Skip to main content
Monk needs an API token to provision and manage infrastructure in your Hetzner Cloud account. Like DigitalOcean, this is a simple token-based setup.

What you need

  • Hetzner Cloud API Token
  • Optional: default region (e.g., eu-central)

Create credentials

1

Open the Hetzner Cloud Console

Log into Hetzner Cloud Console and select the project you want Monk to manage.
2

Go to API Tokens

In the left sidebar, navigate to Security > API Tokens.
3

Generate a token

Click Generate API Token. Name it something like monk-deployment. Select Read & Write permissions.
4

Copy the token

Copy the token immediately. It is shown only once and cannot be retrieved later.
5

Provide to Monk

When you deploy to Hetzner, Monk requests the token through a secure local form, never through the chat. You can also tell your agent:

Required permissions

The token needs Read & Write permissions. Hetzner tokens are scoped to a single project: one token cannot access resources in other projects. There is no fine-grained permission model; Read & Write grants full access to all resources within the project.

How credentials are stored

You enter credentials in a form in the local dashboard, never in chat. Monk keeps them in your OS keychain (or an encrypted file where there is no keychain) on your computer and pushes them to your cluster when a deployment needs them. The coding agent never sees the values. See Security.

Troubleshooting

Token revoked: generate a new token from Security > API Tokens in the Hetzner Cloud Console and update credentials in Monk. Wrong project: Hetzner tokens are project-scoped. Make sure you generated the token in the correct project. Insufficient permissions: make sure the token has Read & Write. Read-only tokens cannot provision infrastructure. Ask your agent for help:

Deploy your first app

Credentials ready? Deploy your app