Self-hosted service
digitalocean/doctl avatar
digitalocean/doctl

doctl: the DigitalOcean API from a terminal

The official command line interface for the DigitalOcean API.

3,455 stars509 forksGoApache-2.0

At a glance

What is it?
doctl is DigitalOcean's official CLI, a Go binary that wraps the v2 API for compute, Kubernetes, databases, apps and registries. It is the right tool if you already run on DigitalOcean and want repeatable commands instead of console clicks, and the wrong one if your infrastructure lives elsewhere.
Who is it for?
Adopt doctl if DigitalOcean is your provider and you want the same operations available from a shell, a Makefile or CI, with JSON output for scripting. Do not adopt it as a multi-cloud abstraction; every command maps to a DigitalOcean resource, and the API token you hand it carries the permissions of that account.
Can I use it commercially?
Yes. Apache-2.0 is a permissive licence: you can use, modify and sell software built on it, as long as you keep its copyright and licence notices.
Is it still maintained?
Yes. The repository last received commits 1 day ago.
What is it written in?
Mainly Go, according to GitHub's language statistics.

Answers come from the project's GitHub data, last synced on September 30, 2026, and from our analysis. They are not legal advice.

Editorial analysis

The gap doctl fills between the DigitalOcean console and your scripts

Every resource on DigitalOcean is reachable through the v2 API, but calling that API directly means writing HTTP clients, handling pagination and formatting output yourself. doctl is the official command-line interface that sits on top of it, so the same operations you would click through in the control panel become single commands you can put in a shell script or a CI job. The README describes it in one line: "doctl is a command-line interface (CLI) for the DigitalOcean API."

The audience is narrow and specific. If you run droplets, Kubernetes clusters, managed databases, App Platform deployments or a container registry on DigitalOcean, doctl is the sanctioned way to drive them from a terminal. It is not a general cloud tool. There is no AWS or GCP backend behind it, and the command list in the README reads like a map of DigitalOcean products: compute, databases, kubernetes, apps, registry, vpcs, projects, monitoring (marked Beta), balance, billing-history, invoice. If those names do not describe your infrastructure, the tool has nothing to offer you.

How doctl talks to the API: Cobra commands over godo

The repository layout shows a conventional Go CLI. Commands live in the commands/ directory, the root entry point is doit.go, and the dependency list in go.mod includes github.com/spf13/cobra for command parsing and github.com/digitalocean/godo v1.213.0, the Go client library for the DigitalOcean API. That is the data flow: a Cobra command validates arguments, calls a godo method, and the result is rendered either as text or as JSON depending on the output flag.

Global flags control the whole session. The README lists -t/--access-token for the API token, -u/--api-url to override the default endpoint, -c/--config to point at a custom config file, --context to select a named authentication context, -o/--output for text or json, --trace to log network activity, and -v/--verbose. The --api-url flag is worth noticing: it means the binary is not hardwired to one host, which is how you would point it at a proxy or a compatible endpoint. The --trace flag is the practical debugging tool when a command fails and the error message is not enough.

A plugin mechanism also exists in the repository: there is a pluginhost/ directory and the go.mod lists github.com/natefinch/pie, the library used for building plugin hosts over subprocess pipes. The README does not document a plugin authoring workflow, so treat that as internal plumbing rather than a supported extension point.

Installing doctl and authenticating your first command

The README calls package managers the preferred route. On macOS that is Homebrew, and the same formula covers both Intel and Apple Silicon machines:

bash
brew install doctl

On Snap-supported systems, the Snap package is the equivalent. Snap confinement means a few capabilities are not granted by default, and the README spells out the connections you need to add. For kubectl integration, which writes your kubeconfig, you connect the kube-config personal-files interface:

bash
sudo snap install doctl
sudo snap connect doctl:kube-config

Two more Snap connections appear in the README. doctl compute ssh needs the ssh-keys interface, and doctl registry login needs the dot-docker personal-files connection so the tool can write registry credentials into your Docker configuration file. If you skip those, the corresponding commands fail rather than silently degrading.

Other platforms are covered by distribution repositories. Arch Linux ships it in the official repository, Fedora likewise, and Nixpkgs carries a package that the README notes is community maintained and may lag the latest version.

bash
sudo pacman -S doctl
sudo dnf install doctl

If no package exists for your system, the README points at the GitHub Releases page, where you download an archive for your OS and architecture, extract it, and move the binary onto your PATH. Containers for each release are published under the digitalocean organization on Docker Hub.

Authentication comes next. doctl reads an API token, and the README documents an auth command group plus a way to keep several accounts side by side. The global flag form is the direct one:

bash
doctl auth init
doctl account get

After a successful authentication, account get returns the email, droplet limit and status of the account the token belongs to, which is the fastest way to confirm you authenticated against the account you intended. The README also documents environment variables for configuring default values and a completion command that wires tab completion into your shell.

Where doctl stops being the right tool

The obvious boundary is provider lock-in. doctl is a client for one vendor's API. If you are running the same workload across two clouds and want one command surface, doctl does not provide it, and no amount of scripting turns it into one, because the resource model underneath is DigitalOcean's.

The second limitation is credential scope. The tool authenticates with an API token, and the README's flag list gives no indication of a per-command permission model: whatever the token can do, doctl can do. That matters when you put the binary in CI. A token generated for a deployment pipeline is the same kind of object as a token you use interactively, so the blast radius of a leaked CI secret is the full account, not a single resource.

Third, some surface area is explicitly not finished. The command list labels monitoring as "[Beta]", so behaviour there should be treated as subject to change. And the README's coverage of the plugin host is absent, which means anyone hoping to extend doctl with custom commands is working against undocumented internals rather than a published interface. The README also does not document a rollback procedure for the package-manager installs, so if a new version breaks a script you should plan on pinning versions yourself rather than relying on documented downgrade steps.

doctl against calling the API or using Terraform

The nearest alternative is not another CLI, it is the DigitalOcean API itself through a client library. godo, the Go client doctl depends on, is public and versioned independently (go.mod pins v1.213.0). Writing against godo directly gives you typed structs and full control over retries, concurrency and error handling, at the cost of writing the argument parsing and output formatting that doctl already provides. If you need one scripted operation, godo is more code than it is worth. If you are building a service that manages droplets on a schedule, godo is the more honest dependency, because you are not shelling out to a binary and parsing its stdout.

The other alternative is a declarative tool such as Terraform's DigitalOcean provider. The difference in approach is fundamental. doctl issues imperative commands: you tell it to create a droplet now, and it does. Terraform keeps a state file describing the desired end state and computes the diff. doctl is better for inspection (listing droplets, fetching an account balance, tailing a deployment), one-off operations, and interactive work. Terraform is better when the same infrastructure must be reproducible and reviewable. Many teams end up with both, using doctl for read paths and Terraform for write paths, which is a reasonable split as long as you do not start mutating Terraform-managed resources from the CLI and confusing the state file.

Maintenance, licensing and the upgrade path

The repository is not archived, and the last push was on 2026-09-23, the same day as the v1.173.0 release. Releases are frequent and versioned, with v1.171.1 and v1.171.2 landing on 2026-09-22 and v1.173.0 the following day, which tells you the project ships patches quickly. The CHANGELOG.md at the repository root is where release notes accumulate.

Upgrade cost depends on how you installed it. Package managers handle it in one command, and that is the main argument the README makes for preferring them. Snap in particular updates on its own channel. If you downloaded a release archive, upgrading means repeating the download and replacing the binary, and nothing in the README automates that for you. If you build from source, the Makefile provides a build target that produces a binary in the builds directory; the Dockerfile uses that same Makefile target inside a golang:1.24-alpine build stage and copies the result into an alpine:3.12 runtime image that runs as a non-root user.

On licensing: the repository carries Apache-2.0. That is a permissive licence with an explicit patent grant, which is generally straightforward for internal and commercial use, but the LICENSE.txt file is the authoritative text and the details of notice and attribution requirements are worth reading rather than assuming. Nothing here is legal advice.

Editorial conclusion

Adopt doctl if DigitalOcean is your provider and you want the same operations available from a shell, a Makefile or CI, with JSON output for scripting. Do not adopt it as a multi-cloud abstraction; every command maps to a DigitalOcean resource, and the API token you hand it carries the permissions of that account. Before rolling it into automation, verify which token scope your pipeline needs, whether your platform's package lags the GitHub releases, and how the Snap confinement rules affect kubectl and registry login.

Frequently asked questions

What is doctl?

doctl is the official command line interface for the DigitalOcean API, written in Go. It exposes command groups for compute, databases, Kubernetes, apps, registries, VPCs, projects, billing and account details, and it can print results as text or JSON.

How do I install doctl?

The README prefers a package manager: brew install doctl on macOS, sudo snap install doctl on Snap-supported systems, sudo pacman -S doctl on Arch Linux and sudo dnf install doctl on Fedora. Otherwise you download an archive from the GitHub Releases page, or pull a container from the digitalocean organization on Docker Hub.

How do I install and configure doctl?

Install it through your package manager, then authenticate with doctl auth init. After that, doctl account get confirms which account the token belongs to, and the README documents environment variables for configuring default values plus a completion command for shell tab completion.

How do I install doctl on Windows?

The README does not list a Windows package manager. It points at the GitHub Releases page, where you find the archive matching your operating system and architecture, download it, and extract the binary. Containers for each release are also published under the digitalocean organization on Docker Hub.

How do I install doctl on Ubuntu?

The README covers Snap-supported systems with sudo snap install doctl, and adds that kubectl use requires sudo snap connect doctl:kube-config. The Nixpkgs package is community maintained and may not be on the latest version.

Official sources

  1. digitalocean/doctl on GitHub
  2. License: Apache-2.0
  3. Project website
  4. README
  5. Releases
Add this badge to your README

If you maintain this project, the badge below links readers to this analysis and shows its maintenance status from the daily GitHub snapshot. Paste the markdown into your README; add ?metric=license or ?metric=stars to the image URL for a different field.

Add this badge to your README

markdown
[![Hysen Labs](https://hysenlabs.com/badge/digitalocean-doctl.svg)](https://hysenlabs.com/projects/digitalocean-doctl)