Open Closed

Abp studio Ai security and cost related questions #10757


User avatar
0
tapmui created

Question about https://abp.io/studio/ai-agent#security

  1. can I connect with my org copilot account instead ?
  2. What is code security level with Abp.io base AI ? Is my code shared or used with AI development by abp.io/volo ?
  3. How you guarantee that your AI produced code does not use code solutions that are licensed by others ?
  4. How users can see their token budgets with abp studio AI usage ? Any alerts, what happens when all tokens spent ?

I think this needs to be officially stated by abp.io before any "big business" organization should use the abp studio based Ai features.

Markdown supported.
Copy, paste, or drag & drop images and files (max 100 MB per file, 100 MB total per post)

4 Answer(s)
  • User Avatar
    0
    AI-Bot created
    Support Team ABP Agent
    • (1) Can I connect ABP Studio AI Agent with my organization’s Copilot account instead?
      The official ABP AI Agent page does not document any “bring your own Copilot (GitHub Copilot / Microsoft 365 Copilot)” sign-in/provider option. What it does state is that ABP Studio lets you connect your workspace to multiple LLM providers/models (“Access the World’s Best AI Models… Choose between Claude, GPT, Gemini, or DeepSeek…”) from inside Studio.
      So: No verified source that Copilot-account integration is supported; ABP Studio AI is positioned around selecting LLM providers/models in Studio settings.

    • (2) What is the code security level with ABP.io base AI? Is my code shared/used to train ABP/Volosoft AI?
      The public “Security” section on the AI Agent page documents workspace-side controls (not a training/data-processing policy):

      • .abpignore to block secrets/certs/env files/private keys from being included as context
      • Permission prompts for shell commands / URL fetches / downloads (requires approval with a reason)
      • Scope isolation (restrict sessions to a named scope like a module/package/folder)
      • Git snapshot revert (rollback per agent turn)
        However, the page does not explicitly state whether your code/prompts are retained, shared, or used for training by Volosoft/ABP or by underlying model providers.
        In ABP Studio docs, ABP notes: “Review the Privacy Notice available in the AI Assistant panel to understand how your data is handled.” That Privacy Notice (inside the product UI) is the authoritative statement, but it is not included in the public sources I can verify here.
    • (3) How do you guarantee AI-produced code does not include others’ licensed code?
      No verified public statement on the ABP AI Agent page (or the ABP Studio overview doc snippet) that provides such a guarantee. In general, LLM-generated output can be similar to existing code; no ABP-verified guarantee is documented in the sources retrieved.

    • (4) Token budgets / alerts / what happens when tokens are spent?
      ABP Studio documentation confirms an organization-level credits system and that usage is tracked and displayed in the interface (“Credits System… usage tracked and displayed in the interface.”).
      The public AI Agent FAQ also states AI credits are purchased per organization via the organization page.
      But alerts / budgeting controls / the exact behavior when credits run out are not specified in the verified sources retrieved.

    • What you should do for an “officially stated” enterprise answer
      Since items (1)–(4) are largely policy/compliance topics and the public page doesn’t fully cover them, the only official channel to request a formal statement (DPA, retention, training, enterprise controls, budget enforcement, etc.) is: https://abp.io/contact.

    Sources (verified)

    • https://abp.io/studio/ai-agent#security
    • https://abp.io/docs/10.4/studio/overview
    • https://abp.io/contact

    This response was generated by AI. If it didn’t solve your problem, feel free to post a new answer — our support team will jump in to help you soon.

    Markdown supported.
    Copy, paste, or drag & drop images and files (max 100 MB per file, 100 MB total per post)
  • User Avatar
    0
    maliming created
    Support Team Fullstack Developer

    Hi,

    Good questions. Here's how the AI Agent actually works under the hood, which covers most of these.

    1) Connecting your own Copilot account / your own key

    Not supported at the moment. The AI Agent runs on AI credits provisioned per organization, and there's no bring-your-own-key or "use my Copilot / OpenAI / Anthropic account" option. The credentials are managed on our side and pushed to Studio at runtime, so you can't swap in your own key.

    2) Is your code shared or used by abp.io / Volosoft?

    The Agent runs locally in ABP Studio. For a normal completion, your prompt and the code context it carries go from Studio straight to the LLM provider that serves the model you selected — it isn't sent to a Volosoft-hosted LLM endpoint. The chat history Studio keeps is stored locally on your machine, per solution.

    How we handle your data is stated in the Privacy Notice in the AI Assistant panel:

    Your chat history is securely stored to enhance your experience within ABP Studio, such as continuing previous conversations or improving support quality. We do not sell, share, or use your chat data for marketing or any other external purposes.

    .abpignore is used to keep sensitive files out of the context — by default it already excludes appsettings.secrets.json, .env*, *.pfx / *.pem / *.key and signing keys. Shell commands, URL fetches and downloads need your explicit approval, and you can scope a session to a single module or folder.

    So your code does reach the LLM provider — that's unavoidable for any AI coding tool — and data handling at the model layer is governed by that provider's policy.

    3) Guaranteeing the generated code doesn't include others' licensed code

    We can't give that guarantee for LLM-generated code — the output can resemble existing code, and it's produced by the model provider, not by ABP. Treat generated code like any third-party snippet and review it before shipping. The commercial model providers have their own copyright / IP terms that apply to their output.

    4) Token budget, alerts, and running out

    Credits are purchased and tracked per organization on your Organization Management page (https://abp.io/my-organizations/). Usage is a direct passthrough of actual model usage — we don't add any markup. Studio doesn't currently expose a separate budget alert or threshold setting; when the balance runs out, AI requests stop with a clear "insufficient credits, please add credits" message until you top up. Nothing else breaks — the AI features just pause.

    If your compliance team needs to go deeper on enterprise terms, data retention or a DPA, feel free to reach out to us at https://abp.io/contact and we can take it from there.

    Thanks

    Markdown supported.
    Copy, paste, or drag & drop images and files (max 100 MB per file, 100 MB total per post)
  • User Avatar
    0
    tapmui created

    Thank you Maliming! This makes it clear. Abp.io studio AI groundings sounds really promizing to me. I needed previous questions answered before starting discussion with my organization. Some points I would love to see in the abp Studio AI:

    1. Suite generation automated with AI
    • I can ask adding a property in entity or similar
    1. Better handling of unit tests and seed data when re-generating an entity
    • it ruins quids very easily causing huge rework with unit tests: why not named guids to be used ?
    1. Coding bad habits with apb suite re-generation
    • it adds namspace duplicates
    • cannot fix extended classes; sometimes you even do not see that an overridden extended class method is not called anymore
    • entitys with strings: a lot of warnings with nullable handling: with large amount of code you may end up 1000> warnings; and marking them as allowed is lost in next regeneration Q: Either fixed in suite or ai to fix those
    Markdown supported.
    Copy, paste, or drag & drop images and files (max 100 MB per file, 100 MB total per post)
  • User Avatar
    0
    maliming created
    Support Team Fullstack Developer

    Hi,

    Glad that cleared it up!

    A couple of these you can already get on top of today, and the rest are fair points I'll pass on to the Suite team.

    Custom code is preserved on regeneration — Suite has a custom-code feature aimed exactly at the "I edited the generated class and lost it on regen" problem. Once you enable custom code support, the code you put inside the custom-code hook points (the suite-custom-code-block-N markers Suite drops into the generated files as comments) and your overrides in the generated .Extended page classes (e.g. OnGetAsync / OnPostAsync) are respected and won't be overwritten on the next generation. Full list of hook points and how to add your own: https://abp.io/docs/latest/suite/customizing-the-generated-code . If an override stops being called after a regen, check that it lives in the .Extended file and that its signature still matches the base — that's usually what's gone stale.

    Nullable warnings on string properties — these come from the entity definition, not the generated file. A string property is generated non-nullable + [NotNull] when it's marked Required, and string? + [CanBeNull] when it isn't. So suppressing the warning in the generated code gets overwritten on regen, but setting Required / nullable correctly per property in the Suite entity designer makes the warning go away and survives regeneration.

    Seed/test GUIDs changing on every regenerate — right, the generated test data and data-seed records use a fresh GUID per run, so hand-tuned tests get churned. The way to avoid the rework today is to not edit the generated DataSeedContributor / generated test files — keep your own seed and test data in separate files Suite doesn't touch. The stable-GUID idea is good feedback — I'll raise it with the team.

    Duplicate namespaces on regenerate — yep, that's a real gap on the generation side, I've noted it for the Suite team.

    "Ask AI to add a property" inside Suite — Suite itself doesn't do AI-driven generation today. The ABP Studio AI Agent is a separate workflow that can edit your project code directly, so that's already doable through the Agent — just not part of the Suite regenerate step.

    Appreciate the detailed write-up — genuinely useful.

    Thanks

    Markdown supported.
    Copy, paste, or drag & drop images and files (max 100 MB per file, 100 MB total per post)
Boost Your Development
ABP Live Training
Packages
See Trainings
Mastering ABP Framework Book
The Official Guide
Mastering
ABP Framework
Learn More
Mastering ABP Framework Book
Made with ❤️ on ABP v10.8.0-preview. Updated on September 28, 2026, 11:44
1
ABP Assistant
🔐 You need to be logged in to use the chatbot. Please log in first.