Hetzner integration
Run your Hetzner servers and DNS without living in the console
Connect a Hetzner project with one API token and every server, volume, firewall, network, DNS zone and certificate in it appears in InfraNest — beside everything you run at other providers. Reboot a machine, fix a record or check an expiry date without opening the Cloud Console.
Free plan · About 2 minutes · One token covers cloud and DNS
- Servers, volumes, firewalls and networks, all controllable
- Zones found and imported the moment you connect
- Resources you can lock against accidental deletion
- Certificate expiry watched with everything else
14 servers · 12 running
Point-in-time copies of your server disks, kept even after a server is deleted.
Floating IP addresses you can attach to and move between your servers.
5 servers are polled by their provider, so memory, disk space and load are not being measured on them.
14 servers across 4 accounts · €425.59/mo
6 snapshots · 71.3 GB stored
3 attached to nothing — €6.30 a month
A reserved address keeps billing after the server it was reserved for is gone. Release it at your provider, or attach it to a server.
14 addresses across 4 accounts
Your Hetzner servers, without the Cloud Console
Connect a project and every server in it appears with its specs, region and state, in the same list as the machines you run elsewhere. Power them on and off, reboot, rebuild, take snapshots and manage backups — and the rest of the project comes with them, so the routine jobs stop being a reason to open the console at all.
- Power, reboot, rebuild, snapshots and backups
- Volumes, firewalls, private networks and load balancers
- Specs, region and state beside every other provider you run
- More than one project? Connect each one and keep them apart
Manual point-in-time copies you take yourself.
6 snapshots, 3 protected from deletion — 375 GB of disk stored as 71.3 GB, 81% smaller.
A snapshot is priced on what it actually occupies, not on the size of the disk it came from — automatically where your provider publishes a rate, and set by you where it does not. It feeds the Spend report, which is where snapshot sprawl stops being a hunch and becomes a number.
For when SSH refuses, the server will not finish booting, or a firewall rule shut you out.
Credentials are temporary, requested per session and expiring shortly after. Opening one is written to the audit log, so the team can see who connected and when.
Nothing gets deleted by accident
A server, volume, firewall, network or load balancer can be locked against deletion, and the lock holds wherever the delete comes from — a single click, a bulk action, or an automation running on its own at three in the morning. It is the protection that matters most on the provider where a machine is one click from gone.
- Lock servers, volumes, firewalls, networks and load balancers
- Enforced for bulk actions and automations, not just single clicks
- A delete made in Hetzner’s own dashboard needs Hetzner’s lock as well
Delete — the machine goes
Destroys mail-01 at your provider. The billing stops.
At TransIP this is a cancellation: the machine keeps running until the end of the period you have already paid for.
Of your accounts, only TransIP works that way — and the confirmation says which of the two you are about to do.
Type the server name to confirm deletion:
Plus your organisation’s re-authentication where it is required — passkey, code or password. The capability check runs first, so you are never asked for a passkey for an action the provider was never going to allow.
Stop tracking — the machine stays
mail-01 will disappear from your server list, monitoring and cost reports. Nothing happens to the machine itself.
The server keeps running and your provider keeps charging for it. To stop paying, delete it at the provider instead.
You can bring it back at any time from Servers → Not tracked. Its metrics, tags and settings are kept.
No re-authentication, deliberately: gating the reversible button would push people towards the one that is not.
Two locks, and either one is enough to refuse
InfraNest’s delete lock
Guards deletion, rebuild and restore through InfraNest (and, where supported, the provider). It can’t stop changes made in your provider’s own dashboard.
TransIP’s own protection
TransIP declares no protection of its own, so ours is the only lock. That is not reported as “off” — the cloud simply never offered one.
Enforced at the deletion itself rather than on the API route, so it also refuses a rebuild, and a delete arriving from an automation or a background job.
DNS for any domain, wherever it is registered
Hetzner DNS will host a zone for any domain you point at it, whoever you bought the name from — and InfraNest finds the zones you already have when you connect, so there is nothing to re-enter. Records are created, edited and deleted in the same editor as every other provider’s, and each one keeps its own identity at Hetzner, so an edit changes exactly the record you meant and a change made outside InfraNest still lines up here.
- Existing zones discovered and imported on connect
- Create, edit and delete records for any domain pointed at Hetzner DNS
- An edit changes the record you meant, not one that looks like it
- Changes made outside InfraNest still match up correctly
Certificate expiry, watched with everything else
Certificates held at Hetzner appear in your certificate list with their expiry dates — beside the ones at your other providers and the ones your servers issued themselves. Checking becomes something you do once, in one place, instead of project by project until you forget.
- Hetzner certificates listed with their expiry dates
- One list across every provider and every server
- Told before a certificate expires, rather than after
See your own Hetzner project in InfraNest
Free plan, no credit card. Connect a project and your servers, zones and certificates appear on their own.
Connect Hetzner in about two minutes
One API token from your Hetzner project, covering cloud and DNS together. Read & Write if you want to manage things from here — a read-only token still shows you everything.
- 1
Create a Hetzner API token
In your Hetzner Cloud project, go to Security → API Tokens and generate a token with Read & Write access. The same token covers both cloud resources and DNS.
- 2
Open Hetzner in InfraNest
Go to Integrations and open Hetzner. Add an optional Account label to recognise the connection later.
- 3
Choose what to manage
Select which features to use it for: Cloud, DNS and Certificates.
- 4
Paste your token and connect
Paste the API token, leave Email me when this integration has problems ticked if you want alerts, then select Connect. InfraNest checks the token and starts bringing in your servers and zones.
That’s it — Hetzner is connected.
Full setup guideSet up with AI
I use Hetzner Cloud, and I want to connect it to InfraNest (infranest.io) — it manages servers, DNS and certificates across providers. It needs a Hetzner API token, created in the project under Security → API Tokens. Walk me through creating one: where that screen is, what the difference between Read and Read & Write means for this, and whether one token really covers both cloud resources and DNS. Then tell me how to check the token works before I paste it in.
What syncs
What InfraNest keeps in sync with Hetzner.
| Cloud resources | Servers, volumes, firewalls, networks and load balancers |
| DNS zones | DNS zones and records |
| Certificates | Certificates and their expiry |
What still happens at Hetzner
InfraNest can't register domains through Hetzner — you'll still do that at your registrar.
Questions about the Hetzner integration
#What happens if the token is revoked or expires?
InfraNest will show an authentication failure and stop being able to manage or sync that project. You'll need to generate a new Read & Write token in the Hetzner Cloud Console and reconnect.
#Can InfraNest change things on the Hetzner side, or is it read-only?
With a Read & Write token, InfraNest can create, edit and delete DNS records and zones, and manage servers, volumes, firewalls, networks and load balancers — these changes are sent to Hetzner directly. A read-only token will show your resources but can't manage them.
#Can InfraNest stop someone from deleting a server by mistake?
Yes. InfraNest can lock servers, volumes, firewalls, networks and load balancers against deletion, and that lock is enforced wherever a delete is attempted — the console, the API, a bulk action or an automation. It can't block a deletion made directly in Hetzner's own dashboard unless Hetzner's own lock is set at the same time.
#Does this cover domain registration too?
No. InfraNest manages DNS zones and records through Hetzner, but it doesn't register domains — that still happens at your registrar.
#I run more than one Hetzner project. Can I connect both?
Yes, you can add more than one Hetzner connection and manage each project's servers, DNS and certificates separately within InfraNest.
Bring Hetzner into one dashboard
Connect a project in about two minutes, then add the next provider. Everything you run, in one place.
Free plan · No credit card required · Set up in minutes