Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Flowise can be self-hosted with npm or Docker, but its maintenance status is a major deployment risk: the official GitHub repository was archived on August 13, 2026, and Flowise’s security page carries a product-sunset notice. Treat a new deployment as an unsupported-software decision, not as a routinely maintained production platform. If you still need to run it, Docker Compose is the documented route; plan persistent storage, protect the credential-encryption key, and restrict access before exposing an instance beyond your machine.

What Flowise does

Flowise is a visual platform for building AI agents and LLM workflows. Its documentation describes three builders:

  • Assistant: a guided way to make an assistant that follows instructions, uses tools, and retrieves information from uploaded files.
  • Chatflow: for chatbots, single-agent systems, and simpler LLM flows, including options such as retrieval, reranking, and Graph RAG.
  • Agentflow: for multi-agent systems and more complex workflow orchestration.

Flowise also reports support for more than 100 sources, tools, vector databases, and memory integrations; that is a vendor-stated capability count, not an independent measurement. Other documented areas include custom code, branching and routing, tracing and analytics, evaluations, human review, APIs, a CLI and SDK, embedded chat, workspaces, and self-hosted or air-gapped deployments.

Choose a deployment route

The right route depends on how much infrastructure you want to operate and how much control you need. Flowise documents npm and Docker self-hosting. Its deployment materials also name cloud providers and hosted platforms, but do not establish a current price or performance ranking.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Route What the documentation establishes What to weigh
npm An official installation route for running Flowise locally or on self-managed infrastructure. You manage the runtime and its updates. Follow the instructions for the exact release you intend to run.
Docker Compose A documented Compose sequence starts the application in the background and serves the local interface at http://localhost:3000. You must configure persistent paths, make mounted directories writable by the container user, and preserve the credential-encryption key.
Cloud infrastructure The project lists AWS, Azure, DigitalOcean, Google Cloud Platform, and Alibaba Cloud. Flowise says established cloud providers require more technical expertise but offer greater flexibility and control.
Hosted deployment platforms The project lists Railway, Northflank, Render, Hugging Face Spaces, Elestio, Sealos, and RepoCloud. Check the chosen platform’s current Flowise image or deployment instructions, persistence behavior, access controls, and support terms.

These platform names indicate documented options, not a recommendation or confirmation of current availability. For any route, include the project’s archived and sunset status in the decision: the official materials do not identify a recommended successor.

Start Flowise with Docker Compose

The documented quick start uses the project repository’s Docker directory. These are the documented steps, not a guarantee that a particular archived release will work unchanged with your current host or Docker installation. Use files from the specific release you choose, and inspect its configuration before starting it.

  1. Obtain the Flowise repository or release files. Use the official project source and select the version you intend to run. The repository is archived, so do not assume its instructions or dependencies are being updated.
  2. Open the Docker directory in the checked-out project.
  3. Create the environment file by copying .env.example to .env.
  4. Review and configure the environment before starting the service. In particular, decide where persistent data and the credential-encryption key will live, and set appropriate authentication and security options for your release.
  5. Start the Compose services with docker compose up -d.
  6. Open the interface at http://localhost:3000 when accessing the instance locally.

The npm method is also documented, but the setup steps and requirements are version-dependent. Use the official instructions for the exact release rather than combining commands or environment settings from different versions.

Make Docker data persistent and recoverable

The Docker README identifies DATABASE_PATH, LOG_PATH, SECRETKEY_PATH, and BLOB_STORAGE_PATH as persistence settings. Without deliberately managed storage, you may lose important application data or files when replacing or recreating a container. The README says the container runs as the non-root node user with UID 1000. On Linux, mounted host directories may need ownership changed to UID/GID 1000 so the container can write to them.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Flowise stores third-party credentials, such as model-provider or vector-database keys, encrypted using an encryption key. Its documentation says a random key is generated by default and stored at a configured file path; it also describes AWS Secrets Manager as an optional key-storage mechanism. Changing the key or its path can prevent saved credentials from being decrypted.

  • Choose durable locations for the database, logs, key, and blob storage before relying on the instance.
  • Check that mounted host directories are writable by UID 1000.
  • Keep the encryption key stable and protect a backup of it separately from the running instance.
  • Keep backups outside the instance, and make sure your restore procedure recovers both application data and the key needed to decrypt credentials.

These are operational precautions based on the documented storage and key behavior; Flowise does not thereby perform backups or guarantee recovery for you.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Secure access before using a VPS

A local address such as http://localhost:3000 is not the same as a secured public deployment. Before making a VPS instance reachable from outside your machine, decide how its UI and API will be protected and limit network access to what your use case needs. Do not treat a successful Compose start as a production security review.

Match authentication settings to your version

The authorization guide describes email-and-password authentication from version 3.0.1 onward, using JWT access and refresh tokens. It recommends setting custom, strong JWT and secret-token values rather than relying on defaults, which could increase the chance of forged tokens and user impersonation. For production email configuration, the guide recommends SMTP_SECURE=true and ALLOW_UNAUTHORIZED_CERTS=false. Older username-and-password application-level authorization is described as deprecated. Confirm the authentication behavior and settings in the documentation for the release you are actually running.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Keep security controls enabled

The environment-variable guide warns that disabling CUSTOM_MCP_SECURITY_CHECK permits arbitrary command execution and creates significant production risk. It says HTTP_SECURITY_CHECK and PATH_TRAVERSAL_SAFETY are enabled by default and describes an HTTP deny list. Do not disable these protections casually; inspect the version-specific configuration and security guidance before changing them.

Review advisories, not just a version number

A Flowise maintainer advisory for CVE-2025-59528 identifies a critical CustomMCP code-injection issue in version 3.0.5 and lists 3.0.6 as the version that patched that specific issue. A fix for one vulnerability does not establish that a release is free of other vulnerabilities. The official security page lists later advisories, says the project is being sunset, and states that new security reports are not being accepted. Review the advisory history for the version you plan to use and decide whether an unsupported application is suitable for your workload.

What the sunset means for a deployment decision

The official repository’s archived status and product-sunset notice materially change the risk of self-hosting Flowise. Do not assume active maintenance, support, or future security fixes. That matters most when an instance handles sensitive credentials, is reachable from the internet, or supports a service that needs ongoing security updates.

  • A contained evaluation: Keep access restricted, use non-sensitive test credentials, and avoid treating the instance as a durable production dependency.
  • An existing deployment: Inventory the version, exposure, stored credentials, persistent data, and backup-and-restore plan. Review the official advisories that apply to that version.
  • A new production system: Assess whether the sunset and lack of ongoing security-report handling are acceptable before committing. The available official material does not establish a recommended replacement.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.