> ## Documentation Index
> Fetch the complete documentation index at: https://help.dsalta.com/llms.txt
> Use this file to discover all available pages before exploring further.

# InfluxDB Cloud

> Time-series database — members, buckets & access

<Tabs>
  <Tab title="Overview">
    Connect InfluxDB Cloud with an All Access API token to sync organization owners and members with their status, buckets and API tokens, and run access reviews. Read-only. Data feeds into your Access accounts and Inventory pages.

    <Info>
      **Read-only access.** DSALTA only reads data from this integration. It never creates, modifies, or deletes anything in your environment, and every remediation step is performed by your team directly in the third-party product.
    </Info>

    <Info>
      **What you'll see.** The Access page lists the **owners and members** of one InfluxDB Cloud **organization** — the organization that owns the token, which is the first one the token can see. InfluxDB Cloud has no separate name field, so each row shows the user's **email address** in place of a name, together with their role, **Owner** or **Member**: the role on the user's record when it carries one, otherwise whether InfluxDB listed the user among the organization's owners or its members (a user in both lists is shown once, as an owner). A user whose status InfluxDB reports as active — or reports no status for — is shown as **Active**; any other status is shown as **Inactive**. InfluxDB exposes no join date on the roster, so each row is stamped with the date of the sync. Pending invitations are not exposed by the API and never appear; a system account created for administrative purposes appears as an ordinary user. InfluxDB Cloud reports no per-user MFA state, so the **MFA** column is blank (shown as a dash).
    </Info>

    <Note>
      DSALTA collects this integration's data when you connect it — you can refresh it at any time with **Sync from integrations** on the **Integrations** page. The compliance checks below re-run once a day at 02:00 America/New\_York.
    </Note>

    ## What DSALTA reads

    DSALTA reads the organization's owner and member lists — email addresses, roles and account status — which appear on your **Access** page; and the organization's **buckets** and **API tokens**, which appear on your **Inventory** page. Each bucket row carries its type, its retention period (or **forever**) and its description; the system buckets InfluxDB creates with the organization are listed like any other, so this part of the page is populated from the first sync. Each API token row carries its description, its status, the number of permissions it holds, its creation date and the user who created it — never the token value, which the API returns redacted and DSALTA drops before the row is stored. The token you connected with appears in that list. Members' last-login times are not available in the API and are not read.

    It calls these InfluxDB Cloud endpoints on your region host (`us-east-1-1.aws.cloud2.influxdata.com` unless you entered another):

    * `/api/v2/orgs`
    * `/api/v2/orgs/{orgID}/owners`
    * `/api/v2/orgs/{orgID}/members`
    * `/api/v2/buckets?orgID={orgID}&limit=100&offset={N}`
    * `/api/v2/authorizations?orgID={orgID}&limit=100&offset={N}`

    Every request is a read. DSALTA has no code path that creates, modifies, or deletes anything in your InfluxDB Cloud environment.

    ## Troubleshooting

    <AccordionGroup>
      <Accordion title="The connection is rejected">
        A token only works on the host of the region its account lives in: a token from the EU region is refused on the default US East host, and the other way round. Enter the region host shown in your address bar after signing in, or leave it empty for US East. A **Custom API Token** starts with no permissions and cannot read the organization's owners and members — generate an **All Access API Token** instead. A misspelled host fails before InfluxDB is reached at all.
      </Accordion>

      <Accordion title="The connection stopped working">
        An All Access token carries its creator's access and stops working when the user who created it is deleted from the organization. Generate a new token — from a system account if you can — then disconnect and connect again. Note that disconnecting permanently deletes the data already collected from InfluxDB Cloud.
      </Accordion>

      <Accordion title="Inventory is missing buckets or API tokens while Access works">
        Buckets and API tokens are read best-effort after the owner and member lists: a failure on either call leaves that part of the Inventory page empty without failing the sync. Click **Sync from integrations** on the **Integrations** page to retry.
      </Accordion>
    </AccordionGroup>

    <AccordionGroup>
      <Accordion title="How do I check whether the connection is healthy?">
        Open **Integrations** in the DSALTA sidebar, stay on the **Connected** tab, and click **Manage** on the integration's card. Open the **Status** tab: it shows either **Connected and working properly** or **Connection issues detected**.

        Use the **Status** tab, not **Overview** — Overview always reports **Connected** regardless of the real state.
      </Accordion>

      <Accordion title="A check shows Failed and nothing changed on my side">
        On an integration-powered check, **Failed** normally means DSALTA was blocked rather than that you are non-compliant. Open the test, go to **Source Data**, and read the result code: **403** is a missing permission, **428** is a setting DSALTA still needs, **500** is a failure on DSALTA's side.

        A real compliance gap shows **207** and leaves the test looking **Completed**. See [Understanding Test Results](/guides/compliance/test-results).
      </Accordion>

      <Accordion title="Data looks out of date">
        Compliance checks re-run once a day at 02:00 America/New\_York. To refresh sooner, open **Integrations → Connected** and click **Sync from integrations** at the top right — it refreshes every connected integration at once.
      </Accordion>

      <Accordion title="How do I repair a broken connection?">
        There is no Reconnect, Repair or Refresh Token button. The only repair available is to disconnect and connect again.

        <Warning>
          **Disconnecting is destructive and cannot be undone.** DSALTA removes the access records, inventory, vulnerabilities, code changes, incidents and device records collected from this integration, and deletes the test results tied to the connection. Export anything you still need as audit evidence first — see [Integration errors](/troubleshooting/integration-errors).
        </Warning>
      </Accordion>

      <Accordion title="Configure scope will not let me change anything">
        That is expected. **Configure scope** is read-only — it shows what DSALTA is permitted to read, and has no Save action. To change what DSALTA can see, change the permissions on the credential in the third-party product, then disconnect and connect again.
      </Accordion>
    </AccordionGroup>
  </Tab>

  <Tab title="How to connect">
    An InfluxDB Cloud All Access API token. The organization is detected automatically. Read-only.

    **Before you begin**

    * An InfluxDB Cloud organization owner — an All Access token carries its creator's access and stops working if that user is deleted.

    You will need:

    | Field | Where to find it | Example |
    | - | - | - |
    | **All Access API token** | **Load Data → API Tokens → Generate API Token → All Access API Token** | Shown once, at creation |
    | **Region host** (optional) | The host in your address bar after signing in; only needed for the EU region | `eu-central-1-1.aws.cloud2.influxdata.com` |

    <Steps>
      <Step title="Start in DSALTA">
        Open **Integrations** in the DSALTA sidebar, find **InfluxDB Cloud**, and click **Connect** to open the connect panel.
      </Step>

      <Step title="Sign in and note your region host">
        Sign in at [cloud2.influxdata.com](https://cloud2.influxdata.com) and note the host in the address bar: `us-east-1-1.aws.cloud2.influxdata.com` (US East) or `eu-central-1-1.aws.cloud2.influxdata.com` (EU). A token only works on its own region's host.
      </Step>

      <Step title="Generate an All Access API token">
        In the left navigation open **Load Data → API Tokens**, click **Generate API Token** and choose **All Access API Token**. Copy the token with **Copy to Clipboard**.

        <Warning>
          **Choose All Access, not Custom.** A Custom API Token starts with no permissions and cannot list the organization's owners and members, so DSALTA rejects it at connect time. The token is shown once; if you lose it, generate a new one.
        </Warning>

        <Info>
          Create the token from a system account if you can: an All Access token stops working when the user who created it is deleted, and the DSALTA connection fails with it.
        </Info>
      </Step>

      <Step title="Connect InfluxDB Cloud">
        Return to the connect panel and paste the token. Enter the **Region host** only if your account is in the EU region; leave it empty for US East. Then click **Connect**.
      </Step>
    </Steps>

    <Check>
      DSALTA validates the token when you click **Connect**, by listing the organization it can see and then reading that organization's owners and members; a token that can see no organization, or whose organization returns no owners or members, is rejected. On success the integration moves to the **Connected** tab, and **Manage → Status** reads **Connected and working properly**. Checks begin reporting after the first sync.
    </Check>

    <Warning>
      **If the connection is rejected.** An invalid token, the wrong region host, or a Custom token without read access to the organization.

      The on-screen message is generic — see [Connection error messages](/troubleshooting/connection-error-messages).
    </Warning>
  </Tab>

  <Tab title="Automated checks">
    Each check below re-runs once a day, at 02:00 America/New\_York, while this integration is connected. Click any check for step-by-step remediation guidance.

    | Check | Severity | What it verifies |
    | - | - | - |
    | [User access to Critical System should be valid](/integrations/influxdb-cloud/user-access-to-critical-system-should-be-valid) | Info | Checks that everyone with InfluxDB Cloud access is an active employee on the People page. |
    | [Offboarded users should not have active access](/integrations/influxdb-cloud/offboarded-users-should-not-have-active-access) | High | Checks that offboarded employees no longer have active InfluxDB Cloud access. |
  </Tab>

  <Tab title="Useful links">
    | Topic | Link |
    | - | - |
    | Setup | [InfluxDB Cloud: create an API token](https://docs.influxdata.com/influxdb3/cloud-serverless/admin/tokens/create-token/) |
    | Remediation | [Manage users](https://docs.influxdata.com/influxdb3/cloud-serverless/admin/organizations/users/) |
    | General | [InfluxDB Cloud](https://cloud2.influxdata.com) |
    | DSALTA | [Connection error messages](/troubleshooting/connection-error-messages) |
  </Tab>
</Tabs>
