OnboardingConnect Providers

DigitalOcean

Prerequisites

  • A DigitalOcean team. Connect one team per token.
  • A team role that can see billing and resources, such as Owner. A token only carries the reads its creator's role allows.

Connect

Generate a token in DigitalOcean

Sign in to the DigitalOcean control panel and switch to the team you want to connect. Open API, then Tokens, and click Generate New Token. Name it for LevelFour and choose an expiration.

Under Scopes, choose Read Only. LevelFour can then read your billing and resources, including resource types DigitalOcean adds later, and cannot create, change, or delete anything. Read Only does not include database credentials or Kubernetes cluster credentials.

For spend alone, read on account and billing is enough. Your costs, invoices and tags all arrive on that pair. The resource scopes below are what add the estate: which Droplets, volumes and snapshots you are paying for, and which of them are idle.

Click Generate Token and copy it. It starts with dop_v1_, and DigitalOcean shows it only once.

If your security policy requires the narrowest token, choose Custom Scopes instead and tick read on account, billing, droplet, block_storage, snapshot, database, kubernetes, load_balancer, reserved_ip, app, project, and sizes. DigitalOcean does not let you add scopes to a custom token later, so a new resource type means a new token.
Do not choose Full Access. It lets the token create, change, and delete resources.

Add it to LevelFour

Open Connect Providers, select DigitalOcean, and click Add access token. Paste the token, then click Connect account.

Confirming it worked

The connection moves to Connected. Your first data appears within a day.

If the connection shows Warning with a note about missing scopes, the token could not list some resource types. LevelFour keeps syncing costs. See Rotating the credential to replace the token.

Rotating or removing access

Rotating the credential

Generate a new Read Only token, paste it into Connect Providers, then delete the old token in DigitalOcean. Rotating does not repeat the first import.

Removing access

Disconnect DigitalOcean under Connect Providers, then delete the token under API in the DigitalOcean control panel.

Troubleshooting

SymptomWhat to do
The token is refusedCheck that it is Read Only (or has account:read and billing:read), that it has not expired, and that its creator can see billing. The token stops working if the person who created it leaves the team
The connection shows Warning about missing scopesA custom token lacks a resource scope. Generate a Read Only token and rotate it
Databases are not listedThe token can read database credentials. Generate a Read Only token, or a custom token without database:view_credentials
A daily figure differs from the invoiceDaily figures are DigitalOcean's nightly estimates. The reconciliation line added when the invoice arrives makes the month match the invoice
Spend from another team is missingEach team needs its own token and connection. LevelFour does not read organization-level billing across several teams yet

Next