads back as absent rather than false."
  2. Changed5 schema fields changedv2.3.0
    • addedInput schema / properties / grpc
      Added value: +{
      +  "additionalProperties": false,
      +  "description": "gRPC-only fields. Applies to kind \"grpc\" and is refused otherwise. Headers given for a gRPC request are written as metadata, which is that transport's only header surface.",
      +  "properties": {
      +    "messages": {
      +      "description": "Request messages. A unary call uses the first.",
      +      "items": {
      +        "additionalProperties": false,
      +        "properties": {
      +          "content": {
      +            "description": "The payload as JSON text. Empty content is written as {}, as Bruno writes it.",
      +            "type": "string"
      +          },
      +          "title": {
      +            "description": "Name of the message. Defaults to \"message N\" by position, as Bruno does.",
      +            "type": "string"
      +          }
      +        },
      +        "required": [
      +          "content"
      +        ],
      +        "type": "object"
      +      },
      +      "type": "array"
      +    },
      +    "method": {
      +      "description": "The fully qualified RPC method, e.g. \"/greet.Greeter/SayHello\". Not an HTTP verb, which is why it is here and not in the top-level method argument.",
      +      "type": "string"
      +    },
      +    "methodType": {
      +      "description": "The RPC shape. All four are written, because Bruno writes all four; note that this server can only run \"unary\" today, so the others author a request Bruno can send and run_collection will refuse.",
      +      "enum": [
      +        "unary",
      +        "client-streaming",
      +        "server-streaming",
      +        "bidi-streaming"
      +      ],
      +      "type": "string"
      +    },
      +    "protoPath": {
      +      "description": "The .proto file describing the service, relative to the collection. Must already exist inside the collection: a path resolving outside it is refused, symlinks included, as is one whose imports leave it however many hops in. Stored relative to the collection whichever spelling is given, so the request survives being cloned elsewhere.",
      +      "type": "string"
      +    }
      +  },
      +  "type": "object"
      +}
    • addedInput schema / properties / kind
      Added value: +{
      +  "description": "Transport. Defaults to \"http\". \"websocket\" and \"grpc\" take no method and no body; their payloads are websocket.messages and grpc.messages.",
      +  "enum": [
      +    "http",
      +    "websocket",
      +    "grpc"
      +  ],
      +  "type": "string"
      +}
    • addedInput schema / properties / method / description
      Added value: +"Required for kind \"http\", refused for \"websocket\" and \"grpc\", which have no HTTP method. A gRPC request names its RPC method in grpc.method."
    • addedInput schema / properties / websocket
      Added value: +{
      +  "additionalProperties": false,
      +  "description": "WebSocket-only fields. Applies to kind \"websocket\" and is refused otherwise.",
      +  "properties": {
      +    "messages": {
      +      "description": "Messages sent in order once the socket is open.",
      +      "items": {
      +        "additionalProperties": false,
      +        "properties": {
      +          "content": {
      +            "description": "The payload, sent verbatim after variable substitution.",
      +            "type": "string"
      +          },
      +          "selected": {
      +            "description": "Whether the message is sent. Defaults to true, and is always written, because a .yml message without it is one Bruno will not send. A false is refused in a .bru collection, which cannot record it.",
      +            "type": "boolean"
      +          },
      +          "title": {
      +            "description": "Name of the message. Defaults to \"message N\" by position, as Bruno does.",
      +            "type": "string"
      +          },
      +          "type": {
      +            "description": "How Bruno's editor should treat the payload: text, json or xml. Nothing validates it, and every frame is sent as text — there is no binary send path.",
      +            "type": "string"
      +          }
      +        },
      +        "required": [
      +          "content"
      +        ],
      +        "type": "object"
      +      },
      +      "type": "array"
      +    }
      +  },
      +  "type": "object"
      +}
    • changedInput schema / required
      Previous value: -[
      -  "collectionPath",
      -  "name",
      -  "method",
      -  "url"
      -]New value: +[
      +  "collectionPath",
      +  "name",
      +  "url"
      +]
  3. First observedv2.2.1

TDQS

A4.3/5.0
Behavior4/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

With no annotations provided, the description carries the transparency burden and does so well: it discloses that scripts run as async functions, that top-level await and bru.sleep/setTimeout/setInterval work, that the script timeout defaults to 5000ms and can be raised via settings, and that websocket/grpc requests reject HTTP method/body semantics. It does not mention overwrite behavior or error cases, but the disclosed behavioral traits go well beyond a minimal statement.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness4/5

Is the description appropriately sized, front-loaded, and free of redundancy?

The description is dense and information-rich, front-loaded with the core purpose and format support, then branching into kind-specific and script-specific details. It earns its length for an 18-parameter tool, though a single long paragraph could be better structured with bullets or section breaks for skimmability.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness4/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

Given the tool's high complexity (18 params, nested objects, no output schema), the description covers the essential orientation: file formats, three transport kinds, key body modes, script execution semantics, and timeout handling. It does not explain return values or overwrite behavior, but the combination of description and rich input schema gives an agent sufficient context to invoke the tool correctly.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters4/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

Schema description coverage is 50%, so the description should add semantic meaning, and it does: it explains how kind interacts with method/body, what form-data file uploads require, and how settings.timeout relates to script execution. The schema itself carries rich descriptions for many properties, and the main description ties key parameters together without simply repeating the schema.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose5/5

Does the description clearly state what the tool does and how it differs from similar tools?

The description opens with a specific verb and resource: 'Generate request files for API testing' and immediately names the supported formats (.bru and .yml). It distinguishes itself from siblings by stating that inline scripts mean 'no separate add_test_script call is needed' and by clarifying the kind-specific behavior (http, websocket, grpc), making the tool's purpose unmistakable.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines4/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

The description gives clear context on when to use create_request: to author request files, with explicit guidance on kind selection and the script inclusion alternative. It does not provide exhaustive when-not guidance against all siblings (e.g., create_crud_requests or modify_request), but the inline-script note and kind distinctions offer solid usage context.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.