Prerequisites
- A Flespi account at flespi.io.
- Access to the Flespi panel to create and manage API tokens.
- For production workloads, an ACL token with permissions scoped to the modules CloudThinker needs.
Setup
1
Generate an API token
In the Flespi panel, navigate to Tokens in the left menu and click the ”+” button:
- Name:
CloudThinker Agent - Type: Standard (development) or ACL (production)
- TTL: set an expiration, for example 90 days — Flespi requires all tokens to have a TTL or expiration date
2
Add the connection in CloudThinker
Navigate to Connections → Flespi and enter the token you just generated.Click Connect. CloudThinker verifies the token and shows a Connected status.
Connection details
Required permissions
For a read-only production token, grant the ACL read (GET) permission on the device, channel, stream, and calculator modules, plus the AI module permission Flespi’s MCP server requires for tool calls. Grant write methods on a module only if you want the agent to create or update those entities.
Flespi requires every token to expire. For long-running integrations, use an inactivity TTL (for example 90 days) — the timer resets on every API call, so an active token does not expire unexpectedly.
ACL tokens deny everything by default. Only explicitly granted permissions are allowed — a token granted write on devices does not have read unless read is also granted.
Agent capabilities
Once connected, agents can:
Some of Flespi’s AI-assisted lookups — searching Flespi and device-manufacturer documentation, generating Flespi expressions — consume Flespi’s monthly AI credits on your account. Plain device, channel, and stream operations do not. See Flespi’s pricing page for current credit allowances and rates, and monitor usage from the AI tile in the Flespi panel.
Verify the connection
Example prompts
Troubleshooting
Invalid or expired access token
Invalid or expired access token
The token may have expired — check TTL and expiration settings in the Flespi panel. Expired tokens are automatically deleted by Flespi, so create a new token and update the connection.
Action is not permitted by ACL
Action is not permitted by ACL
Your ACL token lacks the required module and method combination. Update the token ACL to grant the needed permission — ACL is deny-all by default, so each permission must be explicitly granted.
AI-assisted tools are refused
AI-assisted tools are refused
Your account’s monthly Flespi AI credits are exhausted. On the free plan, wait for the next month; on a commercial plan, check your overage settings in the Flespi panel. Device, channel, and stream operations keep working.
HTTP 429 rate limit
HTTP 429 rate limit
Flespi calculates combined API, MQTT, and traffic usage per minute. Reduce request frequency or batch operations. The highest-usage token gets blocked first; other tokens continue working.
Security
- Least privilege — grant only the permissions the agents need for your use case; start read-only and widen later.
- Read-only by default — use read-only credentials unless you want agents to make changes through this connection.
- Rotate credentials — rotate keys and tokens on your normal schedule; CloudThinker picks up the new value when you update the connection.
- Revoke on offboarding — remove the credential at the provider when you delete a connection or a teammate leaves.
- Dedicated token — create a separate token for CloudThinker; never share it across integrations or use a Master token
- ACL for production — use ACL tokens with only the minimum required permissions; ACL tokens are deny-all by default
Related
MCP Connection
Custom MCP integrations
Kubernetes Connection
Container orchestration for IoT workloads