Model or dataset
crisng95/flowkit avatar
crisng95/flowkit

flowkit: three Veo modes are unported and one of them has no fallback

AI agent can create video content better than you. No reason why you do it manually in google flow!

926 stars485 forksPythonMIT

At a glance

What is it?
A video generation pipeline for Google Flow that runs its RPCs through a Chrome extension, because that is the only place they can be signed. The September 2026 move to flow.google.com retired the token the old REST transport depended on, the project now needs you to supply your own project id, and three Veo capabilities are deliberately left unported with a named error instead of a wrong result.
Who is it for?
Read the service terms of the account you are automating before anything else, because this project's approach is to sign its requests through a live browser session rather than through a documented API, and that choice belongs to the operator of the account, not to the tool.
Can I use it commercially?
Yes. MIT is a permissive licence: you can use, modify and sell software built on it, as long as you keep its copyright and licence notices.
Is it still maintained?
Yes. The repository last received commits 1 day ago.
What is it written in?
Mainly Python, according to GitHub's language statistics.

Answers come from the project's GitHub data, last synced on October 4, 2026, and from our analysis. They are not legal advice.

Editorial analysis

A signed-in browser tab is the only place the requests can be signed

The architecture has three parts and the middle one is a Chrome extension.

A Python agent built on FastAPI with a SQLite store exposes a REST API on port 8100. It connects over a WebSocket to an MV3 service worker in the extension, and sends what the diagram calls envelopes. The extension then mints reCAPTCHA and runs Flow's `batchexecute` RPCs inside a tab where someone is signed in to `flow.google.com`. The page is explicit that this is the only place the calls can be signed.

That single design decision explains most of what follows. There is no service account, no API key, and no headless path in the documented setup; a signed-in tab is part of the runtime, and so is the extension's willingness to keep doing what the previous version did. The communication channel is a local WebSocket, which is also why the release history includes an entry about a detected extension hijack, since anything that can talk to that port can ask the extension to mint tokens and issue requests.

The upside is that a consumer video tool with no public API becomes scriptable without reverse-engineering a signing algorithm. The cost is that the whole pipeline now has a browser in its critical path.

The September 2026 move retired the token the old transport needed

The top of the page is a migration notice, and it explains what changed on the vendor's side.

Flow moved to `flow.google.com` in September 2026 and stopped minting the `Bearer ya29.…` token that the old `aisandbox-pa.googleapis.com` REST API depended on. The `batchexecute` transport that replaced it is in place and, the page says, verified end to end against the live API, with image generation, 2K image export and image-to-video all running.

The upgrade path has two steps and one of them is a loss of convenience. Reload the extension, and the page gives a minimum version, v0.3.2 or newer. Then pin `FLOW_PROJECT_ID`, because Flow Kit can no longer create the project for you. A tool that used to provision its own project id now requires you to supply it, which is the kind of change that silently breaks an unattended run.

Everything Omni 1.1 Flash supports is described as ported and live-verified: text-to-video, first frame, first plus last frame, and references. So the migration is complete on one model family and partial on another, which is the situation the next section is about.

Three Veo capabilities fail loudly instead of producing the wrong shot

The unported list is specific and the reason is specific too. Three capabilities were left out of the Veo path because their payloads were never captured off the new UI: video upscale, Veo reference-to-video, and Veo start plus end frame chaining.

The failure mode is the interesting decision. Each one raises `UNSUPPORTED_ON_BATCH_API` rather than returning something approximate, and the page frames that as the point, the opposite of quietly producing the wrong thing.

Two of the three have documented workarounds. For Veo reference-to-video and Veo start plus end frame chaining, Omni covers the same shot by setting `model_family=omni_flash`, or `FLOW_ALLOW_DEGRADED=1` drops the request to plain image-to-video. Video upscale has no fallback at all, so an upscale request on that path is simply not available.

Restoring a capability properly means capturing its payload from the current interface, and the page points at `docs/CAPTURE.md` for that. Naming the missing three, naming the error, and naming the degraded paths is more useful to a caller than a feature list would be, and it is the section of this page worth reading twice.

The badges point at a different repository and the extension has its own version line

Two version numbers in this project do not agree with the one in the release list, and the header links point somewhere else entirely.

The repository is `crisng95/flowkit` and the newest tags are v1.2.1 on 2026-09-25, described as a fix for a detected extension hijack, v1.2.0 on 2026-09-17, the Flow migration, and v1.1.0 on 2026-05-09. But the setup script's own documentation refers to v1.3.1 as the version in which the Gemini CLI target was removed, which is a version with no release behind it. And the extension has a separate line entirely, since the migration notice says to reload at v0.3.2 or newer.

Meanwhile the header links, the stars link, the issues link, the deepwiki link and a pointer to a CLAUDE.md all resolve to `tuannguyenhoangit-droid/google-flow-agent`, a different repository name than the one this project lives in. Whether that is a rename, a fork, or a leftover from a move is not stated.

For a user the practical effect is that the version a bug report should mention is ambiguous. The agent, the extension and the setup script all carry numbers, one of the numbers is ahead of the published tags, and the badge you would click to file an issue goes to a different project.

The review provider is swappable at runtime, including the agent itself

The video review step is where the project meets another agent, and it treats the choice as runtime configuration.

The 36 skills under `skills/` are plain markdown recipes named `fk-*.md`, and the setup script calls that directory the single source of truth. The provider behind the review step is swappable without a restart, through `agent/providers.json` or the `/fk-change-provider` command, and the dashboard can do it as well.

The table of agents lists four integrations with different mechanisms. One agent reads the skill files natively and has vision over files and contact sheets. Claude Code auto-loads through `CLAUDE.md` and exposes native slash commands. Codex CLI is pointed at the skills through `AGENTS.md`. The Antigravity CLI reads the skill files manually.

The review column is the interesting half, because one option is the agent reviewing itself. That entry is described as an official opt-in self-review with no CLI, no model and no API key, with score sheets filled in by hand through a `review-sheets` step followed by `review-submit`. The other options are a Claude-based default role, Codex, and Antigravity.

A hand-scored sheet in the middle of an automated pipeline is an honest acknowledgment that video review is not yet automatable, and making it a first-class provider rather than a fallback is unusual design.

The setup script documents a failed integration in detail

The setup script is a configuration generator with a long paragraph explaining a target it removed, and that paragraph is the most technical text on the page.

Running it with no arguments is interactive, and it takes a tool name for Claude Code or Codex, a value for all tools, plus `sync` to re-sync previously selected tools and `clean` to remove generated configs. State lives in a `.fk-setup.json` file at the root, and the generated output is per-project command files.

The removed target was the Gemini CLI, dropped in v1.3.1, and the reason is a negative result rather than an opinion. Verified against version 1.2.7 of the replacement, Antigravity does not expand a project's `.gemini/commands/*.toml`, does not expand `.claude/commands/*.md` either, and none of `GEMINI.md`, `AGENTS.md` or `CLAUDE.md` appear in the context of a print-mode run, even inside a trusted folder. Its own commands arrive through a plugin system that imports extensions rather than command files.

The script still cleans up after the old target, and the comment says why: so an install from before v1.3.1 does not keep stale command files for a CLI that no longer exists. That is the kind of migration note that saves someone an afternoon, and it is also a useful warning about which agent file formats are actually read.

Nine pipeline stages, one optional one

The production path is a single chain, and the front page spells out every stage.

Story, then entities, then reference images, then scene images, then 8-second video clips, then narration through text to speech, then concatenation, then thumbnails, then upload to YouTube. Everything is described as orchestrated through the API or through the agent skills.

The output table explains what each stage is for. Reference images are one per character, location or prop and exist to hold visual consistency. Scene images compose all the referenced entities. The clips are generated from scene images with camera motion and sound effects. Narration is voice-cloned per scene, and the final video is the concatenated clips trimmed to the narrator's timing. Thumbnails get text overlays and branding, and the upload step carries a search-optimized title, description, tags and hashtags.

Two details stand out. The 4K upscale is the only optional stage, which is a sensible place to put the cost. And the reference image system is what makes the published examples work, since the front page shows one character holding the same face, glasses and coat across four scenes, and another across intensive care, a hospital, an interview and city streets, all from a single 50-scene project.

The extension dashboard, meanwhile, shows a request counter reading 614 total and 328 successful, which is a development snapshot rather than a claim about steady-state reliability, but it is the number the project chose to publish.

Editorial conclusion

Read the service terms of the account you are automating before anything else, because this project's approach is to sign its requests through a live browser session rather than through a documented API, and that choice belongs to the operator of the account, not to the tool. With that settled, flowkit is a substantial piece of work for anyone producing multi-scene AI video: a reference-image system for character consistency, a nine-stage pipeline ending in upload, four coding agents wired to the same 36 markdown skills, and an unusually honest record of what it cannot do. Three things to check. The bridge is a browser extension, so a mismatched extension version breaks the pipeline silently until a call fails, and the page names the minimum version to reload. Three Veo capabilities are unported, two of which have a documented degraded path and one, video upscale, has none. And the repository's own release history shows a fix for a detected extension hijack, which is worth reading before pointing the local agent at a signed-in Google session.

Frequently asked questions

How does flowkit talk to Google Flow?

Through a Chrome extension acting as a browser bridge. A Python agent on FastAPI with SQLite exposes a REST API and talks to the extension's MV3 service worker over a WebSocket on localhost:9222, and the extension mints reCAPTCHA and runs Flow's batchexecute RPCs inside a signed-in flow.google.com tab, which the page calls the only place they can be signed.

Why does flowkit need my own FLOW_PROJECT_ID?

Flow moved to flow.google.com in September 2026 and stopped minting the Bearer ya29 token the old aisandbox-pa.googleapis.com REST API needed, so the batchexecute transport replaced it. When upgrading, reload the extension at v0.3.2 or newer and pin FLOW_PROJECT_ID, because Flow Kit can no longer create the project for you.

Which video modes does flowkit not support?

On the Veo path, video upscale, Veo reference-to-video and Veo start plus end frame chaining are unported, because their payloads were never captured off the new UI. Each fails with UNSUPPORTED_ON_BATCH_API. Omni can cover the latter two with model_family=omni_flash, or FLOW_ALLOW_DEGRADED=1 drops them to plain image-to-video, while video upscale has no fallback.

How do I change the video review provider in flowkit?

At runtime, with no restart, by editing agent/providers.json or using the /fk-change-provider command; the dashboard can do the same. The options are muse, the agent itself, which hand-scores sheets through review-sheets then review-submit with no CLI, model or API key, plus claude as the default video_review role, codex, and agy.

What does the flowkit pipeline produce end to end?

Story, entities, reference images, scene images, 8-second clips, narrator text to speech, concatenation, thumbnails and a YouTube upload, with an optional 4K upscale. Outputs are one reference image per character, location or prop, scene images composed from them, voice-cloned narration per scene, a final video trimmed to the narrator timing, branded thumbnails, and search-optimized metadata.

Official sources

  1. crisng95/flowkit on GitHub
  2. Issues
  3. License: MIT
  4. README
  5. Releases
Add this badge to your README

If you maintain this project, the badge below links readers to this analysis and shows its maintenance status from the daily GitHub snapshot. Paste the markdown into your README; add ?metric=license or ?metric=stars to the image URL for a different field.

Add this badge to your README

markdown
[![Hysen Labs](https://hysenlabs.com/badge/crisng95-flowkit.svg)](https://hysenlabs.com/projects/crisng95-flowkit)