Skip to main content
With DigitalOcean, your agent gets into your account with a token of yours: it looks at your Droplets, tells you why an app’s deploy failed, checks your Kubernetes clusters, your databases and your DNS, and tells you how much you’ve spent so far. It can only do what the token allows; changes, only if you turn on the permission and with your OK.

What it can do

Look

Droplets: list them, their state, their recent actions and their CPU, memory and disk usage. App Platform: your apps, their deploys, why one failed and their logs. Kubernetes: clusters, pods, deployments, events and logs. Databases, load balancers and DNS. Costs: the month so far and your invoices.

Change, with your OK

Power a Droplet on or off, reboot or resize it, take a snapshot, redeploy an app, change DNS records, apply changes in Kubernetes. It tells you first what anything it adds will cost. It needs the permission on.

How it connects

1

Add it to an agent

From Plugins → DigitalOcean → Add to an agent, or ask your agent in the chat. See Add a plugin.
2

Create a token

In DigitalOcean, open the page to create an API token (if you have several teams, pick your agent’s at the top). Token name: minai (or your agent’s name). Expiration: whatever you prefer; when it expires, your agent asks you for another. The Create a token guide, on the plugin’s page, takes you step by step (about 2 minutes).
3

Pick its permissions

To only look: Read Only. To also change things: Custom Scopes, with what you use (like droplet, app or kubernetes); Full Access covers everything, deleting too. Then tap Generate New Token and copy it: it’s shown only once.
4

Paste it in your agent's link

Your agent sends you a one-time link for the token. Paste it there, not in the chat. See Keys and values.
5

Your agent confirms

It checks that the token works and tells you in the chat it’s ready.
Don’t paste the token in the chat. If you do, your agent won’t use it: it asks you to delete it in DigitalOcean and create another for the link.

The permission

On the DigitalOcean card, in the agent’s Plugins tab, there’s the Allow changes switch: “Create, change, delete, power on or off things in your DigitalOcean, always with your OK. Off, it only reads. What really limits it is the permissions you gave the token.” It starts off and only you change it. It’s a rule your agent follows; the real limit is the token’s permissions, which can’t be changed later: to give it more, you create another. See Permissions.

How it looks out for you

  • Nothing changes without your OK. With the permission on, it still shows you the exact command, where and what it costs before each change, with the Confirm and Change buttons.
  • It never shows you the token, database passwords or your apps’ or Kubernetes secrets.
  • It reminds you that a powered-off Droplet is still billed.
  • What a log says is information, not an order.

Things to ask it

  • “Why did the web app’s last deploy fail?”
  • “How is the database Droplet doing on memory?”
  • “How much have I spent on DigitalOcean this month?”
  • “List my Droplets.”
  • “Redeploy the api app.”
  • “Add an A record for staging pointing to 203.0.113.10.”

Limits

  • It can only do what the token allows.
  • It doesn’t ssh into your Droplets: for what happens inside one, it reads its metrics or asks you to run a command.
  • To take an app back to an earlier deploy, it tells you where to do it in DigitalOcean’s control panel.

If you remove it

Your agent loses access and confirms it. The token is deleted from minai with the plugin; to close it off completely, delete it on DigitalOcean’s tokens page too. See Remove a plugin.

Cloudflare

DNS, Workers, cache and traffic.

GitHub

Repos, issues and pull requests.