OneCLI connects AI agents to Docker Hub with your username and a personal access token. Agents can browse and manage repositories, tags, and organizations. The gateway injects the credentials into every request, so your agent never sees them.Connecting takes about a minute.
Open app.docker.com, then Account settings > Personal access tokens, and click Generate new token. Name it OneCLI, choose the access permissions (Read-only, or Read & Write if agents should change repositories), and copy the token right away. Tokens start with dckr_pat_.
2
Enter it in OneCLI
In the OneCLI dashboard, open Connections > Docker Hub, enter your Username and the Personal Access Token, and click Connect Docker Hub.
The Docker Hub connect window in OneCLI.
OneCLI signs in to Docker Hub when you connect and rejects wrong credentials right away.
Grant the connection to each agent that needs it, and choose per tool what runs freely, what needs approval, and what’s blocked. Delete repository and Delete tag can’t be undone, so put them behind approval. Organization rules add guardrails on top. A blocked request never reaches Docker Hub.To disconnect, remove the connection in Connections > Docker Hub, then delete the token in Docker under Personal access tokens.