> ## Documentation Index
> Fetch the complete documentation index at: https://docs.cloudthinker.io/llms.txt
> Use this file to discover all available pages before exploring further.

# FPT Cloud

> Connect FPT Cloud to inspect VMs, networks, tags, and activity in your VPCs and run approved VM, disk, and tag changes

Connect FPT Cloud to let CloudThinker agents inspect the VMs, networks, disks, tags, and activity in your VPCs, and change them after you approve.

The connection uses one **personal access token** and reaches every VPC that the token's user can see, so you do not enter a VPC or an organization.

## Prerequisites

* An FPT Cloud account that you sign in to at [console.fptcloud.com](https://console.fptcloud.com) with **FPT ID** or your organization's **SSO**.
* Access to at least one VPC. An organization admin assigns VPCs to users in **IAM**.

<Info>
  The token carries the permissions of the user who creates it, in every VPC that user can see. To limit what CloudThinker can reach, create the token from a user who has access only to the VPCs and permissions you want to share.
</Info>

## Setup

<Steps>
  <Step title="Create a personal access token">
    Sign in to the FPT Cloud console with FPT ID or SSO, then open [**Token**](https://console.fptcloud.com/tokens). You can also select **Token** near the bottom of the left navigation bar.

    1. Click **Create**.
    2. Enter a **Name**, such as `cloudthinker`.
    3. Select an **Expiration**.
    4. Click **Create**.
    5. Copy the full token value.
  </Step>

  <Step title="Add the connection in CloudThinker">
    Open **Connections**, choose **FPT Cloud**, and enter:

    * **Alias**: a short name for this connection, such as `production`
    * **Description**: what this connection is for
    * **FPT Cloud personal access token**: the token you just copied

    Click **Connect**. CloudThinker lists the VPCs that the token can see, then shows a **Connected** status with the VPC count.
  </Step>
</Steps>

<Warning>
  FPT Cloud shows the token value only once. If you close the dialog before you copy it, delete the token and create a new one.
</Warning>

## Connection details

| Field                               | Required | Description                                                                                              |
| ----------------------------------- | -------- | -------------------------------------------------------------------------------------------------------- |
| **Alias**                           | Yes      | A name for this connection. Use a different alias for each FPT Cloud connection.                         |
| **Description**                     | Yes      | What this connection is for.                                                                             |
| **FPT Cloud personal access token** | Yes      | The token from the FPT Cloud **Token** page. The connection can reach every VPC that this token can see. |

## Required permissions

A token is not bound to a VPC or an organization. It carries the permissions of the user who created it across the whole FPT Cloud API.

* To read, the user needs access to the VPCs you want agents to inspect.
* To let agents make approved changes, the user also needs the matching permissions, such as VM power actions or tag management.
* The connection test needs only a signed-in user with at least one assigned VPC.

<Tip>
  For read-only use, create the token from a user whose role in **IAM → Roles** grants only the read permissions you need. The built-in **ORG Super Admin** and **VPC Super Admin** roles grant full administrative rights.
</Tip>

## Agent capabilities

| Capability              | Description                                                                                                                                          |
| ----------------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------- |
| **VPC discovery**       | List the VPCs the token can see, with their region and platform                                                                                      |
| **VMs**                 | VM inventory and detail, NICs, attached resources, flavors, templates, and storage policies                                                          |
| **Networks**            | Subnets, security groups, floating IPs, load balancer backends, and Edge Gateway VMs                                                                 |
| **Storage and backup**  | Disks, snapshots, snapshot schedules, backups, and restore points                                                                                    |
| **Tags**                | Tags, tag assignments, tag coverage, and tag policies                                                                                                |
| **Activity and search** | The VPC activity log and resource search inside the selected VPC                                                                                     |
| **Permissions**         | Check which FPT Cloud permissions the token's user holds in a VPC                                                                                    |
| **Approved changes**    | Create, power, reboot, rename, resize, or delete a VM, and change its NICs, disks, snapshots, schedules, and tags. Each change **requires approval** |

When the token can see one VPC, agents use it. When it can see several VPCs, the agent lists them and asks you which one to use.

<Info>
  The connection does not create Kubernetes clusters or databases. Historical CPU, memory, disk, and network usage is available only in a VMware VPC. A console link, a monitoring link, an export link, or a password reset is returned only after you approve it.
</Info>

### Verify the connection

```text theme={null}
@alex list the VPCs and VMs available through my FPT Cloud connection
```

### Example prompts

```text theme={null}
@alex #report list my FPT Cloud VMs with their status and IP addresses
@alex #report show the FPT Cloud VMs that have no tags and #recommend tags for them
@alex #report reboot the FPT Cloud VM web-01 and ask me before you change it
```

## Troubleshooting

<Accordion title="FPT Cloud personal access token is required">
  The token field is empty, or the pasted value contains a space or a line break. Copy the full token again without extra characters, then reconnect.
</Accordion>

<Accordion title="FPT Cloud rejected the personal access token.">
  The token has expired, was deleted, or was not copied in full. On the FPT Cloud **Token** page, check that the token status is **Active**. If it is **Expired** or missing, create a new token and reconnect.
</Accordion>

<Accordion title="FPT Cloud token lacks permission to list its VPCs.">
  FPT Cloud refused to list the VPCs of the token's user. Ask your organization admin to check the user's role in **IAM**, then reconnect.
</Accordion>

<Accordion title="FPT Cloud token has no assigned VPC.">
  The token's user has no VPC. Ask your organization admin to give the user access to a VPC in **IAM**, or create the token from a user who has one.
</Accordion>

<Accordion title="FPT Cloud could not be reached from the executor.">
  CloudThinker could not open a connection to FPT Cloud. Retry the connection. If it fails again, check the FPT Cloud status with FPT Cloud support.
</Accordion>

<Accordion title="FPT Cloud rate limit reached. Retry the connection later.">
  FPT Cloud is limiting requests. Wait a few minutes, then retry the connection.
</Accordion>

<Accordion title="FPT Cloud is temporarily unavailable. Retry the connection later.">
  FPT Cloud returned a server error. Wait a few minutes, then retry the connection.
</Accordion>

<Accordion title="The agent says the token cannot see a VPC">
  The VPC you named is not assigned to the token's user. Ask the agent to list your FPT Cloud VPCs, then choose a VPC from that list.
</Accordion>

## Security

* **Least privilege** — grant only the permissions the agents need for your use case; start read-only and widen later.
* **Read-only by default** — use read-only credentials unless you want agents to make changes through this connection.
* **Rotate credentials** — rotate keys and tokens on your normal schedule; CloudThinker picks up the new value when you update the connection.
* **Revoke on offboarding** — remove the credential at the provider when you delete a connection or a teammate leaves.

- **Set an expiration** — choose the shortest expiration that fits your use, and create a new token before the old one expires.
- **Delete the token to revoke access** — deleting a token on the FPT Cloud **Token** page stops all access through it immediately.

## Related

<CardGroup cols={2}>
  <Card title="Connections" icon="plug" href="/guide/connections/overview">
    See all available provider connections.
  </Card>

  <Card title="Approval" icon="shield-check" href="/guide/approval">
    How approval-gated actions work
  </Card>
</CardGroup>
