Skip to main content
Connect FPT Cloud to let CloudThinker agents inspect the VMs, networks, disks, tags, and activity in your VPCs, and change them after you approve. The connection uses one personal access token and reaches every VPC that the token’s user can see, so you do not enter a VPC or an organization.

Prerequisites

  • An FPT Cloud account that you sign in to at console.fptcloud.com with FPT ID or your organization’s SSO.
  • Access to at least one VPC. An organization admin assigns VPCs to users in IAM.
The token carries the permissions of the user who creates it, in every VPC that user can see. To limit what CloudThinker can reach, create the token from a user who has access only to the VPCs and permissions you want to share.

Setup

1

Create a personal access token

Sign in to the FPT Cloud console with FPT ID or SSO, then open Token. You can also select Token near the bottom of the left navigation bar.
  1. Click Create.
  2. Enter a Name, such as cloudthinker.
  3. Select an Expiration.
  4. Click Create.
  5. Copy the full token value.
2

Add the connection in CloudThinker

Open Connections, choose FPT Cloud, and enter:
  • Alias: a short name for this connection, such as production
  • Description: what this connection is for
  • FPT Cloud personal access token: the token you just copied
Click Connect. CloudThinker lists the VPCs that the token can see, then shows a Connected status with the VPC count.
FPT Cloud shows the token value only once. If you close the dialog before you copy it, delete the token and create a new one.

Connection details

Required permissions

A token is not bound to a VPC or an organization. It carries the permissions of the user who created it across the whole FPT Cloud API.
  • To read, the user needs access to the VPCs you want agents to inspect.
  • To let agents make approved changes, the user also needs the matching permissions, such as VM power actions or tag management.
  • The connection test needs only a signed-in user with at least one assigned VPC.
For read-only use, create the token from a user whose role in IAM → Roles grants only the read permissions you need. The built-in ORG Super Admin and VPC Super Admin roles grant full administrative rights.

Agent capabilities

When the token can see one VPC, agents use it. When it can see several VPCs, the agent lists them and asks you which one to use.
The connection does not create Kubernetes clusters or databases. Historical CPU, memory, disk, and network usage is available only in a VMware VPC. A console link, a monitoring link, an export link, or a password reset is returned only after you approve it.

Verify the connection

Example prompts

Troubleshooting

The token field is empty, or the pasted value contains a space or a line break. Copy the full token again without extra characters, then reconnect.
The token has expired, was deleted, or was not copied in full. On the FPT Cloud Token page, check that the token status is Active. If it is Expired or missing, create a new token and reconnect.
FPT Cloud refused to list the VPCs of the token’s user. Ask your organization admin to check the user’s role in IAM, then reconnect.
The token’s user has no VPC. Ask your organization admin to give the user access to a VPC in IAM, or create the token from a user who has one.
CloudThinker could not open a connection to FPT Cloud. Retry the connection. If it fails again, check the FPT Cloud status with FPT Cloud support.
FPT Cloud is limiting requests. Wait a few minutes, then retry the connection.
FPT Cloud returned a server error. Wait a few minutes, then retry the connection.
The VPC you named is not assigned to the token’s user. Ask the agent to list your FPT Cloud VPCs, then choose a VPC from that list.

Security

  • Least privilege — grant only the permissions the agents need for your use case; start read-only and widen later.
  • Read-only by default — use read-only credentials unless you want agents to make changes through this connection.
  • Rotate credentials — rotate keys and tokens on your normal schedule; CloudThinker picks up the new value when you update the connection.
  • Revoke on offboarding — remove the credential at the provider when you delete a connection or a teammate leaves.
  • Set an expiration — choose the shortest expiration that fits your use, and create a new token before the old one expires.
  • Delete the token to revoke access — deleting a token on the FPT Cloud Token page stops all access through it immediately.

Connections

See all available provider connections.

Approval

How approval-gated actions work