Skip to content

Guides & reference

Account settings and your data

Every section of your account page: plan, AI points history, usage meters, agent runs, your AI key, API keys, two-step verification, password, data export and deletion.
Sculptural study of connected forms and structured ideas

Your account page at /account is where everything about your flowss account lives: your plan and billing, your AI points and their history, today's usage, your recent agent runs, your own AI provider key, API keys for the developer API, two-step verification and your password, a download of all your data, and the route to account deletion. This page walks through each section from top to bottom, describes every control and message, and then covers the account settings that live elsewhere: your profile details, email preferences, the usage-measurement switch and signing out.

At a glance

Section on /accountWhat it is forMore detail
HeaderGreeting, your plan, your AI points or calls left, your email address.The header
Current plan cardYour plan, price, billing cycle and renewal date, plus Upgrade or Manage billing.Managing your subscription
AI pointsYour hosted AI balance, buy buttons, and Points history.The AI points card
Jump back inTiles that open each studio.Jump back in
Today's usageDaily meters for AI requests, rendering, export, PlantUML, TikZ and literature search.Today's usage
Agent runsYour last 20 agent runs, how each ended and what it cost.Agent runs
Bring-your-own keySave an AI provider key to your account (Starter and up).Bring-your-own key
API keysCreate and revoke keys for the render API and developer API.API keys
Pricing tiers, Docs & quickstart, SupportShortcuts to the pricing page, the docs and support.Help shortcuts
SecurityTwo-step verification and Password.Security
Your dataExport everything and Account deletion.Your data

Three sections have their own link you can share or bookmark: /account#billing (the plan card), /account#security and /account#account-data.

Opening your account page

  • From the header on your Library, the account page and other pages with the header bar: select the pill with your avatar and name. Its tooltip reads "Account, billing, API keys".
  • From any studio: open the account button (your avatar) and choose Account & billing. The same menu has Library, Plans (the pricing page), Settings where the studio has one, an AI points row showing your balance, and Sign out.
  • Directly: go to /account.

If you open the account page while signed out, you are taken to sign in and brought back afterwards.

Along the top of the page are the flowss logo (back to the home page), Pricing, Docs, a Library link, the pill with your avatar and name, and a sign-out button. On narrow screens the Pricing, Docs and Library links are hidden; the shortcut cards further down the page lead to the same places.

The header

The header greets you by your first name with a greeting that follows your device's clock: "Good morning", "Good afternoon", "Good evening", or "Burning the midnight oil" between midnight and 5 a.m. (it shows "Welcome back" for a moment while the page loads). Your first name comes from the name on your account, or from the part of your email address before the @ if there is no name.

Beside the greeting:

  • Your avatar — the picture from your sign-in provider, or your initial on a coloured tile if there is none.
  • A plan chip, for example "Plus plan".
  • An AI chip, showing "N AI points left" (with a green gauge, or red when you have none left). If your points balance cannot be read, it may show "N AI calls left today" instead, or no chip at all.
  • Your email address, on wider screens.

After a purchase, a green notice appears above the header: "Your plan is active. Thanks for subscribing." after a subscription, or "100 AI points added to your balance. Thanks for the top-up." after a point pack.

The Current plan card

The card at the top right shows your plan name, its one-line description, the price in the corner, how you are billed and when the plan renews. On Free its button is Upgrade; on a paid plan it is Manage billing, which opens Stripe's billing portal for card changes, invoices, plan changes, switching between monthly and annual, and cancelling. Every state of the card, and every message it can show, is described in Managing your subscription. For what each plan includes, see Plans and what they include.

The AI points card

The AI points card shows your hosted AI balance. It appears whenever you are signed in and your account's points can be read, on every plan, Free included.

What the card shows:

PartWhat you see
BalanceYour total spendable points, as a large number.
BreakdownOn a plan with an allowance: "150 of 200 monthly + 0 purchased" (with your own numbers). On a plan without one but with bought points: "40 purchased (no monthly allowance on Starter)". Otherwise: "Free includes no hosted AI" (or the name of your plan).
MeterOn a plan with an allowance, a bar showing how much of this month's allowance you have used: green, amber from 80% used, red when it is all used.
Buy buttonsOn Plus, Ultra and Enterprise: 100 pts — $5 and 500 pts — $20, with "One-time payment. Purchased points never expire and are spent after your monthly allowance."
No hosted allowanceOn Free and Starter, instead of buy buttons: a card headed "No hosted allowance" with a Get Plus — 200 pts / mo button and the note "Hosted points start on Plus, and point packs top up that allowance. Bringing your own API key instead starts on Starter — a Free account has no AI at all, hosted or its own."

Under the card, the rules that apply whatever your balance:

"1 point per standard AI call; an Architect run 4, an agent run 8, a deep-specialist run 47; a flow costs the sum of its steps; an attached image adds 2. The allowance is monthly on every plan — a year paid up front still resets on the 1st (UTC), not all at once; purchased points never expire and are spent after it. Your own API key skips points entirely, on Starter and up."

Buying a pack is described step by step in Managing your subscription. How points work in the studios is in AI points and limits.

Points history

Under the rules, Points history lists the last 50 movements of your balance, newest first. Dates are in UTC, the same clock the allowance resets on; hover over a date to see the full date and time. The list scrolls within the card.

EntryMeaningShown as
Hosted AI callPoints spent on an AI request.A negative number, for example −8
Top-up — 100-point pack (or 500-point pack)A pack you bought.A positive number in green
Top-up refunded, Top-up disputed, Top-up reversedA pack's points taken back after a refund or a card dispute.A negative number
Adjustment by flowssA correction made by the flowss team.Positive or negative

The line under each entry says where the points came from: "Monthly allowance", "Purchased points" or "Monthly + purchased". When there is nothing to show yet, the list reads "Nothing yet — top-ups and hosted AI calls will be listed here."

Jump back in

Jump back in is a launchpad of tiles, each opening a studio:

TileDescription on the tile
Studio (the wide tile)"Code-to-diagram across N engines + FlowScript", where N is the current engine count (110 at the time of writing), with Open the Studio →
Evidence"Agentic evidence graphs from papers"
Lab"FlowScript — typed research diagrams"
Science"Biology · Chemistry · Physics · Math"
Weave"Drag-drop canvas"
BPMN"Visual process modeler"
Sketch"Hand-drawn diagrams"

All workstations → at the top right of the section opens the Studio. Study and Figure do not have tiles here; open them from the studio switcher or the command palette. On Free, opening a studio outside your plan takes you to the pricing page with a note explaining it is part of Starter.

Today's usage

Today's usage shows how much of each daily allowance you have used today. The note beside the heading reads "Resets at midnight UTC · Counted against your account".

MeterWhat it counts
AI requestsRequests to the AI service.
Headless renderDiagrams rendered through the render API.
Server-side exportExports produced on the server.
PlantUML proxyPlantUML diagrams rendered through the server.
TikZ / LaTeXTikZ / LaTeX conversions.
Literature searchSearches for papers in Evidence.

Each meter shows "used / cap" and a bar that turns amber from 80% and red when the cap is reached. The caps depend on your plan; the full table is in Plans and what they include.

The AI requests meter is a backstop. While the points system is running, hosted AI is charged in points (see the AI points card above), so this meter can stay at or near zero even on a busy day. Engines rendered through the Kroki relay also have a daily cap, but it has no meter here.

If per-account counting is not available, the meters fade and show off, and the note reads either "Anonymous IP bucket — sign in for per-account meters" or that meters are disabled.

Agent runs

Agent runs lists your last 20 runs of a studio's agent (such as the flowss Studio Agent) or flow, with the note "Your last 20 · times in UTC".

ColumnWhat it shows
WhenThe start time, for example "Sep 29, 14:05", in UTC.
AgentThe agent or flow, by the name the agent panels use.
OutcomeCompleted, Failed, Stopped (you stopped it), Timed out, Running, or Did not finish (a run still marked running more than 10 minutes after it started).
PointsThe points the run was charged.

If you have no runs yet, the section reads "No agent runs yet. Runs you start from an agent panel appear here with how they ended and the points they were charged." See The flowss Studio Agent and its modes.

Bring-your-own key

The Bring-your-own key panel saves an AI provider key to your account, so AI features run on your own provider account instead of hosted points. Its description begins with the entitlement: "Bring your own AI key — Starter and up." It continues: "Paste a key from any of eight providers and AI requests skip the platform quota — billed directly to your provider account. Encrypted at rest with AES-256-GCM; we never see plaintext after you click save."

Saving a key (Starter and up)

  1. Choose the provider from the drop-down: "OpenAI (GPT-5 family, o-series)", "Anthropic (Claude)", "Google (Gemini)", "DeepSeek", "Alibaba Qwen (通义千问)", "Zhipu GLM (智谱)", "Moonshot Kimi" or "Mistral".
  2. Paste the key into the field. The placeholder shows the shape of that provider's keys (for example sk-ant-… for Anthropic). Use the eye button to show or hide what you typed.
  3. Choose Save key. The confirmation reads "Saved · AI calls now use your key".

Once saved, the panel shows a green card with the provider (for example openai) and the first characters of the key followed by "…", a Remove button, and "Last saved [date]. AI requests bypass the platform quota and bill to your provider account directly."

To remove the key, choose Remove and confirm "Delete your saved BYOK key? AI calls will go back to the platform quota." The panel then shows "Key removed".

On Free

On Free the panel shows no form, only the message "Bringing your own AI key is part of Starter and up, so it isn't active on Free. Any key you save stays encrypted and unused until then — it is never sent to a provider on a plan that can't use it. Upgrading turns it on for your next request." and a See Starter button.

If you saved a key while on a paid plan and later moved to Free, the saved card turns amber and reads "· not in use on this plan". It starts working again on the first request after you upgrade.

Account key or browser key

There are two places to put a key. A key saved here is stored, encrypted, with your account and used on every device you sign in from. A key pasted into a studio's Settings panel lives only in that browser, is cleared when you sign out, and takes priority over the account key while it is there. For the full picture, including which providers support image features, see Bring your own AI key.

API keys

The API keys panel creates keys for the developer API. Its description reads: "For the headless /api/render endpoint (which needs a key or a signed-in session), the /api/v1 endpoints and the MCP server — wire diagrams into CI, docs builds, or back-end pipelines. Cleartext is shown ONCE on creation." API keys are available on every plan.

Creating a key

  1. Type a name in the field "Key name (e.g. CI pipeline)". Names can be up to 80 characters; a blank name becomes "Untitled".
  2. Choose Create key.
  3. A box headed New key — copy now, won't show again shows the full key. Keys begin with glyp_.
  4. Choose Copy ("Copied to clipboard" confirms it) and store the key somewhere safe, such as your CI system's secret store.
  5. Choose Dismiss to close the box. The full key cannot be shown again.

Each key in the list shows its name, its first characters followed by "…", "last used [date]" or "never used", and "created [date]".

Revoking a key

  1. Choose Revoke beside the key.
  2. Confirm "Revoke this key? Existing integrations using it will stop working immediately."
  3. The panel shows "Key revoked" and removes the key from the list.

When there are no keys, the panel reads "No API keys yet. Create one to call /api/render and the /api/v1 endpoints from CI — the render API needs a key." How to send a key with a request, and the limits that apply, are in The REST API, Embedding and the render API and The flowss MCP server.

Warning: An API key works without your password and without a browser session, so it keeps working after a password change. If a key may have leaked, revoke it.

Help shortcuts

Three cards sit below the keys:

  • Pricing tiers — "Compare Free / Starter / Plus / Ultra / Enterprise." Opens /pricing.
  • Docs & quickstart — "The 20-minute fluency guide, every engine, every shortcut." Opens /docs.
  • Support — "hello@flowss.ai · a person reads every message." Opens an email to support with the subject "flowss support". You can also use the support form.

Security

The Security section (/account#security) has two cards: Two-step verification and Password.

Two-step verification

Two-step verification adds a second step to signing in: after your password (or Continue with Google / Continue with GitHub), flowss asks for a 6-digit code from an authenticator app such as 1Password, Google Authenticator or Authy. Someone who learns your password, or gets into your inbox, still cannot get into your account. It is optional and off until you turn it on.

To turn it on:

  1. Open /account#security and choose Turn on two-step verification.
  2. A QR code appears with three numbered notes: "Scan this code with your authenticator app.", "Enter the 6-digit code it shows." and "Your other devices are then signed out, and ask for a code when you sign in there."
  3. Scan the QR code with your authenticator app. If you cannot scan, the text beside it reads "Can’t scan? Type this key into the app instead. Save it in your password manager too — it is how you get back in if you lose your phone." Type the key shown below that into your app; the copy button beside the key copies it.
  4. Type the 6-digit code from the app into Code from the app. Verify and turn on stays disabled until you have typed six digits.
  5. Choose Verify and turn on. To abandon setup, choose Cancel.
Tip: Save the setup key in your password manager before you finish. There are no backup codes: the setup key is how you recreate your codes on a new phone.

When it is on, the card shows a green On badge and a line such as "Authenticator app (2026-10-04 14:05 UTC) · added Oct 4, 2026". The browser where you turned it on stays signed in. On your other devices, flowss asks for a code from your app before you can carry on.

Under the card, a box headed If you lose your phone explains what to do. With two-step verification on, it says the setup key you saved recreates your codes in any authenticator app. If you have lost every copy of the key, email hello@flowss.ai from your account's address; proving the account is yours without a code takes time.

Signing in with two-step verification on:

  1. Sign in as usual with your email and password, Continue with Google or Continue with GitHub.
  2. A page headed Enter your verification code says your email address has two-step verification on and asks you to "enter the 6-digit code it shows for flowss".
  3. Type the code into Verification code and choose Verify. You continue to where you were going.

The same page has a Sign in with a different account button, and help if you have lost your phone: "Lost your phone? If you saved the setup key when you turned this on, add it to an authenticator app on any device and enter the code it shows. Lost the key too? Email hello@flowss.ai from the address on your account."

To turn it off:

  1. Choose Turn off on the card.
  2. A confirmation box reads "Turn off two-step verification? Your account will be protected by your password alone. Enter the code your authenticator app shows now to confirm it is you."
  3. Type the current code into Code from the app.
  4. Choose Turn off (it stays disabled until you have typed six digits), or Keep it on to back out.

Turning it off always needs a fresh code from your authenticator app, so neither a stolen password nor a browser left signed in can switch it off.

Password

The Password card changes your password. Its description reads "Changing it signs you out on every other device, and we email you that it changed."

  1. Enter your Current password.
  2. Enter a New password (the field's hint reads "At least 8 characters") and type it again in Confirm new password.
  3. If two-step verification is on, a Code from your authenticator app field appears; enter the code your app shows. (The field also appears if the server asks for a code after you submit.)
  4. Complete the verification challenge if one is shown.
  5. Choose Change password. It stays disabled until all three password fields are filled in.

On success the card reads "Password changed. Other devices have been signed out." and you receive an email that your password was changed.

If you sign in with Google or GitHub and have never set a password, you cannot change one here. Use Forgot password? on the sign-in page to create one. See Creating an account and signing in.

Your data

The Your data section (/account#account-data) has a link, What we hold, and why, to the Privacy Policy, and two cards.

Export everything

Export everything downloads one JSON file with every record flowss holds against your account. In the words of the card: "profile, workspace, projects, teams, keys, plan, usage, invitations, feedback and the security log. The file describes what each table holds and what it leaves out. Live secrets are withheld and the file names each omission: an API key arrives as its prefix, never its hash; a saved AI key as its provider and prefix, never its ciphertext."

To export:

  1. Choose Download my data. The button reads Building your file… while the file is prepared.
  2. Your browser saves a file named like flowss-account-export-2026-10-04.json (with the date in UTC).
  3. The card confirms "Downloaded [file name]".

What the file covers:

AreaExamples of what is included
ProfileYour name, email, avatar and preferences.
Your workYour cloud-synced workspace, projects you own (with full diagram data), projects you can open and your role in each, comments you left, reusable sketch components, links between your diagrams and repository files.
Study and classesYour Study decks, cards, course progress and review history; cohorts you created or belong to; coursework you set or submitted, with grades and feedback.
ResearchResearch atlases you own or belong to, their sources, claims and synthesis runs, your screening decisions, risk-of-bias judgements and canonical entities.
Teams and invitationsTeams you own or belong to, team and project invitations sent to you or by you, your entries in project activity feeds.
Plan and AIYour plan and billing period, AI point balance, point purchases, your daily usage counters, and the AI provider key you saved (provider and prefix only).
KeysAPI keys you created (prefix only) and when each was last used.
CommunicationsFeedback and bug reports you sent, private support requests, emails we sent you, email categories you opted out of, whether mail to your address hard-bounced or was reported as spam, and waitlist sign-ups with the consent wording you agreed to.
SecuritySecurity-log events on your account, such as API keys created and revoked, a saved AI key added or removed, plan changes and point top-ups, plus crash reports captured while you used the app.

Each section of the file carries its own description of what it holds. Where columns were withheld, the section says so; where a section would survive account deletion, it says why; and where a section does not exist on the service, it says there is nothing to report rather than leaving you to wonder. The file also lists up front what account deletion would keep and why. Some records of emails sent to you can refer to several recipients, so they are listed for manual review rather than in full; contact support for a verified, individually redacted copy.

Note: The export covers what is stored with your account. Work that lives only in one browser (for example documents you made while signed out) is not in the file. Export those from the studio they are in; see Exporting your work.

Account deletion

Self-service account deletion is temporarily unavailable while protection for shared work is being improved. The Account deletion card says so:

"Self-service account deletion is temporarily unavailable while we improve protection for shared work. Contact support to request deletion or help with an earlier incomplete request. You can still export your data and manage your subscription. Sending a support request does not delete your account or cancel your subscription."

The card has three links: Contact support about deletion (the support form), Export my data and Manage billing.

To request deletion:

  1. Download your data first with Download my data if you want to keep any of it.
  2. If you pay for a plan and want to stop paying, cancel it in Manage billing. A deletion request does not cancel your subscription.
  3. Open the support form, choose the Privacy topic, and say you want your account deleted. Mention any shared work (projects or teams with other members, classes you teach, shared research atlases) or an earlier incomplete deletion. You can also email hello@flowss.ai from the address on your account.
  4. Support reviews the request and confirms the outcome. Privacy requests are answered within 30 days.

The intended scope of deletion is published in the Privacy Policy and summarised here.

What deletion removes

RemovedNotes
Your profile and your ability to sign inName, email address, avatar and preferences.
Your cloud workspaceEvery diagram in it.
Projects, teams and research atlases nobody else belongs toContents included.
Your research-atlas work, even where the atlas survives youYour canonical entities, the concept links pointing at them and your screening decisions. Some of this can disappear from other people's research.
Your API keys and saved AI provider keyIntegrations using either stop working.
Your plan, AI points and point purchasesA live subscription is cancelled before anything is erased.
Everything else that is only yoursYour comments, sketch components, coursework submissions, usage counters, agent run history, crash reports and the log of emails sent to you.

What deletion keeps, and why

KeptWhy
Your unsubscribe and spam-complaint recordsKept against the address alone, so you are never emailed again.
Security-log entriesUnlinked from your account and kept as an audit trail; payment-processor identifiers are stripped out first.
Feedback you sentThe message stays; your email address, account link and device id are wiped.
Things other people are attached toInvitations you sent, coursework you set on a class, repository links on a shared project and replies under your comments stay, with your authorship removed.
A research atlas you shareHanded on to a remaining member (promoted to owner if needed) rather than deleted.
Risk-of-bias judgements in an atlas someone else still usesKept without your authorship, because removing them would silently change the review's certainty ratings.
Your entries in shared project activity feedsKept but emptied of your name, account link and preview text.
Invoices and charges held by the payment processorTax and accounting law requires them.
Anonymous product telemetryNever carried your account; it ages out on the 90-day schedule.

What stops a deletion: a project or team that still has other members (transfer ownership or remove the members first), and a class you teach that still has students (there is no way to hand a class over inside the product, so this needs a person at flowss to resolve). A class nobody else has joined does not block anything; it is deleted along with the assignments you set on it.

Warning: Completed deletion cannot be undone. Deleted accounts are not restored, from backups or otherwise, so download your data first.

Your name, email address and picture

There is no control on the account page to edit your display name, email address or profile picture:

  • Name and picture come from your sign-in. With Google or GitHub, they are your name and avatar there; with email and a password, your name is the one you gave when you signed up.
  • Email address: to change the address on your account, contact support from the address currently on the account.

To correct anything else flowss holds about you, contact support. See Privacy and your data.

Email preferences

flowss sends two kinds of email:

  • Service messages about your account: security notices, receipts, billing notices and anything you ask for. These cannot be switched off.
  • Commercial email in two lists: Product news ("Launches, new workstations, pricing changes.") and Getting-started emails ("A few short nudges in your first week.").

Every commercial email has two links in its footer:

  • Unsubscribe from these emails — opens a page headed Unsubscribe? that asks whether to stop sending that kind of email (for example "getting-started email") to your address. Choose Yes, unsubscribe to confirm; the page then reads Unsubscribed. This stops only the list the email came from. Mail apps that offer a one-click unsubscribe button use the same link.
  • Email preferences — opens a page headed Email preferences showing each list with an On or Off badge and an Unsubscribe or Resubscribe button. If you have unsubscribed from all non-essential email, the page says so, and resubscribing to one list turns only that list back on.

Preferences are managed from these email links; you do not need to sign in to use them.

Usage measurement

flowss measures anonymous product usage with first-party telemetry: a random per-browser id, an event name from a fixed list, the studio the event happened in, a few approved properties and a timestamp. It never includes your account, email, IP address, diagram content or search text. A nightly job deletes rows older than 90 days (after a backlog, some can survive a few days longer).

To switch it off for a browser:

  1. Open the Privacy Policy and go to section 4, "Product telemetry — exactly what is collected".
  2. Under "Anonymous usage measurement on this browser", choose Turn usage measurement off.
  3. The status reads "Off. New events and pending events are discarded."

While measurement is on, the status reads "On. No account identifiers or content are collected." The setting applies to that browser and can be changed back at any time with Turn usage measurement on. If your browser sends Do Not Track or Global Privacy Control, measurement is already off, the status reads "Off — your browser privacy signal is respected." and the button is disabled. If your browser cannot store the choice, a note says so; the setting then applies only until you reload. Turning measurement on or off does not subscribe you to any email.

Signing out

Choose the sign-out icon beside your name in the header, or Sign out in a studio's account menu. Signing out clears this device's personalisation, any AI key saved in this browser, and the cached plan and points balance, and leaves your documents untouched. See Creating an account and signing in.

Tips

  • Turn on two-step verification. It takes a minute and protects your projects, saved keys and billing even if your password leaks.
  • Name each API key after where it is used ("CI pipeline", "docs build") so you know which to revoke.
  • Copy a new API key before you choose Dismiss; it is never shown again.
  • Check Points history when your balance moves unexpectedly: every spend, top-up and reversal is listed.
  • Download your data occasionally as a personal backup of what is stored with your account.
  • On a shared computer, sign out when you finish.

Limits and known constraints

  • Self-service account deletion is temporarily unavailable; deletion is by support request.
  • There is no in-app control to change your display name, email address or profile picture.
  • Two-step verification is set up with one authenticator app from this page and has no backup codes. When you sign in, a code from any authenticator verified on the account is accepted. If you lose your phone, add the setup key you saved to a new authenticator app; if you lost the key too, email support from the address on your account.
  • The account page has no usage meter for renders through the Kroki relay, although that relay has a daily cap.
  • Exports and other account operations are limited to 30 a day per account.
  • Points history shows the last 50 movements; agent runs show the last 20.
  • An API key is shown in full only once, at creation.
  • After a reload, the API keys list may still include a key you revoked earlier, with no revoked marker; revoked keys no longer work. Choosing Revoke on one again shows "Key not found or already revoked."
  • Saving your own AI key requires Starter or above.
  • Usage meters reset at midnight UTC; the AI points allowance resets on the 1st of each month (UTC).

Troubleshooting

What you seeWhat it meansWhat to do
You are sent to sign in when opening /accountYou are signed out.Sign in; you return to your account page.
The AI points card is missingYour account's points could not be read (account storage is unavailable).Reload in a moment.
The Points history list is missing from the AI points cardThe history could not be read just now.Reload later; your balance above is still correct.
Usage meters show offPer-account metering is not available right now.Nothing to do; your limits still apply.
"That code didn’t match. Codes change every 30 seconds — enter the one your app shows now."Wrong or expired code.Enter the code your app shows now. Check your device clock is set automatically.
"That took too long. Enter the current code from your app."The verification step expired.Enter a fresh code.
"Too many attempts. Wait a few minutes, then try again."Too many code or password attempts.Wait a few minutes.
"Confirm a code from your authenticator app first, then try again."This browser's session has not been verified with a code.Sign out, sign back in and enter your code, then try again.
"Two-step verification isn’t available on this deployment yet."The feature is not switched on.Try again later.
"Couldn’t load your security settings. Check your connection and refresh."The security card could not load.Check your connection and reload.
"Couldn’t start two-step setup. Check your connection and try again." or "Couldn’t turn two-step verification off. Check your connection and try again."The request did not reach the sign-in service.Check your connection and try again.
"Sign-in isn’t available. Refresh the page and try again."The sign-in service could not be reached from this page.Reload the page.
"Enter the 6-digit code from your authenticator app."The code field is empty or not six digits, or a code is needed to change your password.Type the six digits your app shows.
"Enter your current password."The Current password field is empty.Type your current password.
"This account has no email address to sign in with."The account has no email address to check a password against.Contact support.
"Your current password is incorrect. If you sign in with Google or GitHub and never set a password, use “Forgot password?” on the sign-in page to create one."The current password is wrong, or the account has no password.Re-type it, or create one with Forgot password?
"Couldn’t change your password. Check your connection and try again."The change did not go through.Check your connection and try again.
"The two new passwords don’t match."The confirmation differs.Type the same new password twice.
"That is your current password. Choose a new one."New and current passwords are the same.Choose a different password.
"Use a password of at least 8 characters."The new password is too short.Use 8 or more characters.
"That password was refused as too weak or previously leaked in a data breach. …"The password is on a breach list or too weak.Choose a different one.
"Complete the verification challenge first."The anti-abuse check was not completed.Complete the challenge, then submit.
"Key doesn't look like a valid key for that provider — check you picked the provider the key came from."The key does not match the selected provider.Pick the right provider in the drop-down.
A message that the key could not be saved, or "Nothing to delete or storage unavailable."Key storage is unavailable.Try again later, or paste the key into a studio's Settings panel for now.
A notice that server-side BYOK isn't configured, pointing to the Studio Settings panelAccount-level key storage is not available.Paste your key into the Settings panel in a studio; it is kept in that browser.
"Could not create key. …"The key could not be created.Try again later.
"Server returned a malformed key response."The key may have been created, but its secret was not shown.Reload the page. If a new key appears in the list, revoke it and create another.
"Key not found or already revoked."The key was already revoked.Nothing to do.
"Could not revoke key."The revoke failed.Try again.
"Too many account operations today. Try again tomorrow."The daily limit for exports and other account operations was reached.Try again after midnight UTC.
"The server returned an empty file — nothing was downloaded." or "Export failed" followed by a status codeThe export failed.Try again; contact support if it repeats.
"Could not build your export. Please try again."The export failed on the server.Try again later.
"This deployment has no database configured, so there is nothing stored server-side to export. …"No account storage is available.Export your work from each studio instead.
"Account export is unavailable … Email support and we will run it by hand."Export is not available right now.Email hello@flowss.ai.
"This preferences link is not valid"The email link was truncated or is very old.Use the link from a more recent email.
"This link manages one list only"The link came from a single-list unsubscribe.Use the Email preferences link in a recent email.
"This unsubscribe link is not valid"The unsubscribe link was truncated or is very old.Use the link from a more recent email, or email hello@flowss.ai.
"We cannot load your preferences right now", "We could not save that" or "We could not record that"A temporary problem; nothing was changed.Try again in a minute, or email hello@flowss.ai.

Something unclear or out of date on this page? Tell us from the Support link in any studio — the flowss team reads every report.

© 2026 Voranox Inc. flowss — Flow Systems Studio. All rights reserved.

This documentation, its text and its examples are protected by copyright. Engine and format names are trademarks of their respective owners — see the terms and copyright and licences.