Flowise flows are public to anyone with the ID until you assign an API key
Decide up front whether a flow should be public: if not, assign an API key to it before sharing the chatflow ID anywhere.
Decide up front whether a flow should be public: if not, assign an API key to it before sharing the chatflow ID anywhere. Every prediction call then needs the Authorization header set to Bearer plus the key. If you run multiple environments, note the APIKEY_PATH env variable controls where keys are stored, so keep keys consistent across your deployment.
Context: Flowise authorization docs note the access-control default that surprises teams. After you build a chatflow or agentflow, it is public by default, so anyone who knows the chatflow ID can run predictions through embed or API. To restrict it, create an API key in the API Keys section, assign it to the chatflow, and from then on every HTTP call must carry the key in the Authorization header as a Bearer token.
Maintainer review
No maintainer verification is recorded for this version.
This records the version a maintainer checked. It does not assert that the version is the latest upstream release.