Connect your clouds
Connect DigitalOcean
Connect a DigitalOcean team with a Personal Access Token for resource and cost scans.
About 5 minutes
DigitalOcean has no keyless connection option. You give Zaysa a DigitalOcean Personal Access Token, which Zaysa stores encrypted. The connected account card shows Key-based. For scanning and costs, create a Read Only token with an expiry.
Before you start
- A Zaysa account. New here? Start with Getting started.
- Access to the DigitalOcean control panel for the team you want to connect, so you can create a Personal Access Token.
What Zaysa gets
A Read Only token lets Zaysa scan resources and read history. See the Permissions reference for each feature's token scope and what happens without it.
Choose the token settings
| DigitalOcean field | Value |
|---|---|
| Token name | Zaysa |
| Expiration | Choose 90 days for a token with an expiry. Zaysa warns before it expires. No expiry is also offered. |
| Scopes | Choose Read Only for scans and costs. Choose Full Access only if Autopilot should apply fixes on this account. |
Connect the team
Open the connection window
In Zaysa, open Resources → Cloud Accounts and click Connect account.
Choose DigitalOcean and name the account
(1) Choose DigitalOcean as the Cloud Provider. (2) Name the connection, for example
Production DO.Generate a token in the DigitalOcean control panel
Click Open Generate New Token (1). Set the token name to
Zaysa, choose 90 days and Read Only, then click Generate Token. Copy the token now. DigitalOcean shows it once.Finding the token form
Expand Where is that page? Click path from the control panel home for the control panel clicks.Paste and check the token
Paste the token into API Token (1). The optional check command then contains your token. Copy it into a terminal to check it before connecting. A working token prints:
Terminal✅ Token works — paste it into ZaysaA rejected token prints:
Terminal❌ Token rejected — generate a new one (step 1)The Spaces access key (optional) fields are needed only if a CI/CD pipeline keeps Terraform state in DigitalOcean Spaces.
Test and connect
Click Test Connection. Zaysa shows Successfully connected to DIGITALOCEAN. Then click Connect Account (1).
Asked to sign in again?
Connecting a cloud account is a sensitive action. If you signed in more than 30 minutes ago, Zaysa asks you to sign in again with your email and password (and your authenticator code, if you use one), then brings you back to Cloud accounts. Open Connect account again, choose DigitalOcean, paste the same token and click Connect Account. DigitalOcean shows a token only once, so if you no longer have it, generate a new one.
Check it worked
Click Check permissions on the card to see which features are ready in this connection; the Check permissions guide explains the results.
The card shows Key-based, Connected (1), the region and the DigitalOcean team.
Run scan on the card takes you to the Cost Optimizer, where you scan the team to see what it costs and where the waste is. The first scan guide walks through it.
If something goes wrong
“Token rejected”
The token may have been mistyped, expired or revoked. Generate a new token and paste it into Zaysa.
Replace an expiring token
Zaysa warns before the token expires. Generate a new token in DigitalOcean. In Zaysa, open FinOps → Optimization, click the ⋮ menu next to the account under Connected cloud accounts and choose Edit account & billing. Paste the new token into API Token and click Save Credentials. Changing the token this way keeps the same account in Zaysa, with its scan history.
Remove access
In DigitalOcean, open API → Tokens and delete the Zaysa token. Then click the bin icon on the account card in Zaysa.