flowleap-keyslisted
Install: claude install-skill flowleap-ai/flowleap-plugins
# FlowLeap Provider Keys (BYOK)
Patent data flows through provider APIs that may need the USER's own
credentials: EPO OPS (consumer key + secret — always a pair) and USPTO ODP
(single API key). Keys live in `credentials.toml` (0600) and are forwarded
per-request; the CLI never prints them (verbose/dry-run redact).
## Diagnose
```bash
flowleap --json keys list # what's configured locally (masked)
flowleap --json keys test # live verdicts: source user|server|none, valid true|false|null
flowleap --json doctor # includes a providerKeys section
```
`keys test` needing nothing locally is fine when `source` is `server` — the
backend has its own keys and commands work without BYOK.
## The agent protocol — when keys are missing or rejected
Failed commands carry a `providerKeysHint` in the JSON error envelope:
```json
"providerKeysHint": {
"code": "provider_keys_required", // or provider_keys_invalid
"provider": "epo",
"requiresHumanIntervention": true,
"nonInteractive": { "command": "flowleap keys set epo --key … --secret …",
"env": ["FLOWLEAP_EPO_KEY", "FLOWLEAP_EPO_SECRET"] },
"signup": "https://developers.epo.org (free, 'My apps' → create app)"
}
```
**Getting keys requires a browser signup — an agent cannot complete this
alone. Do not retry, do not invent keys.** Tell the user:
> This command needs EPO OPS credentials. Please run `flowleap setup` in a
> terminal (guided, ~2 minutes; free keys from https://developers.epo.or