Skip to content

Guides & reference

Bring your own AI key

Use your own Anthropic, OpenAI, Gemini, DeepSeek, Qwen, GLM, Kimi or Mistral key on Starter and up: setup, storage, security, limits and errors.
Sculptural study of connected forms and structured ideas

On Starter and every plan above it, you can run flowss's AI features on your own account with an AI provider instead of on hosted AI points. Paste a key from Anthropic, OpenAI, Google Gemini, DeepSeek, Alibaba Qwen, Zhipu GLM, Moonshot Kimi or Mistral, and every AI feature in every studio sends its requests through that key: your provider bills you directly, and no flowss points are spent. This page covers which plans can use a key, the eight providers and what each can do, the two places you can keep a key and exactly how each is stored and protected, which key wins when you have more than one, what a request can cost you at your provider, the daily fair-use ceiling, what happens when your plan changes, and every message you might see along the way. For hosted AI and points, see AI points and limits; for the bigger picture, AI in flowss.

At a glance

FactValue
PlansStarter, Plus, Ultra and Enterprise. Not available on Free
ProvidersAnthropic, OpenAI, Google Gemini, DeepSeek, Alibaba Qwen, Zhipu GLM, Moonshot Kimi, Mistral
Cost in pointsNone. Your provider bills you for each request
Where to add a keyStudio Settings (kept in this browser), or your account page (saved to your account, encrypted)
Which key is usedA key in this browser first, then a key saved to your account, then hosted points
Daily fair-use ceiling1,000 AI requests a day per account, at most 300 of them agent runs. Resets at midnight UTC
Full multi-step agentAnthropic keys. Other providers run each agent request as a single pass without tools
ImagesEvery provider except DeepSeek
Sign-inRequired. A key is checked against your plan, so it is not used while you are signed out
Not used forCalls made through the MCP server, and the flowss Support Agent on the support page

Who can use your own key

PlanYour own keyNotes
FreeNoThe key form on your account page is replaced by an explanation and a See Starter button. A key typed into Studio Settings is stored but refused on every request
StarterYesYour key is the only AI on Starter, because Starter has no hosted points
Plus, Ultra, EnterpriseYesYou can use your key, hosted points, or switch between them by adding and removing the key

The rule is checked on every request, from your signed-in session. A key that is refused is never sent to any provider; flowss tells you why and leaves the key where it is. One plan rule applies even with your own key: the Studio's advanced Photo → Engine (clean-up modes, a forced target engine, alternates and render repair) needs Plus or above. Ordinary photo import works on Starter with your key.

The eight providers

ProviderName in the pickerKey looks likeGet a key atImages
OpenAIOpenAI (GPT-5 family, o-series)sk-…, sk-proj-…, sk-svcacct-… or sk-admin-…platform.openai.comYes
AnthropicAnthropic (Claude)sk-ant-…console.anthropic.comYes
GoogleGoogle (Gemini)AIza…aistudio.google.comYes
DeepSeekDeepSeeksk-…platform.deepseek.comNo
Alibaba QwenAlibaba Qwen (通义千问)sk-…dashscope.console.aliyun.comYes
Zhipu GLMZhipu GLM (智谱)id.secret (two parts joined by a dot)open.bigmodel.cnYes
Moonshot KimiMoonshot Kimisk-…platform.moonshot.cnYes
MistralMistralA key with no prefix, usually 32 charactersconsole.mistral.aiYes

The key shape check is only a typo net: it catches a key pasted under the wrong provider before anything is sent. Whether the key actually works is decided by the provider when the first request arrives.

Note: For Alibaba Qwen and Moonshot Kimi, the "Get a key at" links open the providers' mainland China consoles, but flowss sends requests to their international endpoints. If the provider rejects your key, create one for the provider's international service instead.

Why so many providers: Anthropic and OpenAI cannot be reached or paid for everywhere. Google covers most of the world; DeepSeek, Qwen, GLM and Kimi can be registered and paid for in mainland China; Mistral is the European option.

The model flowss asks for

flowss picks a model for each provider. These are the defaults; flowss may move to a newer model in the same family as providers retire old ones.

ProviderModel usedModel used for images
AnthropicClaude Sonnet 5 for most work; Claude Opus 5 for the deep specialists (Conductor (multi-studio), Critic (judge, do not fix), Framing analyst, Methods & statistics review) and Weave's Deep analysis; Claude Haiku 4.5 for growing mind-map branchesClaude Sonnet 5
OpenAIGPT-5.6 Terra (gpt-5.6-terra) for everythingThe same
Googlegemini-2.5-flashThe same
DeepSeekdeepseek-chatNone
Alibaba Qwenqwen-plusqwen-vl-plus
Zhipu GLMglm-4.6glm-4v-plus
Moonshot Kimikimi-latestThe same
Mistralmistral-large-latestpixtral-large-latest

If your provider rejects a model setting that an older model does not support, flowss retries the request once in a plainer form rather than failing it.

What each provider can do

Every AI feature works on every provider, with two differences.

FeatureAnthropicOpenAI, Google, Qwen, GLM, Kimi, MistralDeepSeek
Quick changes, conversions, tutors, Evidence extraction and every other one-shot featureYesYesYes
Photo, sketch and handwriting reading; images attached to agent runsYesYesNo
The full multi-step agent (tools, several figures, verify, critique and refine)YesSingle passSingle pass

Single pass means an agent request makes one edit to the figure that was open when you pressed Run in the agent's pane (in the Studio, Run the flowss Studio Agent), then flowss runs its own verification and at most one repair. The log says "This provider runs a single pass without tools: one edit to the active diagram, then the platform's own verification." A read-only mode such as a review reports findings and leaves the figure unchanged: "This provider runs a single pass without tools, so this review reports findings and leaves the diagram unchanged." In single-pass mode the flowss Studio Agent cannot create, switch, rename or delete figures. See The flowss Studio Agent and its modes.

With a DeepSeek key, image features stop with "DeepSeek has no vision model, so photo and handwriting features are unavailable with this key. Bring an Anthropic, OpenAI, Google, Qwen, GLM, Kimi or Mistral key for image input." Studio Settings warns about this as soon as you pick DeepSeek.

Two places to keep your key

You can keep a key in this browser, save one to your account, or both.

In this browserSaved to your account
Where you add itStudio SettingsThe Bring-your-own key panel on your account page
Plans that see the formAll plans (the key is refused on Free)Starter and above
Where it worksThis browser only, in every studioEvery browser and device where you sign in, in every studio
How it is storedIn this browser's local storage, tied to your accountEncrypted on flowss's servers
Test buttonTestNone
Removed whenYou remove it, sign out, clear site data, or another account signs in on this browserYou remove it, or delete your account

Add a key in this browser

  1. Open the Studio at /studio.
  2. Open Settings: press ⌘, (Ctrl+, on Windows and Linux), choose Settings… in ⌘K, or open your account menu (your avatar) and choose Settings or the AI points row. A link to /studio?settings=ai opens it directly.
  3. In Bring your own API key, click your provider's card. Each card shows "Get a key at" with a link to the provider's key page.
  4. Paste the key into the field. The field hides it; the eye button (Reveal / Hide) shows it.
  5. Optional: click Test (tooltip "Send a tiny request to verify the key works"). It sends one small diagram request through your key. On success it says "Anthropic (Claude) key works — diagram generated." (with your provider's name); otherwise it shows the provider's or flowss's reason.
  6. Click Save. A tick confirms it. Save and Test stay greyed out, with no message, while the field holds something that does not look like a key for the provider you picked: check the provider card first.

The section's own description reads: "Paste a key from any supported provider and AI requests bill to your provider account instead of spending points (Bring your own AI key — Starter and up). Your key is stored in this browser's localStorage until you sign out, and sent only with AI requests (headers X-User-Api-Key + X-User-Ai-Provider); we never log it." Under the field it adds "Stored locally — sent only to your chosen provider" (naming the provider) "via our proxy.", "Billed directly to your provider account (you control the spend)." and "Clearing site data removes the key — we can't recover it."

To remove it, click the bin button (tooltip Remove key from this browser), or clear the field and click Save.

Note: The Daily AI usage box at the top of Settings ("Free tier — 25 generations per day per browser", with Reset counter) is a tally this browser keeps. It does not limit a signed-in account: hosted AI is metered in points, and your own key by the daily fair-use ceiling.
Note: A key in this browser belongs to the account that was signed in when you saved it. Signing out removes it, and so does another account signing in on this browser. A key saved while nobody was signed in is removed the next time anyone signs in, because flowss cannot tell whose it is; enter it again once you are signed in.

Save a key to your account

  1. Sign in and open your account page.
  2. Find Bring-your-own key. It begins "Bring your own AI key — Starter and up." and goes on: "Paste a key from any of eight providers and AI requests skip the platform quota — billed directly to your provider account. Encrypted at rest with AES-256-GCM; we never see plaintext after you click save."
  3. Choose your provider from the list.
  4. Paste the key. The eye button (Show / Hide) reveals it.
  5. Click Save key. The panel confirms "Saved · AI calls now use your key".

The saved key then appears as a card with the provider and the first eight characters of the key (for example sk-ant-a…), "Last saved" with the date, and "AI requests bypass the platform quota and bill to your provider account directly." Remove asks "Delete your saved BYOK key? AI calls will go back to the platform quota." and then confirms "Key removed". You can keep one saved key at a time; saving another replaces it.

On Free, the panel does not offer the form. It explains "Bringing your own AI key is part of Starter and up, so it isn't active on Free. Any key you save stays encrypted and unused until then — it is never sent to a provider on a plan that can't use it. Upgrading turns it on for your next request." and offers See Starter, which opens the pricing page.

If your account already holds a saved key but your plan cannot use it (for example after moving to Free), the card is amber, its provider line ends "· not in use on this plan", and Remove asks instead "Delete your saved BYOK key? It isn't in use on this plan, so nothing about your AI calls changes — but the key is gone for good."

Which key is used

For each AI request, flowss uses the first of these that exists:

  1. A key in this browser (from Studio Settings), with the provider you picked for it.
  2. A key saved to your account.
  3. Hosted AI, paid with your points.

So a key in this browser overrides a saved key, and either key overrides your points. To go back to hosted points, remove your keys. The AI row in your account menu (and the badge in Study and the Library) reads Own key ("You're using your own AI key — unmetered") when a key is kept in this browser; a key saved only to your account is used just the same but does not change that reading.

How your key is stored and protected

A key kept in this browser

  • It lives in this browser's local storage, tied to the account that saved it, and is removed when you sign out (in any tab).
  • It is attached only to AI requests, in the X-User-Api-Key header with the provider in X-User-Ai-Provider.
  • flowss's server holds it in memory for that one request, uses it to call the provider you chose, and never writes it to a database or a log.
  • Some providers quote a key back in an error message. Every crash report is scrubbed of anything that looks like a credential before it is written anywhere.
  • Anyone with access to this browser profile can read local storage. On a shared computer, prefer saving the key to your account, and sign out when you finish.

A key saved to your account

  • It is encrypted on the server with AES-256-GCM. Only the ciphertext, the initialisation vector and the authentication tag are stored in the database.
  • The encryption key is kept separately from the database, so a copy of the database alone does not reveal your key.
  • The first eight characters are stored in clear so the panel can show which key is saved.
  • It is decrypted in memory, per request, only to call your provider, and only for your signed-in session. The database's access rules deny every client access to the stored row.
  • Remove deletes the row. Deleting your account removes it too.
  • Your data export lists a saved key by its provider and prefix only, never the encrypted key. flowss also records each save and removal in its security audit trail.
  • The panel's own line "we never see plaintext after you click save" means flowss never shows or stores the key in clear; the server still decrypts it in memory for each of your AI requests, as described above.

Where your key goes

A key only ever travels to the provider you paired it with. flowss calls each provider's own published API endpoint: Anthropic and OpenAI directly, Google's Gemini API, api.deepseek.com, Alibaba's international DashScope endpoint, open.bigmodel.cn for GLM, Moonshot's international endpoint (api.moonshot.ai), and api.mistral.ai. The provider's own terms and privacy policy apply to what it receives. What flowss sends with each request is described on AI in flowss.

What a request can cost you at your provider

flowss spends no points on your key, but your provider charges you per request at its own prices. Each request asks for at most a set amount of output, and most use far less:

RequestMost output it may ask for
Generating a diagram16,000 tokens
Refining a diagramTwice the size of the diagram, between 8,192 and 16,000 tokens
A course or a course unit8,000 tokens
A multi-figure project8,192 tokens
TikZ / LaTeX export6,000 tokens
Study cards4,096 tokens
Photo reading4,096 tokens (8,192 for the advanced Photo → Engine)
A tutor answer700 tokens
Handwriting to text512 tokens
An agent runBetween 8 and 20 model turns, depending on the mode, each re-sending the growing conversation

Diagram generation and refinement also make one extra request if the first answer cannot be read. Agent runs on the deep specialists use Claude Opus 5 on an Anthropic key, which your provider prices higher than its standard model.

Tip: Set a monthly spending limit in your provider's console. It is the most reliable way to cap what AI in flowss can cost you.

The daily fair-use ceiling

Requests on your own key are unmetered, not unlimited. Each request still costs flowss server work (fetching a URL for the agent, rendering to verify a result, handling an uploaded image), so each account has a daily ceiling:

CeilingLimitMessage when reached
AI requests on your own key, every feature together1,000 a day"Daily limit for AI requests on your own key reached (1000/day). It resets at midnight UTC — nothing was sent to your provider."
Agent runs on your own key300 a day, within the 1,000"Daily limit for agent runs on your own key reached (300/day). It resets at midnight UTC — nothing was sent to your provider."
  • The ceiling is counted per account, whichever device or key you use.
  • It resets at midnight UTC.
  • A request refused at the ceiling is never sent to your provider, so it costs you nothing there.
  • A request that flowss refuses for another reason first (too long, a link that is not an allowed https address, a malformed file) does not count against the ceiling. A link that is allowed but cannot be fetched is found out later and does count.
  • Weave's Generate on a mind-map branch also has its own limit of 60 a day per network address, whichever way you pay.

Hosted AI's daily safety limits never apply to your own key.

When your plan changes

ChangeWhat happens to your key
Free to Starter or aboveA key you already stored (in this browser or on your account) starts working on your next request. Nothing to re-enter
A paid plan to Free (or a subscription that ends)A saved key stays stored and encrypted but is not used. The account panel shows it in amber with "not in use on this plan", and the AI row in your account menu reads Key not in use for a key kept in this browser. It is never sent to a provider while your plan cannot use it
Any plan, while flowss cannot read your plan for a momentThe key is not used for that request: "We couldn't read your plan just now, so the AI key you brought wasn't used — nothing was sent to your provider. Please try again in a moment."

On Free the account page offers no form for a new key (see Save a key to your account); Studio Settings still lets you keep one in this browser, where it is stored but refused until you upgrade.

Using your key outside the app

  • The REST API. A direct call to the REST API can carry your provider key in the X-User-Api-Key header, with X-User-Ai-Provider naming the provider, alongside your flowss API key. Always send the provider header: without it, flowss guesses the provider from the key's shape, and DeepSeek, Qwen and Kimi keys look like OpenAI keys. A key saved to your account is not used for API calls, because they carry no browser session. See The REST API.
  • The MCP server. AI tools called through the MCP server always run on hosted points; your own key is not used there. See The flowss MCP server.

Tips

  • If you plan to use agents heavily, choose an Anthropic key: it is the only provider that gets the full multi-step agent.
  • If you work with photos, sketches or handwriting, avoid DeepSeek, which has no vision model.
  • Use Test before you rely on a new key. It costs one small request at your provider.
  • Saving the key to your account is the better choice if you use several browsers or devices, or share a computer.
  • Keep a spending limit set at your provider; flowss's ceiling counts requests, not money.
  • On Plus and above you can keep both: remove the key from this browser when you want to spend hosted points instead, and paste it back when your points run low.
  • If you change provider, pick the new provider's card or list entry before pasting, so the key shape check matches.

Limits and known constraints

  • Not available on Free, and not used while you are signed out.
  • One key at a time in this browser and one saved to your account; a key in this browser always wins.
  • The full multi-step agent needs an Anthropic key; other providers get a single pass.
  • DeepSeek keys cannot read images.
  • The advanced Photo → Engine needs Plus or above even with your own key.
  • 1,000 AI requests and 300 agent runs a day per account; Weave branch ideas 60 a day per network address.
  • You cannot choose the model; flowss picks one per provider (see The model flowss asks for).
  • Qwen and Kimi requests go to the providers' international endpoints by default; a key created for a mainland China region account may be rejected there.
  • Your key is not used for MCP calls or for the flowss Support Agent on the support page.
  • If a saved key cannot be decrypted (for example after a security key change on flowss's side), the request falls back to hosted AI and spends points if you have them. Save the key again to fix it.
  • The AI reading in your account menu only reflects a key kept in this browser.

Troubleshooting

Message or symptomCauseWhat to do
Save and Test stay greyed out in Studio SettingsThe pasted key does not look like a key from the provider you pickedCheck you picked the provider the key came from, and that you copied the whole key with no spaces
"Key doesn't look like a valid key for that provider — check you picked the provider the key came from."The same, on the account pageChoose the right provider in the list, then save again
"That doesn't look like an API key from a supported provider. Nothing was sent."The key in this browser matches no provider's shapePaste the key again in Studio Settings, or remove it
"Bringing your own AI key is part of Starter and up, so the AI key you brought wasn't used on the free plan. Nothing is wrong with the key — it wasn't sent to any provider, and it stays exactly where it is. Upgrade to Starter and it works on your next request."You are on FreeUpgrade to Starter. The message says "the AI key saved to your account" when it is about your saved key
"Bringing your own AI key is part of Starter and up, and signed out we can't tell which plan this key belongs to — so it wasn't used or sent to any provider. Sign in and it works on your next request…"You are signed outSign in. If the key was saved while signed out, it was removed at sign-in; enter it again
"We couldn't read your plan just now, so the AI key you brought wasn't used — nothing was sent to your provider. Please try again in a moment."A temporary problem reading your planTry again in a moment
"Your API key was rejected: …" followed by the provider's wordsThe provider refused the key: revoked, mistyped, or issued for a different regionCheck the key in your provider's console and paste it again. For Qwen and Kimi, use a key from the provider's international platform
A message from your provider about rate limits, quota or billingYour provider's own limit or balanceRaise the limit or add credit at your provider, or wait
"Daily limit for AI requests on your own key reached (1000/day)…"The daily fair-use ceilingWait until midnight UTC; on Plus and above, remove the key to use hosted points meanwhile
"Daily limit for agent runs on your own key reached (300/day)…"The daily agent-run ceilingWait until midnight UTC, or use one-shot features meanwhile
"DeepSeek has no vision model, so photo and handwriting features are unavailable with this key…"DeepSeek cannot read imagesUse a key from another provider for image features
"This provider runs a single pass without tools…" in the agent logYour key is not an Anthropic keyUse an Anthropic key, or hosted AI, for the full multi-step agent
"Advanced Photo → Engine is part of Plus and Ultra…"The advanced photo pipeline is a plan featureUpgrade to Plus, or use ordinary photo import
Your account menu's AI row reads Key not in useA key is kept in this browser but your plan cannot use itUpgrade to Starter, or remove the key
Your account menu still shows points after you saved a key to your accountThe reading only reflects a key kept in this browserNothing to fix: the saved key is used. Your points stay untouched
Your key disappeared from Studio SettingsYou signed out, another account signed in, or site data was clearedPaste it again, or save it to your account instead
"Nothing to delete or storage unavailable."You pressed Remove but no key is saved, or saving is temporarily unavailableReload the account page; try again later if the key is still listed
"Could not save key."A temporary problem storing the keyTry again later; meanwhile, keep the key in this browser
Points were spent although you saved a keyYour saved key could not be read, so the request fell back to hosted AI; or the request came through the MCP server, which always uses pointsSave the key again on your account page. For MCP, see The flowss MCP server

Something unclear or out of date on this page? Tell us from the Support link in any studio — the flowss team reads every report.

© 2026 Voranox Inc. flowss — Flow Systems Studio. All rights reserved.

This documentation, its text and its examples are protected by copyright. Engine and format names are trademarks of their respective owners — see the terms and copyright and licences.