Flower Labs
company · GermanyScores
1 product on the map — 1 open.
Openness
4 high confidence- license
- Apache-2.0(OSI
- source
- public(the framework, simulation engine and deployment runtime)
- core features withheld
- yes — OIDC account authentication, audit logging and the Helm charts are documented as Flower Enterprise features, and the SuperLink reports license-missing and license-invalid errors
Flower's framework and deployment runtime are Apache-2.0, but Flower Labs reserves part of the production operating layer for a paid tier: its own documentation marks OIDC login, audit logging and the Helm charts as Flower Enterprise features. That is open core, not a separate product sold beside a complete one.
- https://flower.ai/docs/framework/helm/index.html recorded 2026-09-27
"Flower Helm charts are a Flower Enterprise feature. See Flower Enterprise for details."
- https://flower.ai/docs/framework/how-to-authenticate-accounts.html recorded 2026-09-27
"OpenID Connect Authentication is a Flower Enterprise feature. See Flower Enterprise for details." The same page lists SUPERLINK_LICENSE_INVALID, SUPERLINK_LICENSE_MISSING and SUPERLINK_LICENSE_URL_INVALID exit codes.
- https://flower.ai/docs/framework/how-to-configure-audit-logging.html recorded 2026-09-27
"Audit logging is a Flower Enterprise feature. See Flower Enterprise for details."
- https://raw.githubusercontent.com/flwrlabs/flower/HEAD/LICENSE recorded 2026-09-27
The LICENSE body: the verbatim Apache License, Version 2.0 text with no added clause.
- https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/flwrlabs%2Fflower recorded 2026-09-27
Repository record for flwrlabs/flower: license apache-2.0, not archived, not a fork, pushed 2026-09-21, 7,140 stars.
Adoption
2 medium confidencePyPI downloads of `flwr`, which carries the simulation engine, the SuperLink and the SuperNode alike, so they count the product itself. Flower draws about two thirds of the monthly PyPI installs across this category.
- https://pypi.org/pypi/flwr/json recorded 2026-09-27
PyPI `flwr` 1.38.0, uploaded 2026-09-22, license Apache-2.0, repository https://github.com/flwrlabs/flower.
- https://pypistats.org/api/packages/flwr/recent recorded 2026-09-27
last_month = 74,715 downloads for the package `flwr`.
Capability
4 high confidenceFlower runs real cross-organization federations, with authenticated SuperNodes, encrypted connections and secure aggregation in the open framework. It stops short of NVIDIA FLARE because its Android SDK does not work with current releases, its Slurm path runs through the hosted SuperGrid, and it publishes no multi-billion-parameter training figures.
- https://flower.ai/docs/framework/explanation-ref-secure-aggregation-protocols.html recorded 2026-09-27
"Flower now provides the SecAgg and SecAgg+ protocols" to aggregate model updates without the server inspecting individual ones.
- https://flower.ai/docs/framework/how-to-authenticate-supernodes.html recorded 2026-09-27
Two mechanisms to authenticate SuperNodes connecting to a SuperLink: automatic timestamp-signature checks, and CLI-managed authentication behind --enable-supernode-auth.
- https://flower.ai/docs/framework/how-to-deploy-supernode-using-slurm.html recorded 2026-09-27
Deploying a SuperNode as a Slurm job: "Each example connects a SuperNode to SuperGrid", after registering its key pair in SuperGrid.
- https://flower.ai/docs/framework/how-to-enable-tls-connections.html recorded 2026-09-27
TLS for SuperLink to SuperNode and user to SuperLink connections, replacing --insecure.
- https://flower.ai/docs/framework/how-to-use-differential-privacy.html recorded 2026-09-27
Central and local differential privacy; "Differential Privacy in Flower is in a preview phase."
- https://flower.ai/docs/framework/tutorial-quickstart-android.html recorded 2026-09-27
"The experimental Flower Android SDK is not compatible with the latest version of Flower. Android support is currently being reworked"; the quickstart is "kept for historical purposes".