Appearance
Replace the Cloud Proxy token and other keys
Flowstate uses two kinds of key to receive AI data from your own Macs and software:
- The Cloud Proxy token, inside the profile on every Mac with the agent. One token covers all your Macs.
- AI service account keys, one for each of your own services that report AI use to Flowstate.
Keys for your AI providers' billing are different — you replace those on the provider's page under Settings → Integrations. See Connect AI providers.
How the Cloud Proxy token works
- It's created when you select Generate MDM profile on Settings → AI → Cloud Proxy, and it's inside the profile that downloads.
- It lasts one year from that moment. When it expires, Macs with that profile stop sending sessions.
- Every time anyone selects Generate MDM profile, a new token is created. Earlier tokens keep working until they expire.
- The page shows the token once. Flowstate doesn't keep a list of the tokens you've generated, so note the date you generate each profile.
- Replacing the token doesn't change your organisation's certificate, Flowstate Tenant CA.
You need access to manage AI telemetry keys to generate a profile — ask your Flowstate admin.
Replace the Cloud Proxy token
Do this a few weeks before the token's one-year expiry, or when someone who handled the profile leaves.
- Open Settings → AI → Cloud Proxy and select Generate MDM profile.
- Replace every
$EMAILin the new profile with your device management tool's email variable, as you did at rollout. See Set the email variable. - In your device management tool, replace the old profile with the new one for every Mac in scope.
- The next day, open Insights → Agent insights → Agent sessions and check sessions are still arriving from those Macs.
- Delete your copies of the old profile file.
Nothing changes for the people using the Macs, and their sessions carry on under the same names.
The old token still works
Generating a new profile doesn't cancel the old token. If you're replacing it because it may have been seen by someone who shouldn't have it, follow the steps below instead.
If the token has leaked
Use this if the profile or the token was posted, shared or lost.
- Contact Flowstate support and ask them to cancel your organisation's Cloud Proxy token.
- Wait until support confirms it's cancelled. A profile you generate before then is cancelled too.
- Generate a new profile, replace
$EMAIL, and deploy it to every Mac straight away. - Check sessions are arriving again in Agent sessions.
Expect a gap
From the moment the token is cancelled until a Mac receives the new profile, that Mac sends nothing to Flowstate, and its AI conversations during that time aren't recorded.
AI service account keys
Each AI service account under Settings → AI → AI Service Accounts has its own key. Your engineers put it in the service that reports AI use. See AI service accounts.
- The key is shown once, when you create the account: select Copy API key before you close the dialog. Flowstate can't show it again.
- It lasts one year from when the account was created.
You need access to update integrations to create or delete AI service accounts — ask your Flowstate admin.
Stop a service account key working
- Open Settings → AI → AI Service Accounts.
- Select Delete on the account's row, then Delete AI service account.
The key stops working straight away, and the service's reports to Flowstate are refused. The account's history is kept.
Replace a lost, leaked or expiring key
- Delete the account, as above.
- Select New AI service account and enter the same Name and Environment as before.
- Select Save AI service account, then Copy API key.
- Give the new key to the engineer who looks after the service, to replace the old one where it's stored.
- Check Last seen on the new account updates once the service runs.