flowifai docs
flowifai gates risky MCP tool calls with human approval — credentials stay on your machine, the cloud only decides and audits. Start with the install guide and the quickstart; the concepts pages explain the model behind the gate.
Get started
- Install flowifai — Install, update, and troubleshoot the flowifai CLI, broker, and wrapper — one signed installer, verified checksums, loopback-only broker defaults.
- One-shot MCP setup — Discover and protect several Claude Code or Cursor MCP servers in one accessible setup flow, with a redacted dry run, isolated profile processes, and recoverable client changes.
- Quickstart: your first MCP approval — Discover your Claude Code or Cursor MCP servers, protect several in one setup run, and approve your first gated tool call.
Concepts
- Core concepts: human in the loop MCP approvals — How flowifai puts a human in the loop for MCP tool calls — the broker/wrapper split, the credential boundary, two-phase execution, and the approval ticket lifecycle.
- Protocol-native approvals: the AI agent approval workflow in your MCP client — How flowifai delivers its AI agent approval workflow protocol-natively over MCP URL elicitation — which clients support the full loop today, how others degrade gracefully, and why the dialog is never the security boundary.
Reference
- Policy reference (CEL) — How flowifai policy rules match tool calls — tool patterns, CEL argument predicates, most-restrictive-wins, default-deny, approval requirements, and schema-drift fail-closed behavior.
- Troubleshooting — Diagnose and fix flowifai setup failures — pairing token 401s, broker connectivity, schema drift, doctor checks, and split-host tunnels.
Security
- Security model — What flowifai defends against and what it does not — the credential boundary, the pull-only cloud, the cooperative gate (not a sandbox), and the audit guarantees.
For agents and LLMs: every doc has a markdown twin at/docs/<slug>.md, the full corpus is at/llms-full.txt, and the curated index is at/llms.txt.