Skip to content

Connect tools over S3

Your Flow XO files are reachable from any S3-compatible tool: the AWS CLI, rclone, mountpoint-s3, or your own code. Generate an access key, then point the tool at Flow XO.

Open Settings → Access keys in a workspace or a project, then open How to connect external tools. It shows the three values every tool asks for:

Setting Value
Endpoint https://flowfs-s3.flowxo.com
Bucket flowfs- followed by your organization ID. Copy it with Copy bucket.
Region us-east-1. AWS tools insist on one. Flow XO doesn’t check it.

The examples below write the bucket as flowfs-YOUR-ORG-ID. Paste yours in its place.

  1. In Settings → Access keys, choose Generate access key.
  2. Name it after the tool that will use it, like “Backup script” or “My laptop”. The name is optional and only you see it.
  3. Choose Generate.
  4. Copy the Access key ID and the Secret access key. Copy as ~/.aws/credentials snippet copies both in the format the AWS CLI reads.

The secret is shown once. If you lose it, revoke the key and generate another.

A key reaches only the files of the place it was generated in.

  • Workspace key: generated in workspace settings. It reaches that workspace’s files, including its projects.
  • Project key: generated in a project’s settings. It reaches that project’s files and nothing outside it.

A request for anything outside the key’s reach is refused with AccessDenied, even with a valid signature.

Add a profile to ~/.aws/credentials:

[flowxo]
aws_access_key_id = YOUR-ACCESS-KEY-ID
aws_secret_access_key = YOUR-SECRET-ACCESS-KEY

Then pass the endpoint with every command:

Terminal window
# List files
aws --profile flowxo --endpoint-url https://flowfs-s3.flowxo.com \
s3 ls s3://flowfs-YOUR-ORG-ID/
# Upload a file
aws --profile flowxo --endpoint-url https://flowfs-s3.flowxo.com \
s3 cp ./report.pdf s3://flowfs-YOUR-ORG-ID/reports/report.pdf
# Download a file
aws --profile flowxo --endpoint-url https://flowfs-s3.flowxo.com \
s3 cp s3://flowfs-YOUR-ORG-ID/reports/report.pdf ./report.pdf
# Copy a whole folder up
aws --profile flowxo --endpoint-url https://flowfs-s3.flowxo.com \
s3 sync ./exports s3://flowfs-YOUR-ORG-ID/reports/exports/

Add a remote to ~/.config/rclone/rclone.conf:

[flowxo]
type = s3
provider = Other
env_auth = false
access_key_id = YOUR-ACCESS-KEY-ID
secret_access_key = YOUR-SECRET-ACCESS-KEY
endpoint = https://flowfs-s3.flowxo.com
region = us-east-1
acl = private

Then use flowxo: paths:

Terminal window
rclone ls flowxo:flowfs-YOUR-ORG-ID/
rclone copy ./report.pdf flowxo:flowfs-YOUR-ORG-ID/reports/
rclone sync ./exports flowxo:flowfs-YOUR-ORG-ID/reports/exports/

Mount the bucket as a folder on Linux or macOS. This reads the flowxo profile from the AWS CLI section:

Terminal window
mount-s3 flowfs-YOUR-ORG-ID /mnt/flowxo \
--endpoint-url https://flowfs-s3.flowxo.com \
--profile flowxo

mountpoint-s3 won’t replace an existing file unless you add --allow-overwrite.

Anyone with a key ID and its secret can read and change every file the key reaches. Treat the secret like a password.

Keys don’t expire. To stop one working, choose Revoke next to it in Settings → Access keys. Tools using it stop working immediately, and this can’t be undone.