# Flowise

> Install Flowise from the App Store, create the administrator account, store model API keys as credentials, build and embed a chatbot, and back up your flows.

Source: https://zopanel.net/docs/app-flowise  
Updated: 2026-10-09

Flowise is a visual builder for AI applications: you connect blocks for models, prompts, memory, documents and tools on a canvas to build chatbots, assistants that answer from your documents, and multi-step agents. Each flow can then be embedded on a website or called through an API. Use it when you want a custom AI assistant without writing much code, with the flows and data on your own server.

## Requirements

| Item | Value |
| --- | --- |
| Image | `flowiseai/flowise:3.1.2` |
| Memory limit | 1024 MB, 1 CPU |
| Free disk to install | about 6.0 GB (the image is about 3.4 GB) |
| Domain | a domain or subdomain pointed to the server, for example `flow.example.com` |
| API key | from at least one model provider (OpenAI, Anthropic, Google, DeepSeek…), added inside Flowise. You pay the provider directly. |

Docker must be installed (**App Store → Install Docker**). Customers need a package that allows Docker apps and has 1024 MB of **RAM (MB)** free for apps; see [App limits for customers](/docs/apps#app-limits-for-customers).

## Install

1. Point the domain's A record to the server.
2. Open **App Store** and click **Install** on the **Flowise** card.
3. Fill in the dialog:

   | Field | What to enter |
   | --- | --- |
   | **Domain** | for example `flow.example.com` |
   | **Owner** | Administrators only: the hosting account the app belongs to |
   | **Free SSL (Let's Encrypt)** | Leave it on |

4. Click **Install** and follow the task log.

Flowise has no install-time fields. ZoPanel keeps everything Flowise writes in one folder and turns off its telemetry:

| Variable | Value |
| --- | --- |
| `DATABASE_PATH`, `SECRETKEY_PATH` | `/home/node/.flowise`: the SQLite database and the encryption key for credentials |
| `BLOB_STORAGE_PATH` | `/home/node/.flowise/storage`: uploaded files |
| `LOG_PATH` | `/home/node/.flowise/logs` |
| `DISABLE_FLOWISE_TELEMETRY` | `true` |

The first start takes one to two minutes. Until Flowise answers, the site shows a "busy" page that reloads by itself.

## Create the administrator behind the setup lock

The first person to open a new Flowise creates its administrator, so ZoPanel keeps it private. Visitors see "This app is being set up".

1. Open **Websites**, choose the domain and go to the **Docker** tab.
2. When the status is `running`, click **Open the app (only for me)**.
3. On the **Setup Account** screen, enter the administrator's name, email (your login) and a password. Flowise requires at least 8 characters with upper- and lower-case letters, a digit and a special character.
4. Sign in.
5. Back on the **Docker** tab, click **Setup finished — open to everyone**.

ZoPanel does not configure email for Flowise, so features that send email, such as password reset links, do not work. Store the administrator password safely.

## Add credentials (API keys)

Flowise stores provider keys as **Credentials**, encrypted with the key in its data folder, and the blocks on the canvas refer to them by name.

1. In the left menu, open **Credentials** and click **Add Credential**.
2. Choose the provider, for example **OpenAI API** or **Anthropic API**.
3. Give it a name, paste the key and click **Add**.

Set a spending limit in the provider's dashboard: every message to a published chatbot is billed to your key.

## Build and publish a chatflow

1. Open **Chatflows** and click **Add New**.
2. Drag blocks from the **+** menu onto the canvas, for example a chat model (select your credential), a memory block and a chain or agent, and connect them.
3. Click **Save** and test it with the chat button on the canvas.
4. Click **</>** (API endpoint) to get the embed snippet for a website, or the URL of the prediction API:

   ```text
   https://flow.example.com/api/v1/prediction/<chatflow-id>
   ```

5. Protect API access with a key from **API Keys**, and allow only your website domains in the chatflow's security settings if you embed it.

For document question answering, use a document loader, a text splitter, an embeddings block and a vector store. Vector stores that keep data in Flowise (for example the in-memory store) or a public managed service (Pinecone, Qdrant Cloud, Supabase…) work; databases on the server itself do not (see [Network limits](#network-limits)).

## Where your data lives

```text
/var/lib/zopanel-apps/<instance>/data/
```

`<instance>` is the domain with dots replaced by hyphens (`flow.example.com` → `flow-example-com`). It is mounted at `/home/node/.flowise` and holds the database (`database.sqlite`: users, chatflows, credentials, chat messages, API keys), the encryption key (`encryption.key`), uploaded files in `storage/` and logs in `logs/`. Only root and the container can read it.

**Important:** the database and the encryption key belong together. A database restored without its key gives "Credentials could not be decrypted".

## Back up

ZoPanel's website backups do **not** include `/var/lib/zopanel-apps`; the **Backups** card on the website's **Docker** tab backs up the app instead, with the database and its encryption key together.

To back up Flowise, click **Back up now** on the **Backups** card of the website's **Docker** tab. Administrators can also set a **Schedule** (**Off**, **Every day** or **Every week**; off by default) and how many copies to **Keep** (1–60, default 7), then click **Save**. Each backup archives `/var/lib/zopanel-apps/<instance>/` into `/var/backups/zopanel-apps/<instance>/YYYYMMDD-HHMMSS.tar.gz`, a folder only root can read that does not count toward the account's disk quota. The container is paused (not stopped) for the few seconds of the copy, so the SQLite database is consistent. Older copies beyond **Keep** are removed, and a failed scheduled backup sends administrators the **Backup failed** alert.

To restore, an administrator clicks **Restore** next to a backup. Flowise is stopped and its data replaced with the archive; the current data is kept aside until the restored app starts, and put back if it does not. Changes made since the backup are lost. Each backup also has a delete button (administrators only), and deleting the app together with its files deletes its backups too. Customers can click **Back up now** and see the list; the schedule and restores are done by the provider. Customers can also export each chatflow from its settings menu on the canvas (**Export Chatflow**) to keep a copy of the flow; credentials are not included and must be added again.

The archives stay on the same server. Copy important ones off it (for example with `scp` or `rclone` from `/var/backups/zopanel-apps/<instance>/`) and store them encrypted, since they contain the encryption key and therefore give access to every stored API key. To restore on another server, install Flowise on the same domain there, copy the archive into `/var/backups/zopanel-apps/<instance>/` on the new server and click **Restore** on its **Backups** card.

## Update

An administrator clicks **Update to latest** on the **Docker** tab. ZoPanel pulls the image this ZoPanel version is pinned to (`flowiseai/flowise:3.1.2`), recreates the container and keeps the data. Newer Flowise versions arrive with ZoPanel updates. Flowise migrates its database on start, so back up first (**Back up now**). Customers ask their provider.

## Network limits

The container is cut off from the server's loopback (`127.0.0.1`) and private networks, from link-local addresses and from other containers. On the server itself it reaches only ports 80, 443, 25, 465, 587 and DNS. For Flowise:

- Blocks that call `localhost` or a private address fail: an Ollama or LocalAI model server, or a PostgreSQL, MySQL, Redis or Qdrant on the same server or on your private network.
- Use public APIs and managed services instead: model providers, hosted vector databases, public HTTP APIs.
- Your websites on the same server are reachable through their public domain over HTTPS (port 443), for example an HTTP request block that calls your own API.
- Another app from the App Store cannot be reached directly; call it through its public domain.

## Troubleshooting

| Problem | What to do |
| --- | --- |
| "This website is very busy right now" just after installing | Flowise is still starting. Wait a minute or two. |
| Visitors see "This app is being set up" | Click **Setup finished — open to everyone** on the **Docker** tab. |
| The password is refused on **Setup Account** | Use 8+ characters with upper and lower case, a digit and a symbol. |
| `Credentials could not be decrypted` | The database was restored without its `encryption.key`. Restore both from the same backup, or add the credentials again. |
| `ECONNREFUSED 127.0.0.1` or a timeout to a private IP | Blocked by design; use a public endpoint. |
| Model errors (401, 429, quota) | Check the credential's key and the balance at the provider. |
| Uploading a large document fails | Requests through nginx are limited to the website's upload size (256 MB by default). Raise **Maximum upload (MB)** on the website's **Tools** tab → **Upload size**. |
| The container restarts while processing documents | It reached the 1024 MB limit. Split documents into smaller uploads or use a hosted embeddings and vector store. |
| `not enough disk space: this app needs about 6.0 GB free…` | Free disk space, then install again. |

Read **Application output** on the **Docker** tab for errors from the app.

## Related

- [What each app does](/docs/app-catalog)
- [App Store and S3 storage](/docs/apps)
- [Open WebUI](/docs/app-open-webui)
- [n8n](/docs/app-n8n)
- [Packages and limits](/docs/packages-limits)
- Official: [Flowise documentation](https://docs.flowiseai.com), [environment variables](https://docs.flowiseai.com/configuration/environment-variables)
