Skip to main content
Let your agents watch and operate your DigitalOcean infrastructure — browse Droplets, reboot, shut down or power them on, read App Platform apps and deployments, trigger a redeploy, check app health, read managed database clusters and their events, manage DNS records, list projects and read the account balance.

Connection

  • Authentication: API key (DigitalOcean personal access token).
Log in to the DigitalOcean Control Panel → Account → API → Tokens tab → Personal access tokens → Generate New Token. Name it, pick an expiration, then under Scopes choose “Custom Scopes” and tick only what you need: account:read (lets the connection check the token), droplet:read, droplet:update (reboot, shut down, power on), app:read, app:update (trigger a deployment), database:read, domain:read, domain:create (create DNS records), project:read, billing:read (balance), and tag:read if you filter Droplets by tag. Click Generate Token and copy it — it is shown only once. “Read Only” also works for reads; avoid “Full Access”.See DigitalOcean’s documentation.

Read actions (17)

Write actions (5)

Permissions

Every action above must be explicitly granted to an agent before it can be used. See Permissions for the grant model and Security for how credentials are protected.
Last reviewed against the provider API: September 2026.