Connect tools over S3
Your Flow XO files are reachable from any S3-compatible tool: the AWS CLI, rclone, mountpoint-s3, or your own code. Generate an access key, then point the tool at Flow XO.
What you need
Section titled “What you need”Open Settings → Access keys in a workspace or a project, then open How to connect external tools. It shows the three values every tool asks for:
| Setting | Value |
|---|---|
| Endpoint | https://flowfs-s3.flowxo.com |
| Bucket | flowfs- followed by your organization ID. Copy it with Copy bucket. |
| Region | us-east-1. AWS tools insist on one. Flow XO doesn’t check it. |
The examples below write the bucket as flowfs-YOUR-ORG-ID. Paste yours in its place.
Generate an access key
Section titled “Generate an access key”- In Settings → Access keys, choose Generate access key.
- Name it after the tool that will use it, like “Backup script” or “My laptop”. The name is optional and only you see it.
- Choose Generate.
- Copy the Access key ID and the Secret access key. Copy as ~/.aws/credentials snippet copies both in the format the AWS CLI reads.
The secret is shown once. If you lose it, revoke the key and generate another.
Workspace keys and project keys
Section titled “Workspace keys and project keys”A key reaches only the files of the place it was generated in.
- Workspace key: generated in workspace settings. It reaches that workspace’s files, including its projects.
- Project key: generated in a project’s settings. It reaches that project’s files and nothing outside it.
A request for anything outside the key’s reach is refused with AccessDenied, even with a valid signature.
AWS CLI
Section titled “AWS CLI”Add a profile to ~/.aws/credentials:
[flowxo]aws_access_key_id = YOUR-ACCESS-KEY-IDaws_secret_access_key = YOUR-SECRET-ACCESS-KEYThen pass the endpoint with every command:
# List filesaws --profile flowxo --endpoint-url https://flowfs-s3.flowxo.com \ s3 ls s3://flowfs-YOUR-ORG-ID/
# Upload a fileaws --profile flowxo --endpoint-url https://flowfs-s3.flowxo.com \ s3 cp ./report.pdf s3://flowfs-YOUR-ORG-ID/reports/report.pdf
# Download a fileaws --profile flowxo --endpoint-url https://flowfs-s3.flowxo.com \ s3 cp s3://flowfs-YOUR-ORG-ID/reports/report.pdf ./report.pdf
# Copy a whole folder upaws --profile flowxo --endpoint-url https://flowfs-s3.flowxo.com \ s3 sync ./exports s3://flowfs-YOUR-ORG-ID/reports/exports/rclone
Section titled “rclone”Add a remote to ~/.config/rclone/rclone.conf:
[flowxo]type = s3provider = Otherenv_auth = falseaccess_key_id = YOUR-ACCESS-KEY-IDsecret_access_key = YOUR-SECRET-ACCESS-KEYendpoint = https://flowfs-s3.flowxo.comregion = us-east-1acl = privateThen use flowxo: paths:
rclone ls flowxo:flowfs-YOUR-ORG-ID/rclone copy ./report.pdf flowxo:flowfs-YOUR-ORG-ID/reports/rclone sync ./exports flowxo:flowfs-YOUR-ORG-ID/reports/exports/mountpoint-s3
Section titled “mountpoint-s3”Mount the bucket as a folder on Linux or macOS. This reads the flowxo profile from the AWS CLI section:
mount-s3 flowfs-YOUR-ORG-ID /mnt/flowxo \ --endpoint-url https://flowfs-s3.flowxo.com \ --profile flowxomountpoint-s3 won’t replace an existing file unless you add --allow-overwrite.
Keep keys safe
Section titled “Keep keys safe”Anyone with a key ID and its secret can read and change every file the key reaches. Treat the secret like a password.
Keys don’t expire. To stop one working, choose Revoke next to it in Settings → Access keys. Tools using it stop working immediately, and this can’t be undone.