Connection
- Authentication: API key (API secret key).
Scaleway console → top-right drop-down menu → IAM & API keys. Best practice: create an IAM application and a policy granting only the permission sets you need — InstancesReadOnly (lets the connection check the key; lists and reads), InstancesServerStart and InstancesServerStop (power on / off) or InstancesFullAccess (also reboot), ProjectReadOnly (projects), DomainsDNSReadOnly or DomainsDNSFullAccess (read or add DNS records), ContainersReadOnly (Serverless Containers), FunctionsReadOnly (Serverless Functions), BillingReadOnly (consumption). Then open the API keys tab → + Generate API key, choose that application as the bearer, and click Generate API key. Paste the Secret Key (shown only once), not the Access Key.See Scaleway’s documentation.
Read actions (18)
| Action | Description |
|---|---|
get_consumption | Get the monthly consumption, per product (value as a money amount, product_name, resource_name, sku, category_name, project_id, project_name, billed_quantity, unit), with total_discount_untaxed_value and updated_at. Optional: billing_period (“YYYY-MM”; current period when omitted), category_name (string as shown on the invoice, e.g. “Compute”, “Network”), order_by (updated_at_desc, updated_at_asc, category_name_desc, category_name_asc), page (integer ≥ 1), page_size (integer 1-100). Requires BillingReadOnly. |
get_container | Get one Serverless Container (status, error_message, image, command, args, port, scaling, probes, limits, public_endpoint, privacy). Environment variables and secrets are removed. Required: container_id (uuid, see list_containers). Optional: region (fr-par, nl-ams, pl-waw, it-mil; default fr-par). |
get_function | Get one Serverless Function (status, error_message, build_message, runtime, handler, scaling, limits, domain_name, privacy, ready_at). Environment variables and secrets are removed. Required: function_id (uuid, see list_functions). Optional: region (fr-par, nl-ams, pl-waw; default fr-par). |
get_project | Get a Project (id, name, organization_id, description, created_at, updated_at). Required: project_id (uuid, from list_projects or the “project” field of a server). |
get_server | Get an Instance (state, state_detail, commercial_type, image, volumes, public_ips, private_nics, security_group, allowed_actions, maintenances). Required: server_id (uuid, from list_servers). Optional: zone (one of fr-par-1, fr-par-2, fr-par-3, nl-ams-1, nl-ams-2, nl-ams-3, pl-waw-1, pl-waw-2, pl-waw-3, it-mil-1; default fr-par-1) — must be the zone of the Instance. |
list_container_namespaces | List Serverless Containers namespaces (id, name, status, error_message, project_id, tags, created_at). Environment variables and secrets are removed. Optional: region (fr-par, nl-ams, pl-waw, it-mil; default fr-par), project_id (uuid), organization_id (uuid), name (string), order_by (created_at_asc, created_at_desc, name_asc, name_desc), page (integer ≥ 1), page_size (integer 1-100). Requires ContainersReadOnly. |
list_containers | List Serverless Containers (id, name, namespace_id, status, error_message, image, port, protocol, privacy, min_scale / max_scale, CPU and memory limits, public_endpoint, created_at). Environment variables and secrets are removed. Optional: region (fr-par, nl-ams, pl-waw, it-mil; default fr-par), namespace_id (uuid, see list_container_namespaces), project_id (uuid), organization_id (uuid), name (string), order_by (created_at_asc, created_at_desc, name_asc, name_desc), page (integer ≥ 1), page_size (integer 1-100). Requires ContainersReadOnly. |
list_dns_records | List the records of a DNS zone (id, name, type, data, ttl, priority). Required: dns_zone (string, the zone name from list_dns_zones: its domain when subdomain is empty, otherwise subdomain + ”.” + domain, e.g. “example.com” or “sub.example.com”); name (string; a record name to filter on, or "" for every record — the API requires the parameter). Optional: type (A, AAAA, ALIAS, CAA, CNAME, MX, NS, PTR, SRV, TXT, TLSA, LOC, SSHFP, HINFO, RP, URI, DS, NAPTR, DNAME, SVCB, HTTPS), id (record id), order_by (name_asc, name_desc), page (integer ≥ 1), page_size (integer 1-100). |
list_dns_zones | List DNS zones (domain, subdomain, ns, status, project_id, updated_at). Required: domain (string; a domain such as “example.com” to list its zones, or "" for every zone — the API requires the parameter). Optional: project_id (uuid), organization_id (uuid), order_by (domain_asc, domain_desc, subdomain_asc, subdomain_desc, created_at_asc, created_at_desc, updated_at_asc, updated_at_desc), page (integer ≥ 1), page_size (integer 1-100). |
list_flexible_ips | List the flexible IPs of a zone (id, address, reverse, server, type, state, project). Optional: zone (one of fr-par-1, fr-par-2, fr-par-3, nl-ams-1, nl-ams-2, nl-ams-3, pl-waw-1, pl-waw-2, pl-waw-3, it-mil-1; default fr-par-1), project (uuid), organization (uuid), name (string), tags (comma-separated exact tags), type (routed_ipv4 or routed_ipv6), per_page (integer 1-100), page (integer ≥ 1). |
list_function_namespaces | List Serverless Functions namespaces (id, name, status, error_message, project_id, registry_endpoint, tags, created_at). Environment variables and secrets are removed. Optional: region (fr-par, nl-ams, pl-waw; default fr-par), project_id (uuid), organization_id (uuid), name (string), order_by (created_at_asc, created_at_desc, name_asc, name_desc), page (integer ≥ 1), page_size (integer 1-100). Requires FunctionsReadOnly. |
list_functions | List the Serverless Functions of a namespace (id, name, status, error_message, runtime, handler, privacy, min_scale / max_scale, memory_limit, timeout, domain_name, created_at). Environment variables and secrets are removed. Required: namespace_id (uuid, see list_function_namespaces). Optional: region (fr-par, nl-ams, pl-waw; default fr-par), project_id (uuid), organization_id (uuid), name (string), order_by (created_at_asc, created_at_desc, name_asc, name_desc), page (integer ≥ 1), page_size (integer 1-100). Requires FunctionsReadOnly. |
list_projects | List the Projects of an Organization (id, name, organization_id, description, created_at). Required: organization_id (uuid; the “organization” field of any server or volume from list_servers / list_volumes). Optional: name (string), order_by (created_at_asc, created_at_desc, name_asc, name_desc), page (integer ≥ 1), page_size (integer 1-100). |
list_security_groups | List the security groups of a zone (id, name, description, inbound_default_policy, outbound_default_policy, stateful, servers, project_default). Optional: zone (one of fr-par-1, fr-par-2, fr-par-3, nl-ams-1, nl-ams-2, nl-ams-3, pl-waw-1, pl-waw-2, pl-waw-3, it-mil-1; default fr-par-1), name (string), project (uuid), organization (uuid), tags (comma-separated exact tags), project_default (boolean), per_page (integer 1-100), page (integer ≥ 1). |
list_server_actions | List the actions an Instance currently allows (e.g. poweron, poweroff, reboot) — check before power_on_server / power_off_server / reboot_server. Required: server_id (uuid, from list_servers). Optional: zone (one of fr-par-1, fr-par-2, fr-par-3, nl-ams-1, nl-ams-2, nl-ams-3, pl-waw-1, pl-waw-2, pl-waw-3, it-mil-1; default fr-par-1). |
list_servers | List the Instances of a zone (id, name, state, commercial_type, public_ips, private_ip, volumes, project, organization, tags). Optional: zone (one of fr-par-1, fr-par-2, fr-par-3, nl-ams-1, nl-ams-2, nl-ams-3, pl-waw-1, pl-waw-2, pl-waw-3, it-mil-1; default fr-par-1), project (uuid), organization (uuid), name (substring), state (running, stopped, stopped in place, starting, stopping, locked), commercial_type (e.g. “DEV1-S”), tags (comma-separated exact tags), order (creation_date_desc, creation_date_asc, modification_date_desc, modification_date_asc), per_page (integer 1-100), page (integer ≥ 1). |
list_snapshots | List the Instance snapshots of a zone (id, name, size, volume_type, state, base_volume, creation_date). Optional: zone (one of fr-par-1, fr-par-2, fr-par-3, nl-ams-1, nl-ams-2, nl-ams-3, pl-waw-1, pl-waw-2, pl-waw-3, it-mil-1; default fr-par-1), project (uuid), organization (uuid), name (substring), tags (comma-separated exact tags), base_volume_id (uuid, from list_volumes), per_page (integer 1-100), page (integer ≥ 1). |
list_volumes | List the Instance volumes of a zone (id, name, size, volume_type, state, server, project, organization). Optional: zone (one of fr-par-1, fr-par-2, fr-par-3, nl-ams-1, nl-ams-2, nl-ams-3, pl-waw-1, pl-waw-2, pl-waw-3, it-mil-1; default fr-par-1), volume_type (l_ssd, scratch, sbs_volume, sbs_snapshot), project (uuid), organization (uuid), name (substring), tags (comma-separated exact tags), per_page (integer 1-100), page (integer ≥ 1). |
Write actions (4)
| Action | Description |
|---|---|
add_dns_record | Add one record to an existing DNS zone; answers the added record(s). Arguments: dns_zone (string, path, the zone name from list_dns_zones: its domain when subdomain is empty, otherwise subdomain + ”.” + domain, e.g. “example.com”); name (string, relative to the zone, "" for the apex, e.g. “www”); type (string: A, AAAA, ALIAS, CAA, CNAME, MX, NS, PTR, SRV or TXT); data (string, the record value as Scaleway writes it: IPv4 for A, IPv6 for AAAA, target host for CNAME / ALIAS / NS / PTR, text for TXT, “10 mx.example.net.” for MX, “20 443 sip.example.com.” for SRV, “0 issue ca.example.com” for CAA — priorities and parameters go inside data); ttl (integer, seconds). Sent as {“changes”: [{“add”: {“records”: [{name, type, data, ttl}]}}], “disallow_new_zone_creation”: true}: a name that does not belong to an existing zone is refused rather than creating a sub-zone. Requires DomainsDNSFullAccess. |
power_off_server | Power off an Instance (fully stops it and releases its hypervisor slot); answers a task (id, status, progress). Arguments: server_id (string uuid, path, from list_servers); zone (string, path, optional: fr-par-1, fr-par-2, fr-par-3, nl-ams-1, nl-ams-2, nl-ams-3, pl-waw-1, pl-waw-2, pl-waw-3, it-mil-1; default fr-par-1, must be the zone of the Instance). Nothing else is sent: the body is fixed to {“action”: “poweroff”}. Requires InstancesServerStop or InstancesFullAccess. |
power_on_server | Power on a stopped Instance; answers a task (id, status, progress). Arguments: server_id (string uuid, path, from list_servers); zone (string, path, optional: fr-par-1, fr-par-2, fr-par-3, nl-ams-1, nl-ams-2, nl-ams-3, pl-waw-1, pl-waw-2, pl-waw-3, it-mil-1; default fr-par-1, must be the zone of the Instance). Nothing else is sent: the body is fixed to {“action”: “poweron”}. Requires InstancesServerStart or InstancesFullAccess. |
reboot_server | Reboot a running Instance; answers a task (id, status, progress). Arguments: server_id (string uuid, path, from list_servers); zone (string, path, optional: fr-par-1, fr-par-2, fr-par-3, nl-ams-1, nl-ams-2, nl-ams-3, pl-waw-1, pl-waw-2, pl-waw-3, it-mil-1; default fr-par-1, must be the zone of the Instance). Nothing else is sent: the body is fixed to {“action”: “reboot”}. Requires InstancesFullAccess. |
Permissions
Every action above must be explicitly granted to an agent before it can be used. See Permissions for the grant model and Security for how credentials are protected.Last reviewed against the provider API: September 2026.