Integrations — Hetzner

Hetzner, in the same control plane as everything else

Hetzner is a German company running its own EU data centers — the cloud most teams reach for first on price, and the only one in Sencai's lineup where DNS, firewalls, and networks are all managed live at the provider, not just recorded in a database. Connect your existing Hetzner account, or let Sencai provision and bill capacity under its own account instead, then run it next to AWS, Google Cloud, Scaleway, or any of the other ten providers from one place. Nothing about your Hetzner contract changes unless you ask it to.

Live DNS: yesLive firewall: yesLive network: yes

Bring your Hetzner account, or let Sencai run one for you

Most teams start by connecting an existing Hetzner account. You hand Sencai an API token, Sencai encrypts it at rest, and nothing moves — the account, the contract, and the Hetzner invoice stay exactly where they are. Revoke access at Hetzner at any time and Sencai's view of that account disappears with it. If you'd rather not hold a Hetzner account yourself, Sencai can provision and bill Hetzner capacity under its own account instead. You get one contract and one invoice from Sencai, at Hetzner's cost plus a 2% margin shown as its own line item — never folded into a bigger number. Both models work inside the same organisation, so you can start with your own account and add Sencai-managed capacity later, or the other way around.

See what's already running the moment you connect

Connecting a Hetzner account triggers an inventory pass, not a migration. Sencai reads every server, network, volume, and DNS zone in the account and lists it alongside whatever you've connected from other providers — no agent required for this step, no downtime, nothing to reconfigure on the Hetzner side. From there, management is opt-in per resource. A server showing up in inventory doesn't mean Sencai starts touching it; you decide which servers get the fleet agent, which firewalls Sencai is allowed to edit, and which DNS zones it manages live. Old test servers, one-off boxes, and anything you'd rather leave alone can sit in inventory, visible, untouched.

Hetzner is the one provider where DNS, firewalls, and networks are all live

Provisioning works the way it does for every connected provider: start, stop, resize, or destroy a Hetzner server from the same screen you use for the rest of your fleet, no separate console, no copy-pasted API calls. Hetzner is also the only one of Sencai's eleven providers where all three live-management surfaces are switched on. DNS record changes, firewall and security-group rules, and virtual network changes go straight to Hetzner's API and take effect immediately — Sencai isn't editing a cached copy of your setup, it's editing the real thing. Add a firewall rule in Sencai and it's live at Hetzner immediately, not queued for a later sync. For servers you manage with the fleet agent, patching, monitoring, and approval-gated runbooks work identically here and on every other Linux host in your fleet, cloud or bare metal.

Every change on Hetzner lands in one audit trail, one cost view

Every action Sencai takes on your Hetzner account — a provisioned server, a firewall rule, a DNS record — writes to an append-only, hash-chained audit log. Entries can't be edited or deleted after the fact, so 'who changed this, and when' is a query against the log, not a forensic exercise after something breaks. That's the same log covering every other provider you connect, so a Hetzner change and an AWS change from the same afternoon sit in the same timeline. Cost visibility works the same way: Hetzner spend shows up next to spend from every other connected provider, with anomaly detection watching for the kind of spike that's usually a forgotten server rather than a spending decision.

Frequently asked

Do I need to move my Hetzner account to Sencai?

No. Connecting an existing Hetzner account doesn't move anything — the account, contract, and invoice stay with you at Hetzner. Sencai stores an encrypted API token and uses it to read and manage resources on your behalf. Revoke that token in the Hetzner console at any time and Sencai loses access immediately; nothing about your Hetzner relationship changes.

What can Sencai actually change on Hetzner, versus just show me?

Provisioning (create, resize, stop, destroy servers) works for every connected provider. Hetzner also gets live DNS, firewall, and virtual network management — changes go directly to Hetzner's API and take effect immediately, not just inside Sencai's own records. That combination, all three live surfaces switched on, is currently unique to Hetzner among the providers Sencai connects to.

Can I run Hetzner next to AWS, Google Cloud, or the other providers in one place?

Yes — that's the point. Connect Hetzner alongside any of the other ten providers Sencai supports and everything shows up in one inventory, one provisioning workflow, one audit trail, and one cost view. You don't switch consoles to move between a Hetzner server and, say, an AWS instance in the same organisation.

Does Sencai support Hetzner's low-cost pricing model, or add its own markup?

If you connect your own Hetzner account, you keep paying Hetzner directly — Sencai adds nothing. If you choose Sencai-managed Hetzner capacity instead, you get one invoice at Hetzner's cost plus a flat 2% margin, shown as its own line so you can always see what Hetzner charged versus what Sencai added.

Where is Sencai based, and does that matter for a German provider like Hetzner?

Sencai is Sencai Tech s.r.o., based in Prague and operating under EU law — the same jurisdiction Hetzner's German infrastructure sits in. For teams keeping data and vendor relationships inside the EU, pairing an EU-based control plane with an EU-based provider keeps that story consistent end to end.

Visit Hetzner ↗

Connect your Hetzner account

Start free with one organisation, one user, and five managed resources — no card required. The first Hetzner inventory pass starts the moment you connect an account.

Start free trialTalk to us