Palo Alto Networks Certified Security Automation Engineer (PCSAE)IntegrationsMedium

A security analyst is developing a custom integration for Cortex XSOAR that needs to create and update incidents in an external ticketing system. The ticketing system's API requires a specific `Content-Type` header (e.g., `application/vnd.ticketing.v2+json`) for all POST and PUT requests. How should this custom header be configured in the integration to ensure all relevant commands send the correct type?

  1. ADefine the `Content-Type` as a default parameter in the integration instance configuration.
  2. BSet the `Content-Type` header in the `BaseClient`'s `_http_request` method.
  3. CUse the `params` dictionary in `BaseClient` to include the `Content-Type`.
  4. DAdd the `Content-Type` header to the `headers` dictionary of each individual `requests.post` or `requests.put` call.
Show answer & explanation

Correct answer: B. Set the `Content-Type` header in the `BaseClient`'s `_http_request` method.

Setting the `Content-Type` header in the `_http_request` method of the `BaseClient` ensures that it is automatically included in every HTTP request made by the integration. This is efficient for headers that are universally required for a specific request type (like POST/PUT) across multiple commands.

Why the other options are wrong

  • A. The integration instance configuration typically supports general headers, but overriding `_http_request` provides more granular control for dynamic or conditional header injection.
  • C. The `params` dictionary is for URL query parameters, not HTTP headers.
  • D. While functional, this approach is repetitive and less maintainable if the header is required across many commands.

Global Custom HTTP Header Configuration

To ensure a specific HTTP header (e.g., `Content-Type`) is consistently included in all relevant requests made by a Cortex XSOAR custom integration, override the `_http_request` method within the `BaseClient` class to inject it centrally.

  • Applies the header to all HTTP requests.
  • Avoids repetitive code in individual commands.
  • Ideal for mandatory API-specific headers.

Memory trick: For consistent 'envelope' labels, set them at the 'post office' (BaseClient).

More Integrations questions