Skip to main content
DigitalOcean API credentials store a DigitalOcean personal access token, used to provision and manage self-managed DigitalOcean droplet clusters and DigitalOcean Kubernetes (DOKS). The token is validated when you save it - Ankra makes a read-only call to the DigitalOcean API (GET /v2/account), so a rejected or mistyped token is refused immediately.

What Ankra Accesses

One token covers both cluster types. For self-managed droplet clusters, Ankra provisions the infrastructure directly: For DOKS, Ankra uses the managed Kubernetes API instead: For cost reconciliation, Ankra also reads the account’s billing:

Creating a DigitalOcean API Credential

1

Get a DigitalOcean token

  1. Log in to the DigitalOcean Control Panel
  2. Go to API → Tokens → Generate New Token
  3. Give it Read & Write access - with Full Access scopes, or custom scopes covering at least droplet, ssh_key, vpc, firewall, tag, load_balancer, and kubernetes (add regions and sizes read for the wizard’s options, and billing:read so Ankra can import your invoices for cost reconciliation)
  4. Copy the token (prefixed with dop_v1_; shown once)
2

Add to Ankra (UI)

Go to Credentials → Add → DigitalOcean, then provide:
  • Name: a unique identifier - lowercase letters and numbers only, cannot start with a hyphen (e.g. do-prod)
  • API Token: the token from the previous step
Click Test connection to verify the token against the DigitalOcean API, then save.
3

Or via CLI

For self-managed droplet clusters you also need an SSH key credential - create one with ankra credentials digitalocean ssh-key create --name my-key --generate.
The token can be rotated later from the credential’s page without recreating the credential - everything using it picks up the new token automatically.

Listing DigitalOcean Credentials

Troubleshooting DigitalOcean Credentials

The table below covers the Test connection result in the Ankra UI: If cost reconciliation shows the DigitalOcean credential as no billing access, the token lacks the billing:read scope: DigitalOcean refused to list its invoices, so what it billed is shown as unknown, never as zero. Add the scope to a new token and rotate it in; the next import (every six hours) reads the invoices. Test connection verifies the token is accepted, not that it has every scope. If the credential saves fine but provisioning later fails with a permissions error, the token is read-only or missing a scope from the lists above - generate a token with the right scopes and rotate it in on the credential’s page.