Adding an API key#
- Go to Settings → Model Configuration
- Select your provider
- Paste your API key
- Click Save
LumenFlow validates the key by making a lightweight test call to the provider. If validation fails, you'll see the specific error.
Key security#
Your API key is encrypted with industry-standard encryption before storage. The encryption is workspace-specific, so keys cannot be accessed across workspaces. Encryption keys are stored separately from your data, providing multiple layers of protection.
Rotating keys#
To rotate your API key:
- Generate a new key from your provider's dashboard
- Go to Settings → Model Configuration
- Click Update Key
- Paste the new key
- The old key is immediately discarded
Revoking access#
If you suspect a key is compromised:
- Revoke the key at your provider's dashboard immediately
- Update the key in LumenFlow settings
- Check the audit trail for unexpected actions
warning Never share your API key in chat messages, emails, or documentation. LumenFlow will never ask for your key outside the settings page.