API Autodiscovery pairs a Mule API implementation with an API instance managed in API Manager. The global autodiscovery element requires the API instance identifier and a flowRef that identifies the flow where API Gateway policy enforcement begins.
MuleSoft explicitly states that flowRef must reference a flow containing an HTTP Listener. The referenced flow represents the inbound API entry point receiving the requests against which API Manager policies are enforced. Connectors that merely use HTTP internally are not sufficient for this requirement.
In an APIkit-generated application, the appropriate flow is typically the main API flow that contains the HTTP Listener and APIkit Router. Individual generated resource/operation flows execute later after routing; they are not the primary inbound policy-enforcement point. Similarly, the APIkit Console flow is intended for interactive API documentation/testing and should not be used as the flowRef for production policy enforcement.
The attribute is not simply supplied dynamically at runtime. It is part of the Mule application's Autodiscovery configuration and identifies the exact listener-based flow paired to API Manager.
Therefore, flowRef must identify the flow containing the HTTP Listener that receives the REST API's incoming requests.
Reference topics: API Autodiscovery; api-gateway:autodiscovery; flowRef; HTTP Listener; API Manager policy enforcement.
Official documentation: https://docs.mulesoft.com/mule-gateway/mule-gateway-config-autodiscovery-mule4
===============================================================
Submit