Skip to content

Install the cloud proxy

Onboarding starts at Settings → AI → Cloud Proxy. There are two rollout paths. Both install the same Flowstate Agent and route its traffic through proxy.flowstate.inc; they differ only in how the device authenticates.

Step 1 - Open Settings → AI → Cloud Proxy

The page has a self-install card, an MDM card, and a custom-hostnames editor. Pick the path that fits your fleet:

  • Self-install (device flow): individual developers, or teams without MDM. No key handling.
  • MDM / managed fleet: silent rollout to managed devices via a generated configuration profile.

Step 2a - Self-install (device flow)

Send users the self-install guide, or point them at the self-install card's link on the Cloud Proxy page. Each user:

  1. Installs the agent on their machine.
  2. Launches it and approves the sign-in prompt in the browser.
  3. Is done. The agent obtains a revocable per-device credential and routes AI traffic through the proxy automatically.

There is no key to copy or paste on this path.

Step 2b - MDM (managed fleet)

  1. Click Generate MDM profile on the Cloud Proxy page.
  2. Flowstate downloads a macOS .mobileconfig named for your tenant. It embeds your org-wide Cloud Proxy key and leaves the user email as the MDM $EMAIL placeholder, so one profile enrols the whole fleet.
  3. The page reveals the org token once, next to the download. Copy it only if you configure a device by hand. It is not shown again.
  4. Deploy the agent package and the profile through your MDM (Kandji, Jamf Pro, Intune, Mosyle, Workspace ONE, JumpCloud). See Install on macOS for the package rollout, and the Windows and Linux pages for those platforms.

Step 3 - Custom AI-service hostnames (optional)

If your organisation uses private or custom provider endpoints (a custom Azure OpenAI endpoint, a private Bedrock host), add those hostnames in the Custom AI-service hostnames editor on the same page. Standard provider hosts are always covered. Changes reach the fleet within about 5 minutes.

Step 4 - Verify traffic

Use any AI tool on an onboarded device, then check Insights → Agent insights → Agent sessions (/plan/main/insights/agents/sessions). Sessions appear within a few minutes, attributed to the signed-in or enrolled user. Individuals can check their own sessions at My AI → My sessions.

Rollout notes

  • The Cloud Proxy does not replace provider billing connectors. Use Usage providers for invoice reconciliation.
  • Rotation of the org token follows the runbook at Key rotation. There is no rotate button on the page.

Where to go next

Flowstate Documentation