InfraNestInfraNest
Hetzner

Hetzner integration

Run your Hetzner servers and DNS without living in the console

Connect a Hetzner project with one API token and every server, volume, firewall, network, DNS zone and certificate in it appears in InfraNest — beside everything you run at other providers. Reboot a machine, fix a record or check an expiry date without opening the Cloud Console.

Free plan · About 2 minutes · One token covers cloud and DNS

  • Servers, volumes, firewalls and networks, all controllable
  • Zones found and imported the moment you connect
  • Resources you can lock against accidental deletion
  • Certificate expiry watched with everything else
Servers

14 servers · 12 running

+ Add server
Snapshots

Point-in-time copies of your server disks, kept even after a server is deleted.

Create snapshot
IP addresses

Floating IP addresses you can attach to and move between your servers.

5 servers are polled by their provider, so memory, disk space and load are not being measured on them.

NamePrice
DigitalOcean — Staging1 of 5€204.00/mo
queue-01Frankfurt · 165.227.40.22 · s-4vcpu-8gbAgent · every minute€48.00/mo
Hetzner — Production2 of 6€149.59/mo
api-02Falkenstein · 5.75.140.21 · cpx41Provider · every 5 min€30.20/mo
build-01Falkenstein · 5.75.140.50 · cax21Monitoring off€7.49/mo
OVHcloud — Beauharnois1€12.00/mo
edge-us-01Beauharnois · 51.222.204.12 · vps-essential-4No metrics API€12.00/mo
TransIP — Amsterdam1 of 2€60.00/mo
mail-01Amsterdam · 89.41.166.20 · vps-bladevps-x8Provider · every 5 min€40.00/mo

14 servers across 4 accounts · €425.59/mo

web-01 golden imageProtectedfrom web-01 · 80 GB disk · 6.2 GB stored6.2 GB
db-01 nightlyfrom db-01 · 40 GB disk · 11.1 GB stored11.1 GB
queue-01 weeklyfrom queue-01 · 80 GB disk · 14.2 GB stored14.2 GB
api-01 before the 2.4 rolloutfrom api-01 · 60 GB disk · 9.8 GB stored9.8 GB
db-01 before schema migrationProtectedfrom db-01 · 40 GB disk · 11.4 GB stored11.4 GB
mail-01 pre-upgradeProtectedfrom mail-01 · 75 GB disk · 18.6 GB stored18.6 GB

6 snapshots · 71.3 GB stored

3 attached to nothing — €6.30 a month

A reserved address keeps billing after the server it was reserved for is gone. Release it at your provider, or attach it to a server.

IP AddressCost
5.161.70.99Ashburn€1.70/mo
5.75.140.99Nuremberg€0.60/mo
159.203.80.99New York€4.00/mo
49.13.55.30Helsinki€0.60/mo
5.75.140.10Nuremberg€0.60/mo
5.75.140.11Nuremberg€0.60/mo
5.75.140.20Falkenstein€0.60/mo
5.75.140.21Falkenstein€0.60/mo
5.75.140.50Falkenstein€0.60/mo
143.198.60.99Amsterdam
165.227.40.99Frankfurt
89.41.166.21Amsterdam
89.41.166.20Amsterdam
51.222.204.12Beauharnois

14 addresses across 4 accounts

Your Hetzner servers, without the Cloud Console

Connect a project and every server in it appears with its specs, region and state, in the same list as the machines you run elsewhere. Power them on and off, reboot, rebuild, take snapshots and manage backups — and the rest of the project comes with them, so the routine jobs stop being a reason to open the console at all.

  • Power, reboot, rebuild, snapshots and backups
  • Volumes, firewalls, private networks and load balancers
  • Specs, region and state beside every other provider you run
  • More than one project? Connect each one and keep them apart
Snapshots

Manual point-in-time copies you take yourself.

Create snapshot
web-01 golden imageProtectedfrom web-01 · 80 GB disk · 6.2 GB stored6.2 GB
db-01 nightlyfrom db-01 · 40 GB disk · 11.1 GB stored11.1 GB
queue-01 weeklyfrom queue-01 · 80 GB disk · 14.2 GB stored14.2 GB
api-01 before the 2.4 rolloutfrom api-01 · 60 GB disk · 9.8 GB stored9.8 GB
db-01 before schema migrationProtectedfrom db-01 · 40 GB disk · 11.4 GB stored11.4 GB
mail-01 pre-upgradeProtectedfrom mail-01 · 75 GB disk · 18.6 GB stored18.6 GB

6 snapshots, 3 protected from deletion — 375 GB of disk stored as 71.3 GB, 81% smaller.

A snapshot is priced on what it actually occupies, not on the size of the disk it came from — automatically where your provider publishes a rate, and set by you where it does not. It feeds the Spend report, which is where snapshot sprawl stops being a hunch and becomes a number.

Console access

For when SSH refuses, the server will not finish booting, or a firewall rule shut you out.

WebSocket URLwss://console.hetzner.cloud/?server=…&token=…Copy
VNC hostconsole.hetzner.cloudCopy
VNC port443Copy
Password••••••••••••Copy

Credentials are temporary, requested per session and expiring shortly after. Opening one is written to the audit log, so the team can see who connected and when.

Nothing gets deleted by accident

A server, volume, firewall, network or load balancer can be locked against deletion, and the lock holds wherever the delete comes from — a single click, a bulk action, or an automation running on its own at three in the morning. It is the protection that matters most on the provider where a machine is one click from gone.

  • Lock servers, volumes, firewalls, networks and load balancers
  • Enforced for bulk actions and automations, not just single clicks
  • A delete made in Hetzner’s own dashboard needs Hetzner’s lock as well

Delete — the machine goes

Destroys mail-01 at your provider. The billing stops.

At TransIP this is a cancellation: the machine keeps running until the end of the period you have already paid for.

Of your accounts, only TransIP works that way — and the confirmation says which of the two you are about to do.

Type the server name to confirm deletion:

mail-01

Plus your organisation’s re-authentication where it is required — passkey, code or password. The capability check runs first, so you are never asked for a passkey for an action the provider was never going to allow.

Delete server

Stop tracking — the machine stays

mail-01 will disappear from your server list, monitoring and cost reports. Nothing happens to the machine itself.

The server keeps running and your provider keeps charging for it. To stop paying, delete it at the provider instead.

You can bring it back at any time from Servers → Not tracked. Its metrics, tags and settings are kept.

No re-authentication, deliberately: gating the reversible button would push people towards the one that is not.

Stop tracking

Two locks, and either one is enough to refuse

InfraNest’s delete lock

Guards deletion, rebuild and restore through InfraNest (and, where supported, the provider). It can’t stop changes made in your provider’s own dashboard.

TransIP’s own protection

TransIP declares no protection of its own, so ours is the only lock. That is not reported as “off” — the cloud simply never offered one.

Enforced at the deletion itself rather than on the API route, so it also refuses a rebuild, and a delete arriving from an automation or a background job.

DNS for any domain, wherever it is registered

Hetzner DNS will host a zone for any domain you point at it, whoever you bought the name from — and InfraNest finds the zones you already have when you connect, so there is nothing to re-enter. Records are created, edited and deleted in the same editor as every other provider’s, and each one keeps its own identity at Hetzner, so an edit changes exactly the record you meant and a change made outside InfraNest still lines up here.

  • Existing zones discovered and imported on connect
  • Create, edit and delete records for any domain pointed at Hetzner DNS
  • An edit changes the record you meant, not one that looks like it
  • Changes made outside InfraNest still match up correctly
DNSManage DNS records across all your zones and provider accounts.+ Add zone
ZoneSecurityRecords
northwind-api.devPendingOpenprovider · 7 records · synced 2h ago7
northwind-app.devCloudflare · 7 records · synced 15m ago7
northwind-docs.comCloudflare · 7 records · synced 37m ago7
northwind-mail.comTransIP · 8 records · synced 10m ago8
northwind.cloudHetzner · 4 records · synced 54m ago4
northwind.comCloudflare · 7 records · synced 15m ago7
Showing 6 of 13 zones
northwind-app.devCloudflare · 7 records · synced 15m ago7
northwind-docs.comCloudflare · 7 records · synced 37m ago7
northwind.comCloudflare · 7 records · synced 15m ago7
northwind.ioCloudflare · 7 records · synced 15m ago7
nwcloud.coCloudflare · 4 records · synced 15m ago4
nwcloud.ioDynadot · 4 records · synced 4h ago4
northwind.cloudHetzner · 4 records · synced 54m ago4
northwind.deHetzner · 7 records · synced 54m ago7
northwind-api.devPendingOpenprovider · 7 records · synced 2h ago7
northwind.euOpenprovider · 7 records · synced 2h ago7
northwind.shopPorkbun · 7 records · synced 2h ago7
northwind-mail.comTransIP · 8 records · synced 10m ago8
northwind.nlTransIP · 7 records · synced 10m ago7

Certificate expiry, watched with everything else

Certificates held at Hetzner appear in your certificate list with their expiry dates — beside the ones at your other providers and the ones your servers issued themselves. Checking becomes something you do once, in one place, instead of project by project until you forget.

  • Hetzner certificates listed with their expiry dates
  • One list across every provider and every server
  • Told before a certificate expires, rather than after
CertificatesEvery SSL/TLS certificate we see across your infrastructure — discovered automatically from your monitors, with expiry tracking and alerts.+ Add certificate
All sourcesCloudflareDigitalOceanHetznerManualMonitorPublic log (crt.sh)TransIP
SubjectExpires
northwind.com5 certificates4 auto-renew · 2 discovered, not monitored
api.northwind.comLet's Encrypt (R3) · rsa 2048 · found by Monitorin 3 months
cdn.northwind.comWildcardCloudflare Inc ECC CA-3 · ecdsa 256 · found by Cloudflarein 10 months
docs.northwind.comLet's Encrypt (R11) · ecdsa 256 · found by Monitorin 2 months
northwind.com+1Let's Encrypt (R3) · rsa 2048 · found by Monitorin 2 months
shop.northwind.comGlobalSign GCC R6 AlphaSSL CA 2023 · rsa 2048 · found by Public log (crt.sh)in 3 months
northwind-app.dev2 certificates2 auto-renew
northwind-app.devWildcardLet's Encrypt (R11) · ecdsa 256 · found by Monitorin 21 days
staging.northwind-app.devLet's Encrypt (R11) · ecdsa 256 · found by DigitalOcean, Monitornext month
Showing 7 of 11 certificates
northwind.com1 certificates1 auto-renew · 1 discovered, not monitored
cdn.northwind.comWildcardCloudflare Inc ECC CA-3 · ecdsa 256 · found by Cloudflarein 10 months
northwind-app.dev1 certificates1 auto-renew
staging.northwind-app.devLet's Encrypt (R11) · ecdsa 256 · found by DigitalOcean, Monitornext month
northwind.cloud1 certificates1 auto-renew · 1 discovered, not monitored
*.northwind.cloudWildcardLet's Encrypt (R11) · ecdsa 256 · found by Hetznerin 2 months
vpn.northwind.example1 certificates1 discovered, not monitored
vpn.northwind.examplevpn.northwind.example · rsa 4096 · found by Manual12 days ago
northwind.com3 certificates3 auto-renew
api.northwind.comLet's Encrypt (R3) · rsa 2048 · found by Monitorin 3 months
docs.northwind.comLet's Encrypt (R11) · ecdsa 256 · found by Monitorin 2 months
northwind.com+1Let's Encrypt (R3) · rsa 2048 · found by Monitorin 2 months
northwind-app.dev2 certificates2 auto-renew
northwind-app.devWildcardLet's Encrypt (R11) · ecdsa 256 · found by Monitorin 21 days
staging.northwind-app.devLet's Encrypt (R11) · ecdsa 256 · found by DigitalOcean, Monitornext month
northwind.com1 certificates1 discovered, not monitored
shop.northwind.comGlobalSign GCC R6 AlphaSSL CA 2023 · rsa 2048 · found by Public log (crt.sh)in 3 months
northwind-mail.com1 certificates1 auto-renew · 1 discovered, not monitored
northwind-mail.com+2Let's Encrypt (R3) · rsa 2048 · found by TransIPin 3 months
northwind.nl1 certificates1 discovered, not monitored
northwind.nl+1Sectigo RSA Organization Validation Secure Server CA · rsa 2048 · found by TransIPin 5 months

See your own Hetzner project in InfraNest

Free plan, no credit card. Connect a project and your servers, zones and certificates appear on their own.

Connect Hetzner in about two minutes

One API token from your Hetzner project, covering cloud and DNS together. Read & Write if you want to manage things from here — a read-only token still shows you everything.

  1. 1

    Create a Hetzner API token

    In your Hetzner Cloud project, go to Security → API Tokens and generate a token with Read & Write access. The same token covers both cloud resources and DNS.

  2. 2

    Open Hetzner in InfraNest

    Go to Integrations and open Hetzner. Add an optional Account label to recognise the connection later.

  3. 3

    Choose what to manage

    Select which features to use it for: Cloud, DNS and Certificates.

  4. 4

    Paste your token and connect

    Paste the API token, leave Email me when this integration has problems ticked if you want alerts, then select Connect. InfraNest checks the token and starts bringing in your servers and zones.

That’s it — Hetzner is connected.

Full setup guide

Set up with AI

I use Hetzner Cloud, and I want to connect it to InfraNest (infranest.io) — it manages servers, DNS and certificates across providers. It needs a Hetzner API token, created in the project under Security → API Tokens. Walk me through creating one: where that screen is, what the difference between Read and Read & Write means for this, and whether one token really covers both cloud resources and DNS. Then tell me how to check the token works before I paste it in.

What syncs

What InfraNest keeps in sync with Hetzner.

Cloud resourcesServers, volumes, firewalls, networks and load balancers
DNS zonesDNS zones and records
CertificatesCertificates and their expiry

What still happens at Hetzner

InfraNest can't register domains through Hetzner — you'll still do that at your registrar.

Questions about the Hetzner integration

#What happens if the token is revoked or expires?

InfraNest will show an authentication failure and stop being able to manage or sync that project. You'll need to generate a new Read & Write token in the Hetzner Cloud Console and reconnect.

#Can InfraNest change things on the Hetzner side, or is it read-only?

With a Read & Write token, InfraNest can create, edit and delete DNS records and zones, and manage servers, volumes, firewalls, networks and load balancers — these changes are sent to Hetzner directly. A read-only token will show your resources but can't manage them.

#Can InfraNest stop someone from deleting a server by mistake?

Yes. InfraNest can lock servers, volumes, firewalls, networks and load balancers against deletion, and that lock is enforced wherever a delete is attempted — the console, the API, a bulk action or an automation. It can't block a deletion made directly in Hetzner's own dashboard unless Hetzner's own lock is set at the same time.

#Does this cover domain registration too?

No. InfraNest manages DNS zones and records through Hetzner, but it doesn't register domains — that still happens at your registrar.

#I run more than one Hetzner project. Can I connect both?

Yes, you can add more than one Hetzner connection and manage each project's servers, DNS and certificates separately within InfraNest.

Bring Hetzner into one dashboard

Connect a project in about two minutes, then add the next provider. Everything you run, in one place.

Free plan · No credit card required · Set up in minutes