Skip to content

security

Keys, tokens and what leaves your machine

Where credentials live, what is sent where, and how to revoke access.

Your AI key is yours

AI features in the extension run on a key you provide, held in VS Code's SecretStorage β€” which is your operating system's credential store, the Keychain on macOS, Credential Manager on Windows, or your keyring on Linux. It is not in settings and not in a file in the extension folder. FlowKy does not proxy those calls and does not see the traffic. If you do not add a key, those features are unavailable rather than silently degraded.

Extension tokens

Signing in to flowky.ai is what connects the extension: it reads the session cookie and exchanges it server-side for a scoped, revocable token. Only that token is stored, never the cookie. Revoke it from Settings β†’ Security, which invalidates the extension immediately.

The local bridge

The channel between browser and editor is a WebSocket on 127.0.0.1, authenticated with a pairing code you copy across once. It is loopback only. Console output, errors, network traffic and screenshots go through it and do not leave your machine.

What is sent to FlowKy

Content-wise, only what you save: tasks, flows, captures you choose to keep, and your brand kit. No prompt, no file content and no source code is sent to FlowKy β€” AI calls go from your machine to your provider.

One thing is sent without you pressing anything, and it is fair to know about it: when you are signed in, the extension reports a count of AI requests to your account, batched and sent shortly after the requests happen. Literally a number and the word ai_request. It is what draws the usage chart on your dashboard and what enforces the daily limit on your plan. If you are not signed in, nothing is sent at all.

The extension also keeps a more detailed record of what you have run β€” which commands, how often β€” but that stays on your machine and is never uploaded. There is no analytics SDK, no crash reporter and no third-party tracker in the extension.

OAuth scopes

Signing in asks for the minimum. Additional scopes β€” Search Console, private GitHub repositories β€” are requested at the moment you use the feature that needs them, not bundled into the sign-in. If you never import from Search Console, FlowKy never asks for it.