Flow Creator

Security

Built to point at real systems

Flow Creator signs in to your environments and calls your APIs. These are the rules it follows while doing that, and how it keeps what it learns.

Accounts and sessions

  • Passwords are hashed with argon2id.
  • Sessions are a random 256-bit token in an http-only cookie; only a hash of it is stored. Sessions last 14 days.
  • Sign-in, reset and sign-up attempts are rate limited per address and email.
  • Reset and invite links work once, expire, and are stored only as a hash. Setting a new password signs you out everywhere else.
  • Requests that change something are refused when they come from another site.

Your credentials

  • GitHub tokens, environment passwords, client secrets, API keys and two-factor secrets are stored encrypted with AES-GCM.
  • They are never sent back to the browser. Alert webhooks are only ever shown as their host.
  • Deploy hook tokens are shown once and stored as a hash.

Run history

  • Tokens are never stored in run history, and sign-in calls are kept with every credential masked.
  • From live environments, responses are kept only as their shape unless you choose to keep bodies, and emails, citizen service numbers and sensitive fields are masked before anything is stored.

Live environments

  • Create, update and assign steps are skipped until you allow writes for that environment.
  • Load tests run only where you allowed them, and the access audit never sends delete probes to a live environment.
  • Load tests and audits only run against domains your project has verified by DNS record or file, so nobody can aim them at someone else’s API.
  • Tours never include deletes.

Calls Flow Creator makes

  • Addresses you enter, such as environments and webhooks, are resolved before every call and must be public: private, loopback, link-local and internal addresses are refused, and so are redirects to them.
  • Webhook addresses must use https.

Who sees what

  • Access is decided per organization and per project: viewer, editor or owner.
  • People outside a project get “not found”, so ids don’t reveal what exists.
  • The people who run Flow Creator have no access to your projects unless your organization invites them.

Check what your roles can reach

The access audit shows, per role and endpoint, what is allowed that shouldn’t be.