Back to docs

Get started

Connect your Hetzner project

From a read-only API token to your first cost chart in five minutes. The fastest visible win in CloudTally.

Last updated: 2026-05-21

On this page

  1. What CloudTally needs from Hetzner
  2. Step 1: Create the token in Hetzner Cloud Console
  3. Step 2: Add the connection in CloudTally
  4. Step 3: Watch the first sync

You'll do three things: create a read-only token in the Hetzner Cloud Console, paste it into CloudTally, and wait about a minute for the initial sync. By the end you'll see a populated dashboard with your first cost numbers.

You need an existing Hetzner Cloud project. You don't need admin rights to your CloudTally workspace — the trial starts you as Owner.

What CloudTally needs from Hetzner

A read-only API token for each project you want tracked. CloudTally never modifies anything in your Hetzner account. We reject tokens with write access during validation, so if you accidentally generate the wrong type, you'll get a clear error rather than a quiet privilege escalation.

One token covers one project. If you have multiple projects, you'll add multiple connections after the first one is working.

Step 1: Create the token in Hetzner Cloud Console

  1. Open the Hetzner Cloud Console.
  2. Select the project you want to track.
  3. In the project sidebar, click Security, then API Tokens.
  4. Click Generate API Token.
  5. Give it a name — cloudtally-readonly is a good default.
  6. Set permissions to Read only. This is important: CloudTally will reject Read & Write tokens.
  7. Click Generate API Token. Copy the token shown on the next screen — Hetzner displays it once and never again.

Step 2: Add the connection in CloudTally

  1. In CloudTally, open SettingsConnections.
  2. Click Add Connection.
  3. Fill in the form:
    • Connection Name — a clear label your team will recognise. Use production, staging, or whatever maps to how you think about the project.
    • Hetzner Project Name — the project's name in the Hetzner Console. Used for display only; it doesn't have to match exactly, but matching reduces confusion.
    • Hetzner API Token — paste the token from Step 1.
  4. Click Connect.

CloudTally validates the token immediately. Common errors and what they mean:

  • "This API token format is invalid" — the token isn't 64 alphanumeric characters. You probably copied something extra.
  • "This Hetzner project is already connected" — there's a connection on another organisation using the same token fingerprint. Use a different token, or remove the existing connection.
  • "Token has write permissions" — generate a new token with Read permission only.

Step 3: Watch the first sync

After the token is accepted, CloudTally kicks off a bootstrap sync. It pulls every resource in the project — servers, volumes, load balancers, floating IPs, snapshots — plus the prices, then computes the current month's cost so far.

Open the Dashboard. Until the sync finishes you'll see No cost data yet. The sync indicator in the header shows progress. Typical projects finish in under a minute. Large projects (hundreds of resources) can take a few minutes.

When the sync completes, the dashboard populates with:

  • This month — what you've spent so far this calendar month.
  • Projected month-end — what you'll spend if usage stays the same. The full forecast (with confidence and category drivers) is a Pro feature; on Free you see the headline number.
  • Top cost drivers — your highest-spend resources, ranked.
  • Cost by type — a chart breaking spend down across server, volume, load balancer, etc.

That's the win. You now know what your Hetzner project is costing, broken down by resource, without having to wait for the end-of-month invoice.

What to do next

You've got about three minutes of useful next work:

  • Set a budget for this month. Pick 80% of last month's spend and wire up an email alert. See Set your first budget.
  • Invite your finance lead. Even if they only read the dashboard, getting them in early reduces "how much did we spend on Hetzner?" Slack pings later. See the Team how-to (coming soon).
  • Connect a second project. Same flow — different token, different project. Each connection is independent: separate sync, separate metering, but all visible from one dashboard.

If you want the full guided path through the trial, the next-best read is Your first week on the trial.