Zendesk connection¶
Connect a task to the Zendesk Support API over a managed Leoflow Connection.
The subdomain host, agent email, API token, and an Extra blob are encrypted at
rest and delivered to the task as AIRFLOW_CONN_<CONN_ID>.
URI shape¶
The Login is the agent email and the Password is the API token; the
control plane percent-escapes the token and ZendeskHook un-escapes it. The
Extra blob (token, use_token) rides in __extra__.
Fields the UI asks for¶
| Field | Required | Notes |
|---|---|---|
| Conn Id | yes | e.g. zendesk_default. Exported as AIRFLOW_CONN_ZENDESK_DEFAULT. |
| Conn Type | yes | zendesk. |
| Host | yes | The subdomain host, e.g. company.zendesk.com. |
| Login | yes | The agent email, e.g. agent@example.com. |
| Password | yes | The API token. Stored encrypted at rest (ADR 0019). |
| Extra | optional | JSON, e.g. {"token":"<api-token>","use_token":true}. |
Example DAG¶
The hook is imported inside the task body so DAG parsing stays import-light.
from airflow.decorators import dag, task
from pendulum import datetime
@dag(schedule=None, start_date=datetime(2026, 1, 1), catchup=False)
def zendesk_export():
@task
def fetch():
from airflow.providers.zendesk.hooks.zendesk import ZendeskHook
hook = ZendeskHook(zendesk_conn_id="zendesk_default")
return hook.get_ticket(ticket_id=1)
fetch()
zendesk_export()
Security notes¶
- Token auth: set
use_token: truein Extra and store the token in Password (or in Extra'stoken). The token grants API access for the agent. - Secrets in logs: never
print()the URI โ it carries the API token. - gRPC channel (agent โ control plane): secrets are served only over an authenticated channel (ADR 0021); Pro must run with TLS.