Connect your clouds

Connect DigitalOcean

Connect a DigitalOcean team with a Personal Access Token for resource and cost scans.

About 5 minutes

DigitalOcean has no keyless connection option. You give Zaysa a DigitalOcean Personal Access Token, which Zaysa stores encrypted. The connected account card shows Key-based. For scanning and costs, create a Read Only token with an expiry.

Before you start

  • A Zaysa account. New here? Start with Getting started.
  • Access to the DigitalOcean control panel for the team you want to connect, so you can create a Personal Access Token.

What Zaysa gets

A Read Only token lets Zaysa scan resources and read history. See the Permissions reference for each feature's token scope and what happens without it.

Choose the token settings

DigitalOcean fieldValue
Token nameZaysa
ExpirationChoose 90 days for a token with an expiry. Zaysa warns before it expires. No expiry is also offered.
ScopesChoose Read Only for scans and costs. Choose Full Access only if Autopilot should apply fixes on this account.

Connect the team

  1. Open the connection window

    In Zaysa, open Resources → Cloud Accounts and click Connect account.

  2. Choose DigitalOcean and name the account

    (1) Choose DigitalOcean as the Cloud Provider. (2) Name the connection, for example Production DO.

  3. Generate a token in the DigitalOcean control panel

    Click Open Generate New Token (1). Set the token name to Zaysa, choose 90 days and Read Only, then click Generate Token. Copy the token now. DigitalOcean shows it once.

    Finding the token form

    Expand Where is that page? Click path from the control panel home for the control panel clicks.
  4. Paste and check the token

    Paste the token into API Token (1). The optional check command then contains your token. Copy it into a terminal to check it before connecting. A working token prints:

    Terminal
    ✅ Token works — paste it into Zaysa

    A rejected token prints:

    Terminal
    ❌ Token rejected — generate a new one (step 1)

    The Spaces access key (optional) fields are needed only if a CI/CD pipeline keeps Terraform state in DigitalOcean Spaces.

  5. Test and connect

    Click Test Connection. Zaysa shows Successfully connected to DIGITALOCEAN. Then click Connect Account (1).

    Asked to sign in again?

    Connecting a cloud account is a sensitive action. If you signed in more than 30 minutes ago, Zaysa asks you to sign in again with your email and password (and your authenticator code, if you use one), then brings you back to Cloud accounts. Open Connect account again, choose DigitalOcean, paste the same token and click Connect Account. DigitalOcean shows a token only once, so if you no longer have it, generate a new one.

Check it worked

Click Check permissions on the card to see which features are ready in this connection; the Check permissions guide explains the results.

The card shows Key-based, Connected (1), the region and the DigitalOcean team.

Run scan on the card takes you to the Cost Optimizer, where you scan the team to see what it costs and where the waste is. The first scan guide walks through it.

If something goes wrong

“Token rejected”

The token may have been mistyped, expired or revoked. Generate a new token and paste it into Zaysa.

Replace an expiring token

Zaysa warns before the token expires. Generate a new token in DigitalOcean. In Zaysa, open FinOps → Optimization, click the ⋮ menu next to the account under Connected cloud accounts and choose Edit account & billing. Paste the new token into API Token and click Save Credentials. Changing the token this way keeps the same account in Zaysa, with its scan history.

Remove access

In DigitalOcean, open API → Tokens and delete the Zaysa token. Then click the bin icon on the account card in Zaysa.

Next steps