AI Agents

Is it safe to give an AI agent access to my FlipperForce data?

Is it safe to give an AI agent access to my FlipperForce data?

Your API key gives an agent the same access you have, so treat it like a password. An agent only acts when you ask it to, and a good prompt shows you every change before it is saved.

Connecting an AI agent is safe when you understand what your API key does and you keep a review step in front of every change.

What your API key can do

Your key carries unrestricted read and write access to every project and record in your workspace. It does not unlock anything you could not already see yourself, but anyone holding it has that same access. Treat it like the password to your accounting system.

Where to keep it

Two approaches, and the right one depends on who else can see the Project.

  • Save it as a Project knowledge file. Convenient, and it works in every conversation automatically. Anyone with access to that Project can retrieve it, which on a shared team Project means everyone on the team.
  • Paste it at the start of each session. A manual step every time, but nothing persists. The right choice for shared or higher-sensitivity setups.

If the key lives in Project knowledge, keep that Project to yourself. Do not put an unrestricted key into a Project shared with contractors, assistants or team members who should not have full write access.

Never paste it into a third-party tool, a browser extension or a website. The only place it belongs is the authorization header on a request to tools.flipperforce.com.

An agent only acts when you ask

Nothing runs in the background. There are no scheduled jobs and no webhooks, so FlipperForce never pushes your data anywhere on its own. Every request happens because you asked for it in that conversation.

How to stay in control

  • Start with read-only requests and end them with Change nothing.
  • Ask the agent to show you every record it plans to create or edit before it saves
  • Approve changes one at a time for anything that edits or removes existing data
  • Tell it never to display the key in a response, a script, a log or a screenshot
  • Review your workspace Activity Log afterward to confirm what was written

Deleting is permanent

Records deleted through the API cannot be recovered. Never give an agent a blanket instruction to delete. Name the specific record, and confirm it yourself first.

Rotate your key if

You share a screen recording, hand off a laptop, remove a team member, or suspect it has been exposed. Request a replacement through the integrations page, or email support@flipperforce.com and we will help.

Related Video

Related FAQs

Still Have Questions?  DaveBot can help!

Get immediate, feature-specific answers without digging through articles. DaveBot is here 24/7 to provide detailed explanations, troubleshooting tips, and guidance on all FlipperForce tools.
Chat with DaveBot (Be Nice, I'm in Beta)!