Choose how the data reaches us
CostGraph pulls it
You supply a read-only token and we call Grafana Cloud once a day. Nothing to run.
You push it
You send us FOCUS records over the API. Credentials never leave your infrastructure.
Before you begin
- In Grafana Cloud, create an Access Policy whose realm is the organization, with
the
billing-metrics:read,org-billing-info:read,org-billing-rate:read,invoices:read, andorgs:readscopes. Create a token for it. - The token must be an organization access policy token, which starts with
glc_. A stack service account token, which starts withglsa_, can’t read billing. - Note the organization slug, the
{org}ingrafana.com/orgs/{org}.
Let CostGraph pull
- Open Settings > Integrations and pick Grafana Cloud.
- Name the connection, pick the tenant these charges belong to, and enter your
organization slug, the
{org}ingrafana.com/orgs/{org}. - Enter the access policy token.
- Select Connect.
Credentials are encrypted at rest and used only to read billing data. Revoke the token
in Grafana Cloud at any time and the connection stops; nothing else is affected.
Push it yourself
Send the charges to CostGraph as FOCUS records instead. Push FOCUS data covers the connection id, thefocus:write key, and the request shape.
Run the exporter
Rather than build that request yourself, run our exporter. It reads Grafana Cloud on a schedule and pushes the records for you, wherever you want to run it: a container, a KubernetesCronJob, or a binary on a machine you already have.