Skip to content

Sign in with DigitalOcean. No token to paste.

Sign in with DigitalOcean is DigitalOcean's OAuth flow: you approve an app on DigitalOcean's own page, and a public app such as an iPhone app must protect the exchange with PKCE. Duskwatch is an independent iPhone app for DigitalOcean, in development; it signs in only through that page, asks only to view, and keeps actions behind a separate permission you approve.

Updated

Why not paste a token

Many tools ask for a personal access token. It works, but it means creating a secret in the control panel, copying it through the clipboard and trusting the app with whatever scope you picked, often full access because it is the easy choice. Duskwatch has no token field at all. You sign in on DigitalOcean's page, with your password, passkey or two-factor code, and the app never sees any of them.

Sign-in asks only to view. Actions are a separate permission.

The first approval lets the app look: droplets, apps, databases, spend, status. That is enough for triage, logs, widgets and everything else that reads. When you want to reboot web-01 or roll back api-prod from the phone, you turn on "Enable actions" and approve a permission that can also act on DigitalOcean's page; it replaces the view-only one, which the app then revokes. Until you do, actions stay unavailable and the app says why.

The permissions involved, who holds each, and what each can do
PermissionHeld byCan doKept
Sign-inYour iPhoneView your teamKeychain, this device only
After "Enable actions"Your iPhone, in place of the sign-in permissionView, plus the 13 guarded actionsKeychain, this device only
AlertsThe alert server, if you turn alerts onView onlyEncrypted, in the EU

Your permissions stay in this iPhone's Keychain

The permission on your iPhone, view-only or with actions, is stored in the Keychain as "when unlocked, this device only": they are not synced to iCloud, not included in a restore to another phone, and never sent to the alert server or any other server. Widgets, the Control Center control and Spotlight never read it; they show a snapshot the app writes.

Because a refresh token works once, the app only ever runs one refresh at a time and saves the new token before using it. Two refreshes racing each other is a common way for apps to sign you out without reason.

The alert server gets its own permission, and it can only read

Push alerts need something awake while your phone sleeps. If you turn alerts on, you approve a third permission on DigitalOcean's page, and that one goes to the alert server. The server checks what DigitalOcean actually granted every time it receives or refreshes it. If the permission could change anything, the server rejects it and revokes it on DigitalOcean. The permissions on your iPhone never reach it. Details on push alerts.

Revoke it on DigitalOcean at any time

  • In the app, "Sign out of acme-prod" revokes the access on DigitalOcean and deletes that team's data from your iPhone.
  • In DigitalOcean's control panel, the API section lists the applications you have authorized, and you can revoke the app there, even without the phone.
  • Turning alerts off deletes what the alert server holds within 24 hours; "Delete my alert data" removes the rest.

An optional Face ID app lock

Actions always ask for Face ID, and that cannot be turned off. The app lock is separate and optional: it also asks for Face ID when the app opens. Lock or not, the app hides its contents in the app switcher, so a glance over your shoulder shows nothing. The full policy is on the security page.

What Duskwatch doesn't do here

  • No personal access token field, now or as a fallback.
  • No password, passkey or two-factor code ever reaches the app.
  • No permission that can change things on any server: the alert server's permission can only read.
  • No sync of permissions to iCloud or to another device.

Questions

  • Do I paste an API token?

    No. Duskwatch signs in only on DigitalOcean's own page with OAuth and PKCE, and has no token field.

  • What does sign-in ask for?

    Only permission to view your team. Actions need "Enable actions", a separate permission that you approve on DigitalOcean's page when you want it, and that replaces the view-only one.

  • Where are my permissions stored?

    In your iPhone's Keychain, "when unlocked, this device only". They are not synced to iCloud and never sent to any server.

  • How do I revoke access?

    Sign out of the team in the app, which revokes the access on DigitalOcean, or revoke the app from the authorized applications in DigitalOcean's control panel at any time.

  • Does the alert server get the full permission?

    No. It gets its own permission that can only view, and it rejects and revokes any permission that could change things.

  • Is there a Face ID app lock?

    Yes, optionally: it asks for Face ID when the app opens. Actions always ask for Face ID, and the app always hides its contents in the app switcher.

Duskwatch is in development. Join the waitlist to hear when it's on the App Store.

We'll email you once when Duskwatch is on the App Store. One-click unsubscribe. How we handle your data

Basic monitoring is free; alerts, most actions and advanced features are part of Duskwatch Pro.